What this tool is for
A short triage review cannot prove that an office is secure. It can identify obvious gaps, preserve useful facts, and help an owner decide what requires immediate attention. Use it after a leadership change, office move, software purchase, suspected incident, or before meeting with an IT provider.
The review should be performed with permission and without changing settings unless the responsible administrator approves. Record the date, reviewer, systems examined, and unanswered questions.
Part one: accounts and access
- Is multifactor authentication enabled for email, administrator accounts, payroll, banking, remote access, and backup consoles?
- Are former employees, temporary staff, vendors, and shared accounts still active?
- Does anyone use one password for multiple business systems?
- Are administrative accounts separate from ordinary email and web-browsing accounts?
- Is there a documented emergency recovery account controlled by more than one authorized person?
Evidence to collect: an access-review export or administrator list, the date of the last review, and a list of exceptions. Do not copy passwords into the worksheet.
Part two: devices and software
- Is there an inventory of laptops, desktops, servers, phones, network equipment, and cloud applications?
- Are operating systems and browsers receiving updates?
- Is endpoint protection active and reporting?
- Are unsupported devices or applications still connected?
- Are company records stored on unmanaged personal devices?
Evidence to collect: device-management inventory, patch status, endpoint status, and the owner for each unresolved device.
Part three: email and payment protection
- Can staff report suspicious messages through a known process?
- Are payment or bank-detail changes verified through a separate trusted channel?
- Are mailbox forwarding rules reviewed after a suspected compromise?
- Are high-risk actions protected by approval or dual control?
- Is the organization’s domain configured with appropriate email-authentication controls?
A suspicious message should not be judged solely by grammar. Attackers can imitate business language. The safer process is independent verification using a known phone number or established communication path.
Part four: backup and recovery
- What data is backed up?
- Where are backups stored?
- Are backup credentials separate from ordinary user accounts?
- Is at least one copy protected from routine modification or deletion?
- When was the last successful restoration test?
- How long would it take to restore the most important service?
Evidence to collect: backup job results, retention settings, restoration-test notes, and the person who can initiate recovery. A green backup dashboard does not demonstrate that a usable file or system can be restored.
Part five: response readiness
- Who is authorized to disable an account or disconnect a device?
- Who contacts the IT provider, insurer, attorney, bank, customers, and law enforcement?
- Where are emergency contacts stored if email is unavailable?
- Is there a written rule against paying or negotiating before proper investigation and approval?
- Has the team practiced a compromised mailbox or ransomware scenario?
Do not investigate a suspected compromise by deleting evidence or repeatedly logging into the affected account. Preserve relevant information and contact the designated responder.
Scoring and next actions
Mark each item as **confirmed**, **unknown**, **not applicable**, or **needs action**. “Unknown” is important: it identifies a management information gap rather than falsely suggesting that a control exists.
Prioritize findings using three questions:
- Could this gap enable unauthorized access to a critical system?
- Could it prevent or delay recovery?
- Could it create a legal, contractual, financial, or safety consequence?
Address high-impact unknowns first. For example, uncertainty about administrator access or backup recoverability usually deserves earlier attention than a cosmetic policy update.
How to preserve the record
Store the completed review where authorized managers can find it, restrict unnecessary access, and schedule a follow-up date. Include supporting screenshots or exports only when they do not expose secrets or sensitive personal information. Note who supplied each piece of evidence and whether it was independently verified.
The goal is not a perfect score. The goal is to convert vague concern into a short list of decisions, owners, and deadlines.
This article is a human-reviewed draft. It is a management tool, not a technical audit, penetration test, legal opinion, or compliance certification.

