← All insights

Practical checklist or tool

The Small-Office Access and Backup Review: A Practical 45-Minute Tool

A repeatable review tool for checking the accounts, devices, backups, and response information most likely to affect a small office.

Small office team using a printed cybersecurity checklist during a calm technology review

Use the review to find facts, not to create anxiety

A short cybersecurity review should produce a reliable list of facts. It should not become a scavenger hunt for every possible vulnerability or a performance test for staff.

Set a timer for 45 minutes. Invite the person who manages technology, the office manager, and the business owner or delegated decision-maker. If a managed service provider controls the systems, ask for read-only evidence or a live walkthrough rather than accepting a verbal summary.

Mark each item Yes, No, Unknown, or Not Applicable. “Unknown” is a useful result because it identifies where evidence is missing.

Part one: accounts and access

Check the following:

  • Every employee has an individual account for email and core systems.
  • Former employees and contractors are disabled.
  • Shared accounts are documented and limited.
  • Administrative accounts are separate from ordinary daily-use accounts.
  • Multifactor authentication is enabled for email, remote access, financial systems, and administrator accounts.
  • Recovery email addresses and phone numbers are current.
  • At least two trusted people can manage recovery without sharing passwords.
  • Vendor access is named, time-limited where practical, and reviewed.

Evidence may include an account export, access review report, screenshots, or service tickets. Do not store passwords in the review file.

Part two: devices and software

Review a sample of workstations, laptops, phones, and network devices. Confirm:

  • Operating systems are supported and receiving security updates.
  • Endpoint protection is installed and reporting.
  • Disk encryption is enabled on portable computers.
  • Automatic screen locking is active.
  • Staff cannot install arbitrary software without approval where that control is appropriate.
  • Lost or stolen devices can be remotely disabled or wiped.
  • Network equipment uses changed administrative credentials and current firmware.
  • Remote access is limited and protected by MFA.

A sample is not a full audit. Record which devices were checked and how the sample was selected.

Part three: email and collaboration

Email compromise is often a business process problem as well as a technical problem. Check whether:

  • External forwarding rules are reviewed.
  • Suspicious sign-in alerts have an assigned owner.
  • Staff know how to report phishing.
  • Payment-change requests require an independent confirmation.
  • Sensitive files are shared with named users or approved groups.
  • Guest access is reviewed.
  • Old shared links are removed or expired where possible.

Use an out-of-band confirmation for changes to bank details, payroll, wire instructions, or vendor payment information.

Part four: backups and recovery

Ask these questions:

  • What data is backed up?
  • How often does the backup run?
  • Where are copies stored?
  • Can an attacker using an ordinary administrator account delete the backups?
  • Are backups encrypted?
  • How long are they retained?
  • When was the last restoration test?
  • Who can authorize restoration?

CISA recommends backups that are automatic and continuous where appropriate, with a copy protected from the production network. The correct design depends on the business, but the test is universal: can the office restore what it needs within a tolerable period?

Part five: response readiness

Locate the incident contact sheet. It should include:

  • Internal decision-maker.
  • IT provider and after-hours number.
  • Cyber-insurance hotline.
  • Legal counsel.
  • Key software vendors.
  • Law enforcement and reporting contacts.
  • Instructions for preserving evidence.
  • A temporary communications channel if email is unavailable.

If no sheet exists, create a draft during the review.

Scoring without false precision

Do not convert the review into a misleading “security score” unless the scoring method is defined. Instead, classify findings:

  • Critical: could prevent essential operations or enable major unauthorized access.
  • High: materially increases likelihood or impact of a common incident.
  • Medium: weakens consistency, evidence, or recovery speed.
  • Low: improvement opportunity with limited immediate impact.

For each finding, name an owner, target date, and evidence required for closure.

What is confirmed and what is uncertain

Confirmed: MFA, software updates, backups, logging, encryption, and incident planning are repeatedly emphasized in federal small-business guidance. A checklist can help identify missing evidence and ownership.

Uncertain: the review cannot establish that a business is compliant, secure, or free of compromise. It is not penetration testing, legal advice, a forensic investigation, or a substitute for a detailed risk assessment.

The output to keep

The final deliverable should be one page containing:

  • Date and participants.
  • Systems reviewed.
  • Yes, No, Unknown, and Not Applicable results.
  • Five highest-priority actions.
  • Owners and due dates.
  • Links or filenames for supporting evidence.

Repeat the review every quarter. A simple, repeatable process is more useful than a complex checklist that no one completes.

Sources