← All insights

Practical checklist or tool

The 40-Minute Cybersecurity Resource Verification Worksheet

A timed worksheet for deciding whether a cybersecurity alert applies to your office, what to verify, and what evidence to retain.

Central Florida nonprofit staff verifying public cybersecurity resources with a timed worksheet.

Use the worksheet before forwarding an alert

A business owner or office manager may receive cybersecurity information from an IT provider, software vendor, employee, industry association, news story, or public agency. The message may be useful, but it may also be incomplete, outdated, exaggerated, or unrelated to the systems your office uses.

This 40-minute worksheet creates a repeatable way to move from alert to decision. It is not a vulnerability scan, legal opinion, incident investigation, or compliance certification. Its purpose is to prevent two common mistakes: ignoring a relevant warning and treating a general warning as proof of compromise.

Set a timer, open your current technology inventory, and create one decision record for the alert.

Minutes 0–5: capture the alert

Record the basics before clicking links or changing systems.

  • Date and time received:
  • Person or organization that sent it:
  • Original source URL:
  • Product, service, campaign, or behavior mentioned:
  • Claimed urgency:
  • Immediate action requested:
  • Person assigned to review:

If the message asks you to sign in, download a file, call a number, or send money, do not use the embedded instructions until the sender and destination are verified independently. Contact the provider through its known website, support portal, or previously documented phone number.

Minutes 5–12: classify the source

Place the source into one of three categories:

  • Primary authority: the affected vendor, CISA, NIST, FBI, FTC, FDLE, a regulator, or another official source.
  • Trusted secondary source: an industry association, managed service provider, insurer, or security company summarizing an original notice.
  • Unverified source: social media, forwarded email, anonymous post, or a message with no traceable source.

Primary sources should control technical and reporting decisions. A secondary summary may help explain the issue, but open the original advisory before deciding. An unverified source may be a lead only.

Record whether the item is current, updated, withdrawn, or archived. Public agencies and vendors sometimes retain older pages for reference, so the page date matters.

Minutes 12–20: compare the alert with your inventory

Look for an exact match, not a general resemblance.

  • Do we use the named product or service?
  • Which edition, subscription, version, or operating system do we use?
  • Is the affected feature enabled?
  • Is the system internet-facing or remotely accessible?
  • Which users, devices, locations, or vendors depend on it?
  • Does the vendor say the issue is exploited, exploitable, or only theoretical?
  • Is a patch, configuration change, workaround, or upgrade available?

Write down evidence such as a device-management report, provider statement, subscription page, version number, or administrator screenshot. Do not store unnecessary sensitive information in the worksheet.

A matching product does not automatically mean the business was compromised. Conversely, the absence of a matching product does not prove that the business is unaffected if the inventory is incomplete.

Minutes 20–27: determine the business consequence

Describe what could happen in business terms.

  • Could email, files, scheduling, billing, payroll, payment processing, or customer access be interrupted?
  • Could confidential, regulated, or personal information be exposed?
  • Could an attacker use the system to reach another vendor or customer?
  • Could the issue create a fraudulent payment or account-takeover risk?
  • What is the maximum acceptable delay before action?

Use three impact levels:

  • Immediate: isolate, disable, patch, or escalate now because exposure or active misuse is plausible.
  • Scheduled: assign a near-term action because the system is affected but no evidence of active compromise is known.
  • Monitor: document why the alert does not currently apply and identify what would change that conclusion.

Do not label an incident “confirmed” unless the evidence supports that conclusion. Use precise language such as “product appears affected; compromise not established” or “vendor confirms patch installed; no suspicious activity identified in available logs.”

Minutes 27–34: assign the action

Choose one or more actions and name an owner.

  • Patch or update the affected product.
  • Disable a vulnerable feature until it can be updated.
  • Require stronger authentication.
  • Review sign-in, endpoint, email, or firewall logs.
  • Reset credentials through a verified process.
  • Ask the vendor for written clarification.
  • Contact the managed service provider or security adviser.
  • Preserve relevant logs, messages, and timestamps.
  • Contact the bank immediately if a payment or account takeover may be involved.
  • Escalate to legal counsel, an insurer, law enforcement, or a regulator when the facts warrant it.

Write a deadline and the evidence that will close the task. “IT is looking into it” is not a closure condition. Better examples are “vendor confirms version 4.2.1 installed on all listed devices” or “provider reviewed sign-ins from September 19–20 and found no unauthorized access.”

Minutes 34–40: close the record

Complete this short decision record:

  • Alert reviewed:
  • Systems checked:
  • What is confirmed:
  • What remains uncertain:
  • Business impact:
  • Action selected:
  • Owner:
  • Deadline:
  • Evidence expected:
  • Escalation trigger:
  • Review date:

If the issue may involve unauthorized access, preserve evidence before deleting messages, rebuilding devices, or changing settings, unless immediate containment is necessary. Coordinate with the organization’s IT provider and incident-response contacts.

Monthly quality check

At the end of each month, review completed worksheets and look for patterns:

  • Are the same systems repeatedly missing patches?
  • Are alerts arriving without a current inventory?
  • Do vendors provide insufficient detail?
  • Are administrators relying on text-message codes when stronger MFA is available?
  • Can the office identify who can make urgent decisions?
  • Are unresolved “monitor” decisions being revisited?

CISA recommends multifactor authentication, strong passwords, software updates, and phishing awareness as core business protections. FTC guidance also emphasizes backups, access control, encryption, vendor oversight, employee training, and incident planning. The worksheet turns those broad recommendations into a small management habit.

The finished record should be brief enough to use and specific enough to support the next decision. It should never be treated as proof that the office is secure. Its value is that it makes uncertainty visible, assigns responsibility, and creates evidence that the business reviewed a warning thoughtfully.

Human-reviewed draft. For suspected compromise, regulated information, or legal reporting questions, involve qualified technical and legal advisers promptly.

Sources