As a Michigan business owner do you know when your risk-assessment duties should begin? You may wonder if it's after hiring your fifth, tenth, or fiftieth employee. However, exposure, legal obligations, and contractual requirements matter more than just a general headcount.
A risk matrix can help even a one-person company prioritize threats. Managed IT records can provide evidence about devices, accounts, and controls.
In this guide, we’ll separate workplace safety from cybersecurity. We’ll also explain when and how a risk assessment should be completed. Keep reading to learn more.
Key Takeaways
Employee count can create administrative or documentation requirements under particular rules. However, it is not a reliable measure of risk.
Your company can begin an assessment by looking at a variety of factors. These may include data, workplace hazards, operational technology, customer obligations, insurance, vendors, and planned operational changes.
The NIST Cybersecurity Framework provides a useful structure for identifying, protecting, detecting, responding to, and recovering from cyber risks. Businesses can adapt that structure to their size without assuming that a small workforce permits weak controls.
WaTech’s live helpdesk provides instant access to local, in-house experts. They can help surface recurring incidents, account problems, and equipment weaknesses.
The Short Answer: There Is No Universal Employee Threshold
A risk assessment can be necessary even when a business only has one employee. This is because employer responsibility begins with recognizing and addressing applicable risks. For example, Michigan’s PPE rule requires employers to assess the workplace for hazards that require PPE and certify the assessment in writing,.
A workplace risk assessment focuses on physical and operating hazards. Alternatively, a cybersecurity risk assessment examines data, systems, access, disruption, and business continuity.
Employee-count thresholds can change documentation or recordkeeping obligations under particular laws. However, they do not make a known hazard irrelevant. Effective hazard identification should lead to reasonable safeguards. These can include safer procedures, multi-factor authentication, recovery processes, or other controls proportionate to the exposure.
Cybersecurity Risk Assessments Are Not Usually Based On Numbers
A two-person organization handling patient information, payment data, confidential files, or controlled equipment can suffer material financial and harm from unauthorized access. Its assessment should examine control measures such as endpoint protection, secure backups, account management, and incident recovery.
Cloud adoption, remote hiring, a new location, a major customer, or a security incident should trigger a reassessment. Each change creates new access paths or dependencies that can alter risk significantly.
What Can Trigger a Risk Assessment for Your Business?
Four categories commonly trigger assessment: legal and regulatory obligations, customer contracts, insurer requirements, and practical business exposure. A customer security questionnaire, renewal application, audit request, or vendor agreement may demand documented review before a statute expressly requires it.
Regulated data, safety-sensitive work, third-party access, and dependence on technology increase the value of formal review. Patch management, for example, can become a business risk issue. This happens when delayed updates could interrupt revenue, expose records, or disable essential equipment.
Technology scope can also broaden the assessment. Comprehensive IT services including managed IT, VoIP phone service, structured cabling, and white label IT solutions may create different assets. These assets, vendors, or access routes must be documented individually.
Legal and Industry Requirements
The HIPAA Security Rule requires covered entities and business associates to perform an accurate and thorough risk analysis. This review should include potential risks and weaknesses to the ePHI they create, receive, maintain, or transmit. PCI DSS applies to organizations that store, process, or transmit payment card data. This makes data flow and payment-system scope more important than just the number of employees your business has.
MIOSHA and OSHA obligations are hazard-specific and sometimes industry-specific. OSHA’s hazard identification guidance emphasizes collecting information, investigating incidents, identifying hazards, and taking corrective action.
Contracts and Cyber Insurance
Larger customers commonly request evidence of risk management, vendor risk management, security controls, and an incident response plan. In a 2024 survey, 80% of respondents required a security or privacy assessment for software vendors. Additionally, 81% considered a vendor’s security-incident history when evaluating software solutions.
Cyber insurance applications often ask about MFA, data backups, endpoint defenses, employee training, and previous assessments. Current cyber insurance guidance identifies MFA, tested backups, endpoint protection, and security awareness training as core carrier controls.
Use This Test To Determine Your Needs
A Michigan business should begin an assessment right away if they feel that a significant event could cause harm. This could include someone getting injured, exposed sensitive information, disruption of essential work, or the breaching a contract. One “yes” involving a high-impact exposure is enough to justify a review.
Questions That Signal an Immediate Need for Assessment
Ask these questions when deciding whether to act:
Do you handle protected health information, electronic protected health information, payment details, financial records, employee personal data, or confidential client files?
Do employees use cloud applications, email, mobile devices, shared credentials, or remote access?
Do vendors have administrative access or ongoing access to business systems and data?
Has a customer, insurer, lender, regulator, or business partner requested security documentation?
Would poor access control allow one compromised account to expose multiple systems?
Could equipment failure, unsafe conduct, or a technology outage stop operations or harm someone?
A positive answer indicates an identifiable exposure that deserves evaluation. Multiple “yes” answers usually justify a broader assessment spanning people, process, technology, and physical safeguards.
When a Lighter Review May Be Relevant
An assessment of a small, low-risk business may start with a documented review. Companies should review their devices, accounts, backups, physical security, administrative access, and essential vendors. This limited approach remains useful only if findings produce specific corrective actions.
The review should expand if the organization adds additional employees, locations, connected equipment, sensitive data, cloud systems, or contractual duties. Growth changes both the likelihood of failure and the potential impact.
How to Complete a Useful Risk Assessment
An effective assessment follows a repeatable sequence. This includes defining the scope, inventory assets, identifying threats, reviewing existing controls, ranking gaps, assigning corrective actions, and scheduling review.
For each significant finding, record the risk owner, action, due date, evidence, and reason. A simple likelihood-and-impact scale can separate urgent risks from lower-priority improvements.
Identify Assets, Data, Hazards, and Threats
Inventory critical systems, network equipment, devices, user accounts, business data, physical work areas, workflows, and third-party providers. An incomplete inventory produces an incomplete assessment. Unknown assets cannot be protected or recovered.
Relevant threats may include phishing, ransomware, unauthorized entry, unsafe work practices, equipment failure, fire, theft, and vendor outages. Each threat should be linked to a specific asset or process.
Evaluate Controls and Prioritize Improvements
Review least-privilege permissions, software updates, tested backups, endpoint security, training, network segmentation, physical safeguards, and written procedures. Evidence such as configuration reports and recovery-test results is more reliable than verbal assurance.
Address high-likelihood or high-impact gaps first, then assign an accountable owner and realistic completion date. A risk matrix supports prioritization, but a competent person in leadership must still consider regulatory, contractual, and human consequences.
Review After Implementing Changes
Reassess at least annually for residual risk and after any material changes to systems, staffing, locations, vendors, workflows, regulations, or customer requirements. Update your findings after an injury, phishing event, or security incident. These events provide direct evidence that previous assumptions or safeguards may no longer be reliable.
Examples for Growing Michigan Businesses
The number of employees your business has can't distinguish a low-exposure office from a highly connected production site or healthcare practice. The following scenarios are starting points because each group's legal duties, contracts, technology, and hazards differ.
Medical and Healthcare Organizations
A small clinic handling electronic protected health information may require a HIPAA security risk review. This can be true whether it employs five people or 50. Relevant areas include electronic health record access, shared workstations, email protection, backups, lost-device procedures, and business-associate access.
The clinic should trace where patient information enters, travels, rests, and leaves the organization. That data-flow analysis reveals risks that an employee count cannot measure.
Industrial and Manufacturing Organizations
A manufacturer may require both workplace safety and cybersecurity reviews when machinery, technology, remote vendor access, or connected facilities are present. The combined assessment should address machine hazards, privileged accounts, network segmentation, downtime exposure, and recovery procedures.
Technology for operations often has different patching and availability constraints from office computers. Consequently, engineering, safety, production, and IT personnel should coordinate control changes.
Professional Services Organizations
A law firm, accounting firm, or consultancy may have few employees. However, they may still retain valuable client records and receive detailed security questionnaires. Its review should examine cloud-storage permissions, email compromise, remote work, data retention, secure disposal, and access to client portals.
Minimize Risk For Your Michigan Business
Risk assessments are essential for workplace safety. Even for small or single person companies, they can be valuable. When you work with experienced experts like WaTech, you'll have peace of mind and security knowing that your data is safe and secure at all times. Set up a complimentary 15 minute discovery call with our team today to learn how we can keep your business safe online.
Frequently Asked Questions
1. What Is Risk Assessment as per OSHA?
OSHA does not impose one universal risk-assessment rule on every employer. Its standards require employers to identify and control applicable workplace hazards, with specific assessment duties varying by hazard, activity, and industry.
2. Can Anybody Do a Risk Assessment?
A staff member can contribute if that person understands the relevant work and risks. The employer remains responsible, while complex safety, cybersecurity, or compliance issues may require specialist input.
3. Who Is Legally Responsible for a Risk Assessment?
The employer or business leadership is responsible for ensuring an appropriate assessment is completed. They should ensure it's documented where required, and followed by reasonable corrective action. Exact legal duties depend on the jurisdiction and applicable standard.
4. Can Any Staff Member Complete a Risk Assessment?
Any employee may provide observations and evidence, but someone competent should lead or review the assessment. That reviewer must be capable of evaluating the relevant hazards, systems, controls, and regulatory requirements.