Most small and mid-sized business breaches do not come from advanced, tailor-made attacks. They come from a small number of common failures: weak passwords, missing multi-factor authentication, unpatched software, unmonitored email rules, backups nobody ever tested. Fixing those failures is not glamorous, but it produces the majority of the risk reduction most organizations will ever need.
This checklist walks through the controls that consistently show up on incident post-mortems as 'missing.' It is not exhaustive and it does not replace a formal risk assessment. It is the practical baseline every growing organization should be able to answer 'yes' to.
1. Identity and access
- Multi-factor authentication (MFA) enforced on email, file storage, VPN, remote access, and every administrator account.
- A password manager approved and rolled out to all employees.
- Shared accounts eliminated or, where unavoidable, protected by MFA and monitored.
- Administrator rights removed from day-to-day user accounts.
- A documented list of every application employees sign into with company credentials.
2. Employee onboarding
- A written checklist that provisions accounts, devices, and access based on role.
- Least-privilege access — new employees receive only what they need for their job.
- MFA enrollment completed on day one, not deferred.
- Security-awareness training delivered before broad system access is granted.
3. Employee offboarding
- A same-day process to disable accounts, revoke tokens, and reset shared credentials.
- Mailbox access preserved for the manager or compliance team as required.
- Company devices collected, wiped, and re-imaged.
- Removal from third-party SaaS applications the employee had access to.
4. Endpoint protection
- A modern endpoint protection product deployed and centrally managed on every device.
- Full-disk encryption enabled on every laptop.
- Automatic screen lock after a short idle period.
- USB and removable-media policies defined and enforced.
- A documented process for lost or stolen devices.
5. Patch management
- A monthly patching cycle for operating systems and third-party applications.
- An out-of-band process for critical security patches.
- Legacy systems identified, documented, and isolated where they cannot be updated.
6. Email security
- SPF, DKIM, and DMARC configured and monitored for the company's domain.
- Advanced phishing and impersonation protection enabled at the mailbox level.
- External sender warnings turned on.
- Regular review of mailbox forwarding rules to catch attacker-created rules.
7. Backups and recovery
- Backups run on a defined schedule for every critical system.
- At least one copy stored offsite or in a separate cloud tenant.
- Backups protected against modification by day-to-day accounts.
- Recovery tested at least annually — restoring real files, not just checking that the job succeeded.
8. Security-awareness education
- Every employee receives baseline security training on hire.
- Ongoing training delivered at least annually.
- Simulated phishing exercises run quarterly and results reviewed with team leaders.
- A clear, blameless way for employees to report suspicious messages.
9. Vendor and remote access
- A list of every third party with access to company systems, data, or endpoints.
- MFA required for all vendor access.
- Access reviewed quarterly and revoked promptly when engagements end.
- Vendor security posture reviewed before granting sensitive access.
10. Logging, monitoring, and incident response
- Sign-in logs, email logs, and endpoint alerts collected and retained.
- A defined process for who investigates alerts and how quickly.
- A written incident response plan covering ransomware, business email compromise, and data loss.
- Contact information for legal counsel, cyber insurance, and law enforcement kept up to date.
11. Cyber-insurance readiness
- Current cyber-insurance application reviewed by whoever runs IT.
- The controls promised in the application actually implemented and evidenced.
- Changes to the environment communicated to the broker before renewal.
12. Leadership review cadence
- A quarterly review of security posture with leadership.
- Metrics tracked over time: patching coverage, MFA coverage, phishing-test results, backup success rate.
- Findings tied to a small number of clear, dated action items.
A note on scope
This checklist supports an organization's security program. It does not constitute legal, regulatory, or compliance certification. Work alongside qualified legal, compliance, and audit partners for anything requiring an attestation.