When business owners imagine a cybersecurity assessment, they picture something out of a heist movie: a hooded figure in a dark room, green text scrolling across a screen, someone typing very fast while saying "I'm in." They brace for us to find something equally dramatic. What we actually find, almost every single time, is far less cinematic and far more human: a handful of ordinary, forgivable things that got deprioritized because everyone was busy running an actual business.
We want to say this clearly, up front, before we get into the details: nothing in this article is a judgment of you, your team, or your decisions. Every gap we're about to describe is one we've seen at well-run, successful, smart companies. Security gaps are not a report card on your competence. They're a report card on the fact that securing a business properly is a full-time specialty, and you were busy doing your actual full-time job.
Not "nobody cares." Nobody owns it, in the specific sense of having it clearly assigned as their job with time carved out to do it. Security tasks get handled reactively, by whoever happens to be free, with no single person tracking what's been done and what hasn't. This single gap explains a huge share of everything else on this list, because ownership is what turns a good intention into a habit, and a habit is what actually protects you. Good intentions, on their own, protect nobody, which is a very depressing sentence to read but also very fixable.
This deserves its own section because it's so common it should have its own holiday. A huge number of the gaps we find trace back to one very specific, very sympathetic cause: the person who used to manage this left the company, and nobody fully replaced their knowledge, only their job title. Dave set up the firewall rules in 2021. Dave configured the backup schedule. Dave had a system, in his head, that made sense to Dave. Then Dave took a job in Calgary, and the company hired someone lovely named Priya to do "IT stuff," and Priya inherited Dave's kingdom with none of Dave's memory. This is not Priya's fault. It was never fully documented, which means it was never really transferable in the first place, which means the gap existed the moment Dave was hired, not the moment Dave left. Businesses don't create this problem. Time and turnover create this problem, for absolutely everybody, eventually.
Almost every assessment turns up at least one shared password used by multiple staff members ("the WiFi password is also the router password is also, somehow, the accounting software password"), and at least one account still fully active for someone who left the company months or, memorably, one time, six years ago. Neither of these is a sign of incompetence. It's simply what happens when there's no formal, automatic process for onboarding and offboarding access, and a human has to remember to do it manually, and humans are, as a species, famously bad at remembering things that don't have a calendar reminder attached.
Most businesses have multi-factor authentication turned on somewhere. Fewer have it turned on everywhere it actually matters: email, remote access, financial systems, and admin accounts especially. Assessments routinely find MFA enabled on the systems that were easy to configure and quietly skipped on the systems that would actually stop an attacker, the digital equivalent of locking your front door while leaving a spare key taped to the doormat labelled "spare key."
We covered this in more detail in our piece on aging infrastructure, but it bears repeating because it comes up in nearly every assessment: there's a very big difference between "we have backups" and "we know our backups actually work," and almost every business we meet has confidently claimed the first one without ever having tested the second. It's the IT equivalent of buying a fire extinguisher and never checking whether it's expired. Comforting to look at. Untested. Hopefully fine.
If something goes wrong today, who gets called first? What gets shut down? Who talks to customers, and who talks to the insurance company? Most small businesses have never written this down, which means the first time anyone will figure it out is during an actual incident, at 11pm, in a group text chat with increasingly alarmed punctuation. This isn't a planning failure so much as a "nobody has ever had two free hours to sit down and think about the worst day of the business's life" problem, which, understandably, ranks low on most people's to-do lists until it's the only thing on the list.
Here's the part that tends to surprise people: every single item on this list is fixable, usually without a large budget, once someone identifies it clearly and gives it an owner. A gap assessment isn't a scary report designed to make you feel behind. It's a short, ranked list of exactly what to do first, second, and third, written by someone who has seen this exact pattern hundreds of times and can tell you, with total confidence, that you are not the outlier here. You are, statistically, the norm.
We don't ask "whose fault was this." We don't hand you a hundred-page report designed to be intimidating. We don't act surprised, because nothing on this list is surprising to us anymore, in the way a dentist is not shocked that you haven't flossed as much as you should have. We look, we document, we rank, and we hand you something you can actually act on, in an order that makes sense for a business your size, not a checklist copied from a Fortune 500 template that assumes you have a security team of forty people.
A cybersecurity GRC program takes findings like these and turns them into an ongoing practice instead of a one-time fire drill, with clear ownership, documented policies, and evidence you can hand an auditor, an insurer, or a customer who asks. It also means the next time someone like Dave leaves, the knowledge leaves with a full handoff, not a mystery.
If you read this whole list and recognized your business in three or four of these points, congratulations, you are a completely normal small business, and also, good timing: this is exactly the moment to fix it, calmly, before anything forces the issue.