- Inventory devices and services. Record owners, models, operating systems, important cloud services, and renewal dates.
- Keep supported software updated. Enable automatic security updates and replace products that no longer receive fixes.
- Require MFA. Prioritize email, administrators, banking, payroll, remote access, and cloud storage.
- Use unique accounts. No shared logins; promptly remove former staff and unnecessary access.
- Limit administrator rights. Daily work should happen without full control of the computer or cloud environment.
- Back up critical data. Use automated, versioned, isolated backups and test restores.
- Secure the network. Update the router or firewall, change defaults, use WPA2/WPA3, and separate guests and untrusted smart devices.
- Protect endpoints. Use built-in or managed anti-malware, disk encryption, screen locks, and device tracking where appropriate.
- Train for common scams. Establish a second-channel process for payments, account changes, and sensitive requests.
- Prepare for incidents. Keep offline contact details for IT, banking, insurance, legal help, and key vendors. Decide who can disconnect systems and notify people.
Review it quarterly
Check the inventory, failed backups, missing patches, administrator list, former staff, unusual forwarding rules, and recovery contacts. After any major staffing or vendor change, review access immediately.
A checklist is a starting point, not a guarantee. Businesses with regulated data, contractual requirements, payment systems, or unusual operational risks should obtain a tailored assessment.