Use the walkthrough to learn, not to perform security theater
This 18-check walkthrough is designed for a small office manager, owner, or designated technology contact. It is not a penetration test, audit, certification, or guarantee. Its purpose is to reveal which important controls can be demonstrated and which exist only by assumption.
Set aside 45 to 60 minutes. Gather your Microsoft 365 or Google Workspace administrator, backup contact, insurance policy, major vendor list, and current employee roster. Record the date, evidence reviewed, owner, and next action.
Access and identity checks
- [ ] Every active worker has a named account.
- [ ] Former workers and contractors have been disabled.
- [ ] Administrator access is limited to people who need it.
- [ ] MFA is enabled for email, remote access, finance, payroll, and administrator accounts.
- [ ] At least two emergency administrator accounts exist, are protected, and have a tested recovery method.
- [ ] Shared accounts have an owner and a documented reason for existing.
Evidence may include an account export, administrator-role report, access review record, or ticket showing termination handling. Do not paste passwords, recovery codes, or secret keys into the worksheet.
Device and software checks
- [ ] Company laptops and desktops have supported operating systems.
- [ ] Endpoint protection is active and reporting.
- [ ] Disk encryption is enabled on portable devices where available.
- [ ] Critical software and internet-facing devices have a patching owner.
- [ ] Remote-management tools are inventoried and restricted.
A screenshot is useful only if it is dated and tied to a device or tenant. A general statement such as “the antivirus is installed” is weaker than an alert-health report showing recent communication.
Email and cloud checks
- [ ] Mailbox forwarding rules are reviewed.
- [ ] Legacy authentication is blocked or formally documented as an exception.
- [ ] External sharing links are reviewed for sensitive libraries and folders.
- [ ] Third-party applications with access to business data are inventoried.
Microsoft Entra security defaults can require MFA, block legacy authentication, protect administrative actions, and block device code flow in applicable environments. Organizations with more complex needs may use Conditional Access instead. Confirm the tenant’s actual configuration rather than assuming a default is active.
Backup and recovery checks
- [ ] Critical systems and data are identified.
- [ ] Backups are encrypted and protected from ordinary user access.
- [ ] At least one backup copy is offline, isolated, or otherwise resistant to deletion.
- [ ] A restoration test has been completed recently.
- [ ] The office knows which credentials and licenses are needed to restore operations.
Record what was restored and whether it was usable. CISA specifically recommends regular testing of backup availability and integrity. A successful file download does not prove that the business can rebuild its most important workflow.
Vendor and response checks
- [ ] Critical vendors have current contacts and escalation procedures.
- [ ] Contracts identify security responsibilities where practical.
- [ ] The office has a written first-hour incident sequence.
- [ ] Employees know how to report suspicious messages, lost devices, and unusual sign-in prompts.
The first-hour plan should include containment, evidence preservation, communications, and decisions about law enforcement, insurance, legal counsel, and affected customers. Do not ask untrained employees to investigate deeply or delete evidence.
Scoring without false precision
Instead of treating the worksheet as a pass/fail exam, classify each item:
- Demonstrated: current evidence exists and an owner is assigned.
- Partially demonstrated: the control exists but is inconsistent, outdated, or incomplete.
- Unknown: no one can verify the control.
- Not applicable: the reason is documented.
Prioritize unknowns involving administrator access, remote access, backups, financial systems, and sensitive information. Unknown is not the same as safe.
What the worksheet cannot tell you
The walkthrough will not identify every vulnerability, test an application, validate legal compliance, or determine whether a security provider is competent. It is a starting instrument. High-risk findings should be reviewed by a qualified professional with access to the relevant systems.
Turn observations into action
For each partially demonstrated or unknown item, record:
- The business impact if it fails.
- The next practical action.
- The person responsible.
- The target date.
- The evidence that will show completion.
Review the worksheet quarterly and after major changes such as a new practice-management system, acquisition, office move, remote-work expansion, or key vendor change.
Sources:
- https://www.cisa.gov/cybersecurity-performance-goals
- https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults
- https://www.cisa.gov/stopransomware/ransomware-guide
- https://www.nist.gov/cyberframework/quick-start-guides

