← All insights

Practical checklist or tool

The 35-Minute Office Security Verification Worksheet

A compact review tool for checking the accounts, devices, backups, vendors, and response contacts that determine whether a small office is prepared for ordinary security problems.

U.S. school administrator and IT technician performing a timed office security walkthrough

How to use this worksheet

Set a timer for 35 minutes. Include the owner or office manager and the person who handles technology, whether that is an employee, consultant, or managed service provider. The purpose is not to conduct a technical audit. It is to identify unanswered questions that could slow the office during a compromise, payment scam, lost device, or outage.

For each item, mark:

  • Yes: verified with current evidence.
  • No: the control is absent or inadequate.
  • Unknown: nobody can verify it during the review.
  • Not applicable: document why it does not apply.

Unknown is not a failure of honesty. It is a risk that needs an owner.

Minutes 0–5: Identify the decision-makers

  • Is one person responsible for approving cybersecurity priorities?
  • Is there a current IT, security, insurance, and legal contact list?
  • Is there a non-email way to reach those contacts?
  • Does someone have authority to disable an account quickly?
  • Does someone know who can contact the bank about suspected payment fraud?

Save the contact list outside the primary email system. A compromised mailbox may not be a reliable place to retrieve emergency instructions.

Minutes 5–12: Check high-impact accounts

Review administrator and financial-access accounts first.

  • Is multi-factor authentication enabled for email administrators?
  • Is MFA enabled for banking, payroll, payment, and accounting portals?
  • Are backup and security consoles protected by MFA?
  • Are administrator credentials unique rather than shared?
  • Are former employees and inactive contractors removed?
  • Does each administrator have a named owner?
  • Are recovery methods current and controlled by the business?

The FTC recommends MFA for access to sensitive information and emphasizes strong, unique passwords, regular updates, access controls, and staff training. ([ftc.gov](https://www.ftc.gov/business-guidance/small-businesses/cybersecurity?utm_source=openai))

If the answer is “MFA is available but not enforced,” mark the item No. Availability is not the same as protection.

Minutes 12–18: Check devices and software

Select three representative devices: an owner or manager laptop, a general staff device, and any device used for sensitive records.

  • Is the operating system supported and receiving security updates?
  • Is automatic updating enabled where appropriate?
  • Is full-disk encryption enabled on laptops and mobile devices that store sensitive data?
  • Is screen locking required?
  • Are lost or stolen devices reported through a known process?
  • Are unsupported applications or remote-access tools identified?
  • Are business and guest wireless networks separated?

NIST’s small-business guidance specifically includes maintaining inventories and prioritizing protections such as device encryption and access controls. ([nvlpubs.nist.gov](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1300.pdf?utm_source=openai))

Do not guess based on a device’s age or appearance. Verify through the operating system, management console, or service provider.

Minutes 18–24: Test the backup story

Ask the person responsible for backups to show evidence, not just a dashboard label.

  • What systems and files are included?
  • When was the last successful backup?
  • Are failures reviewed by a named person?
  • Is at least one recovery copy protected from ordinary network compromise?
  • Can the office restore a representative file?
  • Who can access the backup console if the main administrator is unavailable?
  • How would employees work if the primary application were offline?

The FTC advises businesses to back up important files regularly and maintain a plan for keeping the business operating after ransomware or another incident. ([ftc.gov](https://www.ftc.gov/business-guidance/small-businesses/cybersecurity?utm_source=openai))

A successful backup job is not proof of a successful recovery. Record the date and result of the latest restoration test.

Minutes 24–29: Review vendors and remote access

List vendors that can access systems, data, payment processes, or facilities.

  • Does each vendor have a specific business purpose?
  • Is access limited to the systems and time required?
  • Does remote access require MFA?
  • Are vendor accounts individually identifiable?
  • Does the contract address data protection and incident notification?
  • Is there a process to remove access when the engagement ends?

The FTC recommends putting security expectations in writing, verifying vendor practices, limiting access, and requiring MFA for vendors with network access. ([ftc.gov](https://www.ftc.gov/business-guidance/blog/2018/12/cybersecurity-small-business-vendor-security?utm_source=openai))

If a vendor says access is “temporary,” ask who will close it and when.

Minutes 29–33: Review response readiness

  • Does staff know how to report a suspicious message?
  • Is there a separate channel for urgent technology incidents?
  • Does the office know who can isolate a device or disable an account?
  • Are bank-fraud instructions written down?
  • Is the cyber-insurance reporting process known?
  • Has the office identified any legal, contractual, or regulatory notification duties that may apply?

Do not promise a notification timeline unless qualified legal or regulatory guidance confirms it. Record the need for professional advice as an action item when appropriate.

Minutes 33–35: Assign the next three actions

Choose no more than three immediate actions. For each, record:

  • The risk addressed.
  • The responsible person.
  • The due date.
  • The evidence that will show completion.
  • Any dependency on a vendor or specialist.

Examples include enforcing MFA on administrators, restoring a test file, removing a former contractor’s access, updating emergency contacts, or replacing unsupported software.

Interpreting the result

A worksheet with many Yes answers may still miss sophisticated risks. A worksheet with several Unknown answers does not prove an incident is occurring. It shows where management lacks visibility. CISA and NIST both present small-business guidance as a starting point for improving risk management, not as a certification or guarantee. ([cisa.gov](https://www.cisa.gov/small-and-medium-sized-business-resources?utm_source=openai))

Repeat the worksheet quarterly and after major changes such as a new payroll provider, office move, cloud migration, acquisition, or staff turnover. Keep prior versions so the business can see whether open questions are actually closing.

Human-reviewed draft. This worksheet is a management aid, not a substitute for professional technical, legal, regulatory, insurance, or incident-response advice.

Sources