← All insights

Practical checklist or tool

The 30-Minute Evidence Check for a Small Office

A short review tool for office managers who need to find practical gaps and produce evidence without pretending that a checklist is a full security assessment.

Office manager completing a timed cybersecurity evidence checklist beside a laptop

A checklist is valuable when it leads to evidence and a decision. It is not valuable when staff mark “yes” because a product exists somewhere in the environment. This 30-minute review is designed for a small Central Florida office that needs a fast, repeatable way to identify obvious gaps in accounts, devices, email, backups, and response readiness.

The review is based on recurring recommendations from CISA, NIST, and the FTC. It is not a penetration test, compliance determination, forensic investigation, or guarantee of security. If the office finds signs of compromise, stop the review and escalate to the appropriate technical and legal contacts.

Before starting

Assign one reviewer and one person who can answer technical questions. Gather access to the Microsoft 365 or other identity administration portal, endpoint-management console, backup reports, vendor contracts, and incident contacts. Do not change settings during the first pass unless there is an urgent, known exposure.

Record the date, reviewer, systems reviewed, evidence location, and unanswered questions. A blank or unknown answer is useful information.

Minutes 0–5: Critical accounts

Check whether the office has:

  • A list of administrators and privileged users.
  • Separate administrator accounts rather than daily-use admin accounts.
  • Multifactor authentication enabled for administrators and remote access.
  • A documented process for removing former employees and vendors.
  • A current emergency contact who can recover the tenant or key systems.

Evidence may include an exported user list, access-review record, policy screenshot, or ticket showing an offboarding action. Do not store recovery codes or secrets in the checklist itself.

NIST identifies identity and access management as part of the outcomes organizations should consider when managing cybersecurity risk. Microsoft also recommends stronger, phishing-resistant authentication for privileged identities where practical. See https://www.nist.gov/itl/smallbusinesscyber/nist-cybersecurity-framework-0 and https://learn.microsoft.com/en-us/entra/fundamentals/zero-trust-protect-identities.

Minutes 5–10: Devices and updates

Select three business devices or review the management console. Confirm:

  • The operating system is supported and receiving updates.
  • Endpoint protection is active.
  • Disk encryption is enabled where appropriate.
  • Screen lock and device passwords are required.
  • Local administrator rights are limited.
  • Lost or stolen devices can be remotely locked or wiped where appropriate.

Record the device name, last check-in, update status, and exception owner. “The vendor handles it” is not evidence unless the business can see a report or contract obligation describing what is handled.

Minutes 10–15: Email and business fraud controls

Review whether the business has:

  • Multifactor authentication for email accounts.
  • A process for reporting suspicious messages.
  • External sender indicators or equivalent warnings.
  • Rules for verifying payment, payroll, and bank-detail changes using a second channel.
  • Email authentication records such as SPF, DKIM, and DMARC where applicable.

The FTC recommends email authentication and verification practices for small businesses. See https://www.ftc.gov/business-guidance/small-businesses/cybersecurity.

Check for unexpected forwarding rules, mailbox delegates, inbox rules, and recently added authentication methods. These findings do not prove compromise, but they deserve investigation when the owner or user cannot explain them.

Minutes 15–20: Backups and recovery

Ask five questions:

  • What data and systems are backed up?
  • How often do jobs run?
  • Are backups protected from ordinary administrator access?
  • When was the last successful restore test?
  • Who can restore systems if the usual administrator is unavailable?

Save the backup report and a restoration-test record. A green backup status is not the same as a usable recovery capability. CISA recommends offline or otherwise protected backups and regular testing of availability and integrity. See https://www.cisa.gov/stopransomware/ransomware-guide.

Minutes 20–25: Vendors and remote access

List vendors with access to systems or sensitive information. For each, record:

  • Business owner.
  • Systems reached.
  • Named accounts or service accounts used.
  • Multifactor authentication status.
  • Approval and termination process.
  • Contract language covering security, breach notice, data handling, and return or deletion.

The FTC advises businesses to put security expectations in writing, verify compliance, limit vendor access, and use multifactor authentication. See https://www.ftc.gov/business-guidance/small-businesses/cybersecurity.

Minutes 25–30: Response readiness

Confirm that the office has a current list of contacts for:

  • Technology provider or managed service provider.
  • Cyber insurer and breach hotline.
  • Attorney or privacy counsel.
  • Bank and payment processor.
  • Executive decision-maker.
  • Law enforcement and reporting channels.

Then ask staff one scenario: “What would you do if the owner received a request to send funds to a new account?” A useful answer includes stopping, not replying through the same channel, and independently verifying the request.

Scoring without false precision

Do not convert this review into a maturity score unless the business has defined what the score means. Instead, classify each item:

  • Confirmed: evidence was reviewed and is current.
  • Partially confirmed: a control exists but scope or ownership is unclear.
  • Unknown: evidence was not available.
  • Exception: a known gap has an owner and due date.

The most urgent items are usually unknown administrator access, absent multifactor authentication, unsupported devices, untested backups, and unplanned vendor access. Priority still depends on the systems and data involved.

What this tool cannot prove

This check cannot determine whether malware is present, whether a provider is competent, whether a business satisfies HIPAA or another obligation, or whether an attacker has already used stolen credentials. It is a management tool for finding questions that need answers.

Repeat the review quarterly and after a major hire, departure, software change, acquisition, office move, or security incident. Keep the evidence file dated. Over time, the file should show not only that the office reviewed controls, but also whether unresolved issues were actually closed.

Sources