How to use this tool
Set a timer for 30 minutes. Include the owner or office manager, the person responsible for technology, and—if available—the outside IT provider. The purpose is not to pass or fail an audit. It is to discover which answers are known, which are assumed, and which have no evidence behind them.
For every question, mark one response:
- Yes, with evidence
- Partly or inconsistently
- No or unknown
Write down the evidence location and assign an owner for every “partly,” “no,” or “unknown” answer.
Minutes 0–5: Define the operating impact
1. What three business activities must continue during a technology outage?
2. Which systems support those activities?
3. Who can authorize an emergency change or temporary workaround?
4. What is the maximum tolerable time for each critical activity to be unavailable?
5. Which customers, patients, clients, vendors, or employees would need an update?
Do not answer with “everything is important.” Rank the work. A small office may be able to operate with email unavailable for a few hours but may not be able to process payroll, schedule appointments, ship orders, or access essential records.
Minutes 5–10: Check identity and access
6. Is multifactor authentication enabled for email, remote access, file storage, banking, and administrator accounts?
7. Are administrator accounts separate from everyday work accounts?
8. Can a departing employee’s access be disabled quickly across major systems?
9. Are shared accounts documented and necessary?
10. Are emergency or recovery accounts controlled, tested, and recorded somewhere outside the affected platform?
CISA recommends requiring MFA wherever possible and prioritizing administrators, sensitive-data users, email, file storage, and remote access. The evidence should be a current settings report or documented review—not simply a provider’s statement that MFA is “available.”
Minutes 10–15: Test backup assumptions
11. What data is backed up?
12. Are cloud files, email, databases, configurations, and critical applications included where needed?
13. Can an attacker using an ordinary administrator account delete or encrypt the backups?
14. When was the last successful restore test?
15. How long did the restore take, and what failed?
16. Who can perform the restore if the usual technology contact is unavailable?
The FTC advises businesses to back up important files and a full backup of the environment to storage that is not connected to the network. The practical test is whether the business can restore useful work, not whether a dashboard shows a green status indicator.
Choose one realistic test: restore a folder, export a set of records, or rebuild a small nonproduction system. Record the date, scope, duration, person performing the test, and any missing permissions or data.
Minutes 15–20: Review detection and first response
17. Who receives alerts for suspicious sign-ins, new administrator accounts, mailbox forwarding rules, or mass file changes?
18. Is there a monitored security log, or are alerts merely stored?
19. What is the first action if ransomware is suspected?
20. Who can isolate a device or disable a compromised account?
21. Where are incident contacts stored if email is unavailable?
The FTC recommends disconnecting affected devices from the network without powering them down when responding to a suspected ransomware incident. A business should confirm that its provider understands this distinction and has a documented process for preserving information needed for investigation.
Create an offline contact card containing the owner, IT provider, cyber-insurance contact if applicable, bank fraud department, legal contact, relevant vendors, local law-enforcement contact, and the FBI’s Internet Crime Complaint Center reporting route.
Minutes 20–25: Check continuity decisions
22. What can staff do manually for one business day?
23. Which forms, phone numbers, schedules, customer lists, or payment instructions must be available offline?
24. Which system should be restored first?
25. How will the business verify that restored data is accurate and free of unauthorized changes?
26. Who communicates with employees, customers, vendors, and regulators if required?
Keep offline materials limited to what is necessary and protect them from unauthorized access. Do not print large amounts of sensitive information without a retention and destruction plan.
Minutes 25–30: Convert gaps into a 30-day plan
27. What is the single most dangerous unknown discovered today?
28. What can be corrected within seven days?
29. What requires a provider, vendor, attorney, insurer, or specialist?
30. What evidence will prove the work is complete?
Use this simple action format:
- Gap: Backup restoration has not been tested.
- Owner: Technology provider and office manager.
- Action: Restore one critical folder to a separate location.
- Due date: Within 14 days.
- Evidence: Restore log, file verification, and lessons learned.
What a useful result looks like
A strong result is not a perfect score. It is a short list of verified strengths and clearly owned gaps. If the office discovers that no one knows who can disable a compromised administrator account, that finding is valuable. If a backup has never been restored, the test result is more important than a reassuring vendor presentation.
Repeat the interview after major technology changes, staff departures, new vendors, acquisitions, or incidents. Keep the completed worksheet with other security evidence, but do not place passwords, recovery codes, or sensitive secrets in the worksheet itself.
Human-reviewed draft; adapt the questions to the office’s systems, contracts, insurance requirements, and legal obligations before publication.

