← All insights

Practical checklist or tool

The Small-Office Security Evidence Worksheet

A manager-friendly worksheet for checking whether basic safeguards exist and whether the office can prove they are operating.

An office manager completing a cybersecurity evidence worksheet at a small business desk

A checklist should produce evidence

Many small offices have security settings that may be useful but are difficult to verify. A provider may say backups are running, MFA is enabled, and devices are protected. The manager still needs a practical way to confirm what is covered, what is excluded, and what happens when a control fails.

Use the worksheet below during a 60-minute review. Record the answer, the evidence location, the owner, and the next action. A “yes” without evidence should be marked “unverified.”

Section 1: Accounts and access

  • Is there a current list of employees, contractors, vendors, and administrators?
  • Does every person use an individual account rather than a shared login?
  • Is MFA enabled for Microsoft 365, remote access, financial systems, payroll, and administrator accounts?
  • Are former users disabled promptly?
  • Are emergency or recovery accounts documented and protected?
  • Are administrator rights limited to people and tasks that need them?

Evidence to collect:

  • Current user export.
  • Administrator-role list.
  • Recent access-review record.
  • Offboarding ticket or checklist.
  • MFA policy or configuration report.

Section 2: Devices and software

  • Is there an inventory of laptops, desktops, phones, servers, network devices, and important applications?
  • Are operating systems supported and receiving security updates?
  • Is endpoint protection active and reporting normally?
  • Are full-disk encryption and screen-lock settings enabled on mobile computers?
  • Are remote-support tools listed and restricted?
  • Are default passwords changed on routers, cameras, printers, and other equipment?

Evidence to collect:

  • Device inventory.
  • Patch-status report.
  • Endpoint-protection dashboard.
  • Encryption-status report.
  • Remote-access software list.

Section 3: Email and identity

  • Are suspicious messages reported through a defined process?
  • Are external senders clearly identified where the system supports it?
  • Are anti-spam, anti-phishing, and domain-authentication settings reviewed?
  • Are mailbox forwarding rules monitored?
  • Are high-risk sign-ins investigated?
  • Are finance and payment-change requests verified through a second channel?

Evidence to collect:

  • Email-security configuration summary.
  • Sample alert or investigation record.
  • List of mailbox forwarding rules.
  • Written payment-verification procedure.

Section 4: Backups and recovery

  • Which systems and data are included in backups?
  • How often do backups run?
  • Are backup credentials separate from ordinary user accounts?
  • Can an attacker who compromises the office administrator delete every backup?
  • Is at least one recovery copy protected against ordinary alteration or deletion?
  • Has the office restored a file, mailbox, application, or complete system recently?
  • Are restoration instructions available if the normal IT contact is unreachable?

Evidence to collect:

  • Backup coverage report.
  • Recent successful and failed-job reports.
  • Restoration test record.
  • Recovery-priority list.
  • Offline or alternate contact sheet.

Section 5: Response and continuity

  • Does the office have a written incident-response plan?
  • Does it identify who declares an incident?
  • Are insurer, attorney, IT, law-enforcement, and vendor contacts current?
  • Can the business communicate if email is down?
  • Are critical manual workarounds documented?
  • Has the team practiced a ransomware, lost-device, or compromised-account scenario?

Evidence to collect:

  • Current response plan.
  • Contact list.
  • Tabletop exercise notes.
  • Business continuity procedures.

Section 6: Vendors and compliance

  • Does each important vendor have a named owner?
  • Does the contract address security responsibilities, notification, data return, and access termination?
  • Is vendor remote access time-limited and MFA-protected?
  • Are regulatory and contractual requirements documented?
  • Does the office know what evidence customers, insurers, or auditors may request?

Evidence to collect:

  • Vendor register.
  • Contracts or security addenda.
  • Access logs.
  • Insurance application and policy requirements.
  • Compliance obligation list.

Scoring the worksheet

Assign each question one status:

  • Verified: evidence is current and the control is operating.
  • Partially verified: the control exists but scope, ownership, or testing is incomplete.
  • Unverified: someone believes it exists, but evidence is missing.
  • Not applicable: document why it does not apply.

Prioritize items that could stop the business, expose regulated information, or allow an attacker to control identities and backups. Do not let a high count of low-risk items distract from one critical weakness, such as an unprotected administrator account or an untested recovery process.

What this tool can and cannot prove

This worksheet can organize a management review and create a starting evidence file. It cannot certify compliance, detect an advanced intrusion, or replace a forensic investigation. It also cannot establish that a vendor’s controls are effective without independent evidence or testing.

Review it quarterly, after major technology changes, and before renewing cyber insurance or signing a sensitive customer contract. The practical goal is a small office that can answer not only “Do we have this control?” but also “Who owns it, how do we know, and what happens when it fails?”

Sources

FTC Cybersecurity for Small Business: https://www.ftc.gov/business-guidance/small-businesses/cybersecurity

CISA small-business resources: https://www.cisa.gov/small-and-medium-sized-business-resources

NIST CSF 2.0 Small Business Quick-Start Guide: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1300.pdf

Sources