How to use this checklist
Set aside 45 to 60 minutes with the person who manages technology, accounting, and office operations. Mark each item Yes, No, Unknown, or Not Applicable. For every No or Unknown, record an owner and target date. A completed checklist is not proof that a business is secure; it is a way to turn vague concern into follow-up work.
Accounts and identity
- Is MFA enabled for every administrator account?
- Is MFA enabled for email, file storage, remote access, payroll, accounting, and payment platforms?
- Are former employees, contractors, and inactive accounts disabled?
- Does each worker have an individual account rather than sharing credentials?
- Are administrator privileges limited to people who need them?
If MFA is unavailable, document the exception and prioritize a replacement or compensating control. CISA recommends using the strongest available method, with phishing-resistant MFA preferred where supported.
Devices and software
- Is there a current inventory of business computers and mobile devices?
- Are operating systems still supported by their vendors?
- Are automatic updates enabled?
- Is endpoint protection installed, active, and centrally monitored?
- Are lost or stolen devices protected by encryption and a screen lock?
Unknown answers deserve attention. An unlisted laptop or unsupported application can become a blind spot during an incident.
Email and payment fraud
- Can employees report suspicious messages through a simple, known process?
- Are payment-account changes verified using a trusted second channel?
- Are high-risk payments subject to a second-person approval?
- Are external forwarding rules reviewed for unexpected changes?
- Are sensitive files shared through controlled links rather than personal email?
These controls address process failure as well as malware. A message can be authentic while the request itself is fraudulent because an account was compromised.
Data and access
- Do you know where customer, employee, patient, client, and financial information is stored?
- Are shared folders organized around job responsibilities?
- Are permissions reviewed at least periodically?
- Is sensitive data encrypted in transit and at rest where appropriate?
- Is there a retention and secure-disposal process?
Do not collect or retain information merely because storage is inexpensive. Data that is not needed is data the business does not have to protect, explain, restore, or disclose.
Vendors and cloud services
- Is there a current list of vendors with access to systems or data?
- Does each critical vendor have a business owner inside your organization?
- Do contracts address security responsibilities, incident notification, and data return or deletion?
- Are vendor administrator accounts protected by MFA and least privilege?
- Is there a documented process for removing vendor access when work ends?
A vendor’s security statement may be helpful, but it is not the same as verifying the controls that apply to your account and contract.
Backups and response
- Are critical files backed up on a defined schedule?
- Is at least one backup isolated from ordinary administrator credentials?
- Are backups encrypted and protected against deletion or alteration?
- Has the business restored a representative file recently?
- Is there a written incident-response and communications plan?
CISA recommends offline, encrypted backups and regular testing of availability and integrity. “Backup completed” is not the same as “business can recover.”
Evidence to retain
For each Yes, save practical evidence:
- A screenshot or report showing MFA coverage.
- A device and software inventory export.
- A backup job report and restoration record.
- A vendor list with review dates.
- Training attendance or acknowledgement records.
- A dated incident-plan exercise summary.
Evidence should avoid exposing passwords, secret keys, or unnecessary personal data. Store it where authorized managers can find it if the normal file system is unavailable.
What the results mean
Five Unknown answers may represent more risk than five No answers because the organization cannot make a decision about an invisible control. Prioritize accounts with broad access, systems that affect revenue, and information subject to legal or contractual duties.
Repeat the walkthrough after major changes: a new cloud application, office move, acquisition, payroll transition, new remote-access method, or significant staffing change. The value comes from repetition and ownership, not from achieving a perfect score.
Every article remains a human-reviewed draft. This article is educational and does not replace legal, regulatory, insurance, or technical advice.

