← All insights

Practical checklist or tool

The Small-Office Security Evidence Pack: 20 Checks Before You Call for Help

A practical worksheet for collecting the facts a technology provider, insurer, auditor, or incident responder needs before recommending next steps.

Office manager using a printed cybersecurity evidence checklist beside a laptop

Why evidence beats assumptions

A small office often knows that “something should be better” but cannot describe the current environment. That slows troubleshooting, makes proposals difficult to compare, and can hide urgent risks.

This checklist is designed for a 30- to 60-minute review. It does not certify security, replace a technical assessment, or prove that a system has not been compromised. It creates a useful starting record for an owner, office manager, technology provider, insurer, or attorney.

Do not record passwords, authentication codes, private keys, recovery codes, or full financial information in the worksheet.

Identity and access

  • List every person with access to business email.
  • Mark former employees, contractors, shared accounts, and service accounts.
  • Identify every global, tenant, domain, server, or local administrator.
  • Record whether MFA is required for email, finance, remote access, backups, and administrator accounts.
  • Note which accounts still use SMS, voice calls, email codes, or password-only access.
  • Check whether sign-in alerts are sent to a monitored person.

For Microsoft 365, record the tenant administrator, emergency recovery method, active privileged roles, external guests, shared mailboxes, forwarding rules, and recent unusual sign-ins. Do not send screenshots containing personal data unless the recipient is authorized to receive them.

Devices and software

  • Count company laptops, desktops, phones, tablets, servers, and network devices.
  • Mark devices that are personally owned but used for business.
  • Record operating-system versions and whether automatic updates are enabled.
  • Confirm that endpoint protection is installed, active, and reporting.
  • Identify remote-support and remote-access tools.
  • Note devices that cannot be updated or are no longer supported.
  • Record who can install software.

The goal is not perfect technical detail. It is to expose unknowns. Write “unknown” rather than guessing.

Email and payment controls

  • Confirm that staff know how to verify payment-account changes.
  • Identify who can approve wires, ACH payments, refunds, payroll changes, and vendor-bank updates.
  • Require a second communication channel for high-risk changes.
  • Review mailbox forwarding and delegation settings.
  • Check whether domain email-authentication records are configured and monitored by the responsible provider.
  • Record the process for reporting suspicious messages.

Business email compromise often succeeds through believable requests rather than obvious malware. A written verification procedure can reduce the chance that a single compromised mailbox controls a payment decision.

Data and vendors

  • List the locations where critical files are stored.
  • Identify the business owner for each major application.
  • Record which vendors can access systems or data.
  • Note whether vendor access is individual, shared, temporary, or always active.
  • Confirm whether contracts address security, breach notification, data return, and access removal.
  • Identify regulated or contractually protected information.

Pay special attention to payroll, accounting, customer relationship management, electronic health record, case-management, document-management, and payment systems. These may be cloud services even when staff describe the business as “on a local network.”

Backup and recovery

  • List what is backed up.
  • Record backup frequency and retention.
  • Identify where copies are stored.
  • Confirm whether at least one copy is offline or otherwise isolated from ordinary administrator access.
  • Identify who can delete or alter backups.
  • Record the last successful restore test.
  • Write down the order in which essential systems should return after an outage.

CISA recommends offline, encrypted backups and regular testing of backup availability and integrity. A green backup dashboard does not prove that files, permissions, applications, and business workflows can be restored.

Detection and response

  • Identify who receives security alerts.
  • Record the phone numbers for the technology provider, cyber insurer, bank fraud team, and legal counsel.
  • Confirm who can disable a user account or disconnect a device.
  • Define what staff should do with a suspected phishing message.
  • Define what staff should do if ransomware appears.
  • Record how evidence will be preserved.

The Federal Trade Commission advises small businesses to have a plan for staying operational after ransomware and to share that plan with people who need to know. The plan should be accessible when email is unavailable.

Score the results

Use three simple labels:

  • Confirmed: supported by a current screenshot, report, policy, test result, or named owner.
  • Uncertain: someone believes it is true, but no evidence is available.
  • Gap: the control is absent, ineffective, or has no accountable owner.

Prioritize gaps that affect administrator accounts, financial transactions, email, backups, remote access, and unsupported systems. Avoid turning the list into a long shopping list. The first action should reduce the most important business risk or make the next decision clearer.

What is confirmed and what is uncertain

Confirmed: This worksheet is a management and evidence tool based on practices emphasized by NIST, CISA, and the FTC. It is not a formal audit and cannot determine whether an office has been breached.

Uncertain: The correct retention period, monitoring depth, contractual wording, and notification obligations depend on the business and its industry. Escalate high-consequence questions to qualified technical, legal, insurance, or regulatory advisors.

Keep the worksheet useful

Review the evidence pack quarterly and after major staff, vendor, application, or office changes. Save dated versions in a protected location. Track each gap to an owner and due date.

The value of the checklist is not the number of boxes marked. Its value is that the office can explain what it has, what it protects, what remains unknown, and what will happen next.

Sources