Identity and access Reduce the chance that a stolen password becomes a business-wide incident.
0/4
Multifactor authentication is required for email, cloud apps, remote access, and admin accounts. Prioritize systems that hold customer, financial, payroll, or operational data. Administrative accounts are separate from everyday user accounts. Admin rights are assigned only when needed and reviewed regularly. User access is reviewed at least quarterly. The review includes shared mailboxes, cloud drives, accounting tools, and line-of-business apps. Departing employees and vendors are removed from systems the same day access should end. This includes device return, session revocation, and forwarding rules.
Devices and patching Keep laptops, desktops, servers, and mobile devices managed and recoverable.
0/4
The business maintains a current inventory of computers, servers, phones, and network equipment. Inventory should show owner, location, operating system, and support status. Operating system, browser, application, and firmware updates follow a defined schedule. Critical security updates have an expedited process. Endpoint protection is installed, monitored, and centrally managed. Alerts are reviewed by a responsible person or managed provider. Company devices use disk encryption, screen locks, and remote wipe where appropriate. Lost or stolen equipment should not expose business data.
Email and web protection Defend the channels most attackers use to reach small and midsize businesses.
0/4
Inbound email filtering blocks suspicious attachments, links, impersonation attempts, and known threats. Review quarantines and exceptions so protection does not silently drift. SPF, DKIM, and DMARC are configured for company domains. These records help reduce spoofing and improve trust in legitimate messages. Employees know how to report suspicious email, texts, calls, and login prompts. Reporting should be easy, visible, and treated as a normal business process. Web filtering or secure browsing protections are active for company devices. Blocks should cover malicious domains, newly registered domains, and risky downloads where possible.
Backup and recovery Make sure ransomware, hardware failure, or accidental deletion does not become a permanent outage.
0/4
Critical files, servers, cloud mailboxes, cloud drives, and business applications are backed up. Do not assume a cloud service automatically gives you the recovery coverage the business needs. Restore tests are performed and recorded on a recurring schedule. A backup that has never been restored is only a guess. At least one backup copy is protected from routine deletion or encryption. Use separation, immutability, or controlled access to limit ransomware impact. Recovery roles, vendor contacts, and communication steps are documented. The plan should be usable when email, phones, or the office network are unavailable.
Network and cloud Protect the systems that connect offices, remote staff, vendors, and cloud services.
0/4
Firewall, router, switch, and access point settings are reviewed and updated. Remove unused rules, default passwords, exposed management pages, and unsupported firmware. Guest Wi-Fi and personal devices are separated from business systems. Segmentation limits what an untrusted device can reach. Remote access uses named accounts, MFA, and approved devices. Avoid shared VPN credentials and unmanaged remote-control tools. Cloud services have baseline controls for MFA, admin roles, sharing, logging, and retention. Review Microsoft 365, Google Workspace, file sharing, identity, and any industry-specific tools.
People and response Prepare employees and leaders to make better decisions before pressure hits.
0/4
Employees receive practical security awareness guidance tied to their actual tools and roles. Short, repeated guidance is more useful than an annual check-the-box exercise. There is a named person or team responsible for coordinating security incidents. They know who to call for IT, legal, insurance, leadership, and vendor support. Important vendors and outsourced systems are reviewed for access, continuity, and data handling risk. Include IT providers, payroll, accounting, phone systems, payment tools, and cloud apps. The business has practiced at least one likely incident scenario. Examples include business email compromise, ransomware, lost device, or cloud account takeover.