NewScam protection for AI agents — connect the Cautellus MCP server
NewSecurity Audit Kit — audit your business in 15 minutes.$69 one-time→
security auditsmall business securityvendor security questionnairebusiness email compromisesecurity audit kit

Security Audit Kit: When a Small Business Actually Needs One

Courtney
8 min read
Share
Free Interactive Guide

Free: How to Keep Yourself Safe From Scammers

9 chapters. Reporting checklist. 30-second protection checklist. Read on the site.

Security Audit Kit: When a Small Business Actually Needs One

You landed your first real customer past "friend who signed up because they like you," and buried in their onboarding packet is a 25-question security questionnaire asking things like "is MFA required on all systems with access to customer data." You don't know. You've never had to know. Up until now, "security" meant not clicking weird links.

That moment — or one like it — is usually the first time a small business owner realizes nobody built a security audit for someone their size. The advice out there is either enterprise-scale (SOC 2 platforms running $7,500 a year and up) or too shallow to answer the question in front of you (a free checklist template that doesn't know what industry you're in). I built the Security Audit Kit for the gap in between, and this is about when it's actually worth reaching for — not a sales pitch dressed as a listicle.

The three moments this actually comes up

Someone besides you has admin access, and you've lost track of who. A contractor who built your original site two years ago. An employee who left in the spring and whose login you meant to revoke. A freelancer who still has the Stripe dashboard bookmarked. None of this is malicious most of the time — it's just what happens when a business grows past one person holding every password in their head. The problem shows up the day it isn't fine anymore: an old account gets phished somewhere unrelated, and it turns out that password still opens your customer database too.

A customer sends you a security questionnaire you don't know how to answer honestly. This is usually the first concrete sign a business has outgrown "just don't get scammed." A bigger customer, a partner integration, or an investor due-diligence request lands with a long form full of questions about encryption, access controls, and incident response, and you're staring at "yes/no" boxes where the honest answer to several of them is "I actually don't know." Answering "yes" without checking is how a company ends up contractually promising something that isn't true.

A partner asks you to prove you're not the weak link. This one's newer and it's exactly the shape of business email compromise risk — a bigger company you're integrating with, or a vendor relationship you're trying to land, wants some proof that a breach on your end can't become a breach on theirs. It's not paranoia. It's the same logic behind callback phishing and CEO fraud: attackers increasingly go after the smaller, less-defended company in a chain to reach the bigger target at the other end of it.

None of these moments call for a $50,000 pentest. They call for someone to actually check the basics, in order, and tell you honestly which parts are yours to fix, which belong to your developer, and which belong to an attorney. It's also worth pairing a one-time audit like this with something ongoing — the Kit checks your systems, but training your team to recognize phishing is what keeps someone from handing over the keys to those systems in the first place.

Not sure if your message is real? Paste it into Cautellus and get a risk score before you reply.

Scan it now →

What's actually in the audit

The Kit runs in three parts, and none of them require installing anything:

A business questionnaire — eight questions about your industry, what data you collect, your team size, and where your customers live. It generates a checklist customized to your actual setup, with every item tagged who owns it: you, your developer, or an attorney.

An AI code scan — a prompt you paste into Claude Code, Cursor, Codex, or Windsurf against your real codebase. It checks for exposed secrets, missing security headers, SQL injection risks, missing rate limits, and outdated dependencies, and hands back a prioritized report. If you're not the one who touches code, the questionnaire generates a ready-to-send message for whoever is.

Dashboard checks — six settings that live inside your actual provider accounts (hosting, database, domain registrar, admin team list) with illustrated walkthroughs and copy-paste SQL where it applies. This is the part that catches the boring stuff that actually takes small businesses down: a hosting account with no two-factor authentication is the kind of finding the audit surfaces in minutes, and it's worth fixing that day, not filing for later — a hardware security key on any account with admin access closes that gap for good instead of relying on a code that can be phished out of you.

There's also a vendor questionnaire template with pre-written, honest answers for the next time a customer sends you one of those 25-question forms, and a panic-mode section — five actions in about 15 minutes — for the day something's already gone wrong and you need to stabilize before you audit anything.

Small and medium businesses aren't a hypothetical target here, either: they took roughly four times more confirmed data breaches than large organizations last year, and ransomware or extortion showed up in 88% of those SMB breaches — more than double the rate at large companies — according to Verizon's 2025 Data Breach Investigations Report. Bigger companies have security teams absorbing that risk. Most small businesses have one person, and that person is usually also doing the books.

Who this isn't for

If you need SOC 2 Type II certification, this doesn't replace an actual auditor. If you handle regulated data at real scale, or you're past the "we should probably check this" stage and into "we need a compliance consultant," the Kit is a starting point, not the finish line. And it doesn't write legal documents — it'll flag that a topic is worth raising with an attorney, but the actual policy language still needs a professional who knows your jurisdiction.

If none of the three moments above sound familiar yet — you're one person, no employees or contractors with system access, nobody's asked you a security question yet — you probably don't need this today. That's fine. It'll still be there when someone does ask.

What it costs

$69, once. No subscription. That includes 12 months of free updates, so when a provider renames a settings menu or a new check becomes relevant, the bundle updates with it. After 12 months, the version you already own keeps working whether or not you renew.

One thing worth being direct about: this is a separate product from Cautellus Plus, the $9.99/month scam-scanning subscription. Buying the Kit doesn't unlock scanner access, and subscribing to Plus doesn't include the Kit. They solve different problems — one checks whether the message in front of you is a scam, the other checks whether your own business is the easy target.

Got something like this in your inbox? Drop it into the scanner — it takes 5 seconds and could save you thousands.

Check it now →

FAQ

Will buying the Security Audit Kit give me Cautellus Plus or scanner access? No. The Kit and the scam scanner are two separate products on the same account. The Kit is a one-time $69 purchase that audits your business's own security setup. Plus ($9.99/month) is the ongoing scam-scanning subscription for texts, links, emails, and screenshots. Buying one doesn't unlock the other.

Will this replace a real penetration test? No, and it's not trying to. A real pentest costs $5,000 to $50,000 and pays a human to actively try to break into your systems. The Kit finds the common, boring gaps — no 2FA on hosting, an old contractor who still has admin access, a leaked API key — before a pentester would even start billing you for them. If you handle regulated data or serve large enterprise customers, you still need the real thing eventually.

I'm not technical. Can I actually use this myself? Most of it, yes. The business questionnaire, the dashboard checks, and the vendor questionnaire response are all browser-based with plain-English instructions — no terminal required. The one technical piece, the AI code scan, generates a one-click message you can hand straight to your developer while you run the other three yourself.

Is $69 the real price, or is there a subscription hiding somewhere? $69 once. No subscription, no recurring charge. That covers 12 months of free updates to the kit's contents; after that, renewal is optional and the version you already have keeps working either way.

What if I've already been hacked — is this still useful, or is it too late? The Kit includes a panic-mode section built for exactly that: five actions in about 15 minutes covering roughly 80% of immediate exposure — email, domain, access revocation, financial alerts, who to notify. Run that first, then come back to the full audit once things are stable.

How is this different from a free security checklist template? A generic checklist asks you the same 200 questions regardless of what your business actually does. The Kit's business questionnaire adapts to your industry, what data you collect, and your team size, so you're only looking at the items that apply to you — plus an AI scan that runs against your actual codebase instead of asking you to guess.

Most small businesses don't get breached because they were careless. They get breached because nobody ever sat down and checked — and by the time someone asks, it's usually a customer, not a choice.

Think you've been targeted? Paste any text, link, email, or screenshot into Cautellus for instant AI analysis.

Check something now →
C

Courtney

Founder, Cautellus · 20+ years in financial services

Two decades in financial compliance, digital security, and fraud prevention. Built Cautellus because the scam detection tools that exist were made for IT departments, not for real people getting weird texts.

Learn more

Support Our Mission

Cautellus is built to protect people from online fraud. Your contribution helps us keep building security tools and resources.

Found This Helpful?

Try Cautellus to check suspicious messages, links, and images against known scam patterns before you trust them.

Try the Scam Scanner