Written by Nate Daniels, owner of The Computer Specialists, LLC and an IT consultant serving businesses since 2002.
Accounts, devices, and updates
- Use unique accounts and strong authentication appropriate to the system.
- Remove or disable access promptly when roles change.
- Keep operating systems, applications, browsers, and supported network equipment current.
- Replace systems that no longer receive necessary security support.
- Use centrally managed endpoint protection where appropriate.
Backups, networks, and cloud services
- Know what is backed up, how often, where copies reside, how long they are retained, and who monitors failures.
- Test whether important data and systems can actually be recovered.
- Document firewalls, switches, wireless networks, VPNs, Internet connections, and administrative access.
- Review Microsoft 365 and other cloud account security, sharing, and recovery settings.
People, vendors, and incident preparation
- Train employees to recognize phishing, scams, suspicious requests, and unsafe handling of information.
- Understand which providers can access sensitive systems or information.
- Maintain current contacts, responsibilities, insurance information, and response procedures.
- Review applicable legal, contractual, privacy, and regulatory requirements with qualified advisors.
This checklist is general information, not legal advice or a guarantee of security or compliance.
Related: Explore practical small business cybersecurity support, or assess your current security and technology practices.