Use the checklist as a conversation starter
A short review cannot prove that an office is secure. It can reveal obvious gaps and create a prioritized list for the person responsible for technology. Run this checkup monthly for high-risk items and quarterly for the full list. Record the date, reviewer, finding, owner, and due date for every open item.
Accounts and identity
- Is multifactor authentication enabled for every Microsoft 365, Google Workspace, banking, payroll, accounting, payment, and remote-access account?
- Are former employees, contractors, and temporary workers disabled promptly?
- Does every person have an individual account rather than sharing credentials?
- Are administrator accounts separate from ordinary daily-use accounts?
- Are there any unknown global administrators, mailbox delegates, forwarding rules, or application consents?
- Do employees know never to approve an unexpected MFA prompt?
If an account appears suspicious, do not simply delete evidence. Preserve sign-in details and contact the responsible IT or security provider. Review recent activity, reset credentials through a trusted process, revoke active sessions, and check for persistence such as forwarding rules or newly registered devices.
Devices and software
- Are operating systems and applications supported by their vendors?
- Are automatic security updates enabled where practical?
- Is endpoint protection installed, active, and reporting on every company-managed computer?
- Are laptops encrypted and protected by screen locks?
- Are unknown remote-support tools or browser extensions installed?
- Are USB devices and personal computers restricted from sensitive work?
- Are old devices securely wiped before disposal, resale, or return?
Make a list of exceptions. An unsupported computer that remains connected because it runs a specialized program is not a mystery; it is a documented risk requiring a replacement or containment plan.
Email and payment processes
- Does the business use anti-spam and malware filtering?
- Are SPF, DKIM, and DMARC configured for company domains?
- Are external messages clearly identified without creating a false sense of safety?
- Must employees verify bank-account changes by calling a known number?
- Are wire transfers and large payments subject to a second-person review?
- Can employees report suspicious messages with one clear method?
Email authentication reduces impersonation risk but does not make every message trustworthy. A compromised legitimate account can send a real-looking message. Verification procedures remain important.
Network and physical office
- Is guest Wi-Fi separate from business systems?
- Have default router, firewall, printer, camera, and wireless passwords been changed?
- Is remote administration restricted and logged?
- Are unused services and ports disabled?
- Are network devices and servers located in a controlled area?
- Are paper records, backup drives, and replacement equipment secured?
- Are printers and copiers configured so stored documents are protected or erased before disposal?
Small offices often overlook printers, phones, cameras, and building systems because they are not viewed as computers. If a device connects to the network, it belongs in the inventory and should have an owner.
Backups and recovery
- What data is considered essential for the next business day?
- How often is it backed up?
- Is at least one backup isolated from routine network access?
- Are backup accounts protected with MFA and separate administrator credentials?
- Has the business restored a real file recently?
- Can the office operate if email, the internet, or a primary cloud service is unavailable?
- Are vendor contact details and license information available offline?
A backup job marked “successful” is not the same as a tested recovery. Restore a representative file, database, shared folder, and system configuration on a schedule.
People and response
- Have employees received recent training on phishing, payment fraud, lost devices, and reporting?
- Does the office know who can authorize an emergency shutdown?
- Is there a printed incident contact sheet?
- Does the cyber-insurance policy require specific controls or notification timelines?
- Has the business practiced a scenario involving a compromised mailbox or locked files?
Prioritize the results
Classify findings as urgent, important, or scheduled. Urgent items include a known compromised account, unsupported internet-facing device, missing backup, or unknown administrator. Important items include incomplete inventory, weak vendor access, and inadequate logging. Scheduled items may include documentation improvements and longer-term network redesign.
The checklist is most valuable when it produces ownership and deadlines. A business does not need to close every gap in one month. It should know which gaps exist, which ones matter most, and what action will reduce them.
Human-reviewed draft. Guidance is general information, not legal advice.

