← All insights

Practical checklist or tool

The 45-Minute Small-Office Identity and Recovery Check

A focused verification worksheet for office managers to review access, backups, vendor support, and recovery evidence without turning the exercise into a full audit.

Central Florida property-management team completing a timed identity-and-recovery verification

Use this as a verification exercise

This 45-minute review is designed for a small office that needs useful evidence quickly. It is not a penetration test, compliance certification, or substitute for an incident investigation. Its purpose is to identify obvious gaps in identity protection and recovery readiness.

Set a timer, assign one person to record answers, and invite the IT provider or system administrator when possible. Do not write passwords, recovery codes, or sensitive patient, client, employee, or financial information on the worksheet.

At the end, classify each item as:

  • Yes: verified with current evidence.
  • No: missing, incomplete, or not working.
  • Unknown: no one can confirm the answer.
  • Not applicable: documented reason applies.

An “unknown” should be treated as a work item, not as a reassuring answer.

Minutes 0–10: confirm the important accounts

Record the date, reviewer, primary technology contact, and the business systems included in the review.

Check whether the office has a current list of:

  • Email and collaboration administrators.
  • Accounting and payment administrators.
  • Cloud-storage administrators.
  • Remote-access and VPN administrators.
  • Backup-console administrators.
  • Practice-management, case-management, or line-of-business administrators.
  • Former employees, contractors, and vendors who may still have access.

For each system, ask:

  • Is there a named person responsible for access decisions?
  • Are administrator accounts separate from ordinary daily-use accounts?
  • Is multifactor authentication enabled for every administrator?
  • Are emergency or recovery accounts documented and controlled?
  • Can the office identify the last access review date?

CISA recommends requiring MFA wherever possible and prioritizing phishing-resistant methods. Security keys and comparable phishing-resistant methods generally provide stronger protection than text-message codes. Source: https://www.cisa.gov/audiences/small-and-medium-sized-businesses/secure-your-business/require-multifactor-authentication

Do not accept “the vendor handles it” as a complete answer. Ask what the vendor handles, what the office controls, and where the evidence can be found.

Minutes 10–20: review staff changes and external access

Select three recent personnel or contractor changes, if available. For each one, verify:

  • The date access was requested.
  • The systems that were approved.
  • The date access was removed or changed.
  • Whether company devices, tokens, or keys were returned.
  • Whether shared passwords or recovery methods were changed when necessary.

Next, select two important vendors and ask:

  • Does the vendor have remote access?
  • Is access named to an individual or shared among support staff?
  • Is MFA required?
  • Is access limited to the time needed for support?
  • Are support sessions logged?
  • Can the office suspend access without waiting for a long contract process?

The FTC advises businesses to control vendor access, use MFA, safeguard data, and limit access to only what the vendor needs. Source: https://www.ftc.gov/business-guidance/blog/2018/12/cybersecurity-small-business-vendor-security

Mark the item “Unknown” if the office cannot obtain a clear answer from the provider.

Minutes 20–30: test the backup story

Identify the systems the office would need first after a serious disruption. Do not begin by asking how much storage is available. Ask whether the backup can restore business operations.

Verify:

  • What data is backed up.
  • How often backups run.
  • Whether backups are separate from ordinary user accounts.
  • Whether at least one copy is protected from routine deletion or encryption.
  • Who receives backup-failure alerts.
  • How long the provider retains backup versions.
  • Whether the office has restored a file or system recently.
  • Whether restoration requires credentials that may be unavailable during an incident.

Choose one representative, non-sensitive file or test system and perform a small restoration if the provider permits it. Record the start time, end time, result, and any manual steps.

The FTC’s small-business guidance recommends regular backups and emphasizes having plans for response, disaster recovery, and business continuity. Source: https://www.ftc.gov/business-guidance/small-businesses/cybersecurity

A backup that has never been restored is an assumption. A successful test is evidence, although it does not prove that every system can be recovered.

Minutes 30–38: review the first-hour contact route

Find the current incident plan or create a temporary contact card. It should contain:

  • Internal decision-maker.
  • IT provider or managed-service contact.
  • Critical software vendors.
  • Legal counsel.
  • Cyber-insurance contact, if applicable.
  • Backup administrator.
  • Key banking or payment contact.
  • Local law-enforcement and FBI reporting information.
  • Communications owner for employees and customers.

Ask one scenario question: “If an employee reports that the screen is encrypting files at 9:00 a.m., who makes the first five calls?” If the answer depends on finding a document that no one has opened recently, update the document now.

The FTC recommends securing affected operations, mobilizing the response team, preserving evidence, and consulting appropriate experts after a breach. Source: https://www.ftc.gov/business-guidance/resources/data-breach-response-guide-business

Do not instruct employees to investigate beyond their training or to erase evidence. The first objective is to report quickly and avoid making the situation worse.

Minutes 38–45: assign actions and owners

Create a short action table:

  • Finding.
  • Risk if unresolved.
  • Owner.
  • Due date.
  • Evidence required to close it.

Prioritize items that could immediately enable account takeover or prevent recovery:

  • Administrator accounts without MFA.
  • Former users who still have access.
  • Unknown backup status.
  • No tested restoration.
  • Shared vendor credentials.
  • Missing incident contacts.
  • Unsupported or unpatched systems.

Use realistic due dates. A small office may not fix every issue in one week, but it should know which issue comes first and who is responsible.

What this check confirms—and what it does not

This worksheet can confirm whether the office has visible evidence for selected identity and recovery practices. It cannot confirm that the network is free of compromise, that every legal obligation has been met, or that a vendor’s security claims are accurate.

Repeat the check quarterly, after staff changes, after a major software migration, and after any incident. The value is not the 45-minute number. The value is creating a repeatable habit in which access and recovery are verified rather than assumed.

Sources