Use the walkthrough to create decisions
This checklist is designed for a small office that wants a structured review in one working session. It is not a certification audit, penetration test, legal opinion, or guarantee of security. Its purpose is to identify gaps, assign owners, and create evidence that the business is managing risk deliberately.
Mark each item as Yes, No, Partial, or Not Applicable. For every No or Partial answer, record an owner and a target date.
People and governance
- A person is named to coordinate cybersecurity decisions.
- The business has identified its most important services and information.
- Legal, regulatory, contractual, and insurance requirements are documented.
- Employees know how to report suspicious messages, lost devices, and unusual payment requests.
- The business has a written incident contact list.
Evidence to retain: a one-page responsibility statement, current contact list, training record, and list of critical processes.
Accounts and identity
- Multifactor authentication is enabled for email and administrator accounts.
- Administrators use separate privileged accounts for administrative work.
- Former workers and contractors are removed promptly.
- Shared accounts are eliminated or formally controlled.
- Recovery methods are documented and tested.
- Sign-in alerts are reviewed for high-risk accounts.
For Microsoft 365, review administrator roles, recent sign-ins, authentication methods, mailbox forwarding rules, app consents, and emergency access procedures. A screenshot alone is weak evidence if it is undated or cannot show who performed the review.
Evidence to retain: dated access review, account list, role assignments, MFA report, and remediation notes.
Devices and software
- Business laptops use encryption and automatic screen locking.
- Security updates are installed on operating systems, browsers, applications, and network equipment.
- Unsupported devices and software are identified with a replacement plan.
- Endpoint protection is active and reporting.
- Personal devices are not given unrestricted access to sensitive systems.
- Lost or stolen devices can be remotely disabled or wiped where appropriate.
Do not confuse antivirus installation with complete endpoint protection. The review should confirm whether alerts are monitored, whether devices are enrolled, and whether a provider can investigate suspicious activity.
Evidence to retain: device inventory, patch report, encryption status, endpoint coverage report, and exception list.
Network and remote access
- Business wireless access is separated from guest access.
- Router and firewall administration uses unique credentials.
- Remote access is limited to approved users and services.
- Vendor remote access is time-limited or reviewed regularly.
- Network equipment firmware is maintained.
- Unused services and exposed management interfaces are disabled.
A small office may not need a complex network architecture, but it does need to know what is exposed and who can change it.
Data and backup
- Critical data locations are identified.
- Backup jobs are monitored for failure.
- At least one backup copy is protected from ordinary network access.
- Backups are encrypted where appropriate.
- Restoration has been tested using representative files.
- Recovery priorities and acceptable downtime are documented.
A successful backup job does not prove that the business can recover. Test the files, permissions, applications, and credentials needed to use the restored data.
Evidence to retain: backup reports, restore screenshots or logs, test date, files restored, time required, and corrective actions.
Email, payments, and fraud controls
- Employees verify payment or bank-detail changes through a separate channel.
- High-value or unusual payments require a second approval.
- Email authentication settings are reviewed with the domain provider.
- Suspicious messages can be reported without blame.
- Finance staff know how to preserve original messages and transaction information.
These controls address business email compromise, which may succeed even when malware is not present.
Vendors and cloud services
- Critical vendors are listed with contact information.
- Contracts identify security responsibilities and incident notification expectations.
- Vendor accounts use MFA and least privilege.
- Data shared with vendors is documented.
- Departing vendors lose access promptly.
A vendor’s security statement is not the same as an assessment of how the vendor connects to your office. Review the actual access path and the business impact if the vendor is unavailable.
Incident readiness
- The office knows how to isolate an affected device.
- Someone knows whom to call for technical response.
- The bank’s fraud number is available offline.
- Insurance, legal, and law-enforcement contacts are current.
- The office has practiced a short account-compromise or ransomware scenario.
Scoring and next steps
Count No and Partial answers, but do not treat the total as a maturity score. One unresolved administrator account or untested backup may matter more than ten minor documentation gaps.
Prioritize actions that reduce likely attack paths or shorten recovery time. A useful action statement is specific: “Require phishing-resistant MFA for administrators by June 30,” not “Improve identity security.”
Confirmed versus uncertain
The checklist reflects practices supported by NIST, CISA, FTC, Microsoft, and CISA ransomware guidance. It does not determine compliance with a law or contract. The business must interpret requirements with qualified professionals where necessary.
The strongest output is not a perfect score. It is a dated record showing what the office reviewed, what it found, what it chose to fix first, and when the result will be tested again.

