← All insights

Practical checklist or tool

The 40-Minute Cybersecurity Evidence Check for a Central Florida Office

A focused worksheet for owners and office managers to verify access, backups, incident contacts, and software maintenance without needing a technical audit.

Central Florida veterinary practice team completing a timed cybersecurity evidence check

Use this as a management check, not a certification

This 40-minute review is designed for a small Central Florida office that needs a useful picture of its current cybersecurity condition. It is not a penetration test, compliance audit, legal opinion, or guarantee of security. Its purpose is to replace assumptions with evidence.

Set a timer, invite the person who manages technology, and record the date, reviewer, systems examined, evidence found, and unresolved items. If a question cannot be answered, mark it “unknown” rather than guessing.

Minutes 0–5: identify the business-critical systems

Write down the systems the office would struggle to operate without:

  • Email and calendars.
  • Accounting, payroll, scheduling, or practice-management software.
  • File storage and collaboration tools.
  • Payment, banking, or payroll portals.
  • Customer, patient, client, employee, or contract databases.
  • Internet, phones, and remote-access services.
  • Backup and recovery platforms.

For each system, record the owner, administrator, vendor, support contact, and recovery method. If no one knows who owns a system, create an action item immediately.

Evidence to collect: current inventory, vendor list, administrator list, and contracts or service summaries.

Minutes 5–15: verify access controls

Answer yes, no, or unknown:

  • Is multifactor authentication enabled for email?
  • Is it enabled for administrator accounts?
  • Is it enabled for banking, payroll, payment, and remote-access services?
  • Are former employees removed from active accounts?
  • Are shared accounts avoided or documented with a specific business reason?
  • Are administrator privileges limited to people who need them?
  • Are recovery email addresses and phone numbers current?
  • Does someone review sign-in alerts or account-security notifications?
  • Can the office disable a compromised account quickly?

CISA recommends multifactor authentication and encourages businesses to use phishing-resistant methods where available. If the strongest method is not yet practical, document the current method, the limitation, and the next upgrade step.

Evidence to collect: account-security exports, screenshots of settings, access-review records, and a list of accounts disabled during the last staffing change.

Do not place passwords or recovery codes in this worksheet.

Minutes 15–23: examine backup evidence

Ask the backup administrator to show:

  • The systems and data included in backups.
  • The date and result of the last successful backup.
  • Whether backup copies are separated from ordinary user access.
  • Who can delete or alter backup data.
  • The retention period.
  • The expected restoration sequence.
  • The last successful test restoration.
  • The contact who can help if the backup console is unavailable.

A green dashboard is not proof that the business can recover. Select one ordinary file and one important business record for a test restoration, using an approved and non-production location. Record whether the restored files opened correctly and whether permissions, names, and dates were preserved.

Evidence to collect: backup job result, retention setting, restoration record, and a list of missing systems or exclusions.

If the office has no restoration test, mark recovery as unverified.

Minutes 23–29: check software and device maintenance

Review whether:

  • Business laptops and desktops receive operating-system updates.
  • Browsers and commonly used applications are maintained.
  • Routers, firewalls, and wireless access points are supported and updated.
  • Endpoint security is active and reporting.
  • Unsupported devices or software are documented.
  • Employees can install unapproved applications without review.
  • Lost or stolen devices can be locked, wiped, or disabled.

The FTC advises small businesses to update security software, use encryption where appropriate, limit access to sensitive information, and protect networks with current security practices.

Evidence to collect: device-management report, update status, endpoint-security status, and list of unsupported equipment.

If the office cannot obtain a report, ask the provider what is monitored and how exceptions are handled.

Minutes 29–34: verify the incident route

Write the answer to each question in one sentence:

  • Who is called first if email is compromised?
  • Who can isolate an infected device?
  • Who contacts the bank about suspected payment fraud?
  • Who contacts the IT provider after hours?
  • Who contacts cyber insurance?
  • Who preserves evidence?
  • Who coordinates with legal counsel?
  • Where is the current employee and vendor contact list stored if cloud systems are unavailable?

The FTC recommends mobilizing a breach-response team quickly and securing operations before continuing normal work. The office should not wait for an incident to discover that its only administrator is on vacation or that its emergency phone number is stored in the inaccessible email account.

Evidence to collect: incident contact card, insurance instructions, vendor escalation path, and offline copy of essential contacts.

Minutes 34–38: inspect payment and vendor verification

Confirm that the office has a rule requiring independent verification for:

  • Changes to bank details.
  • Urgent wire or ACH requests.
  • New payroll instructions.
  • Requests for gift cards or unusual purchases.
  • Vendor remote-access changes.
  • Requests to disclose passwords, codes, or sensitive files.

Verification should use a known phone number or separate communication channel, not the contact information in the unexpected message.

Evidence to collect: written payment-change procedure, approval record, and vendor-access list.

Minutes 38–40: assign the next three actions

Choose no more than three actions. Assign one owner and one due date to each.

Prioritize:

  • An administrator or banking account without MFA.
  • A former employee with active access.
  • Backups that have never been restored.
  • An unsupported internet-facing device.
  • No after-hours incident contact.
  • A payment process based only on email.
  • Sensitive data stored in an unknown location.

Record the issue, business consequence, owner, due date, and evidence required for closure. A task is not complete because someone says it was fixed; it is complete when the office can show the relevant setting, report, test result, or approved record.

Review result

Use one of four ratings for each section:

  • Verified: evidence was reviewed and the control operated as expected.
  • Partially verified: the control exists but has gaps or exceptions.
  • Unknown: the office could not obtain reliable evidence.
  • Not applicable: the item does not apply, with a written reason.

NIST’s CSF 2.0 Small Business Quick-Start Guide supports this evidence-oriented approach by helping smaller organizations understand and prioritize cybersecurity risk. It does not require every office to implement identical controls.

Final caution

This worksheet cannot determine whether your office satisfies HIPAA, financial, contractual, insurance, or Florida legal requirements. It also cannot establish that a provider performed adequate technical work. Use it as a management conversation starter and retain the results as a human-reviewed draft record.

Repeat the check after major staffing, software, banking, vendor, or network changes, and at least periodically. The value is not the score. The value is knowing which important decisions are supported by evidence and which still depend on assumptions.

Sources