Free Resource
The same baseline our engineers check on day one with every new client. Work through it in an afternoon — no security team required.
Passwords alone are not enough. Require MFA for email, cloud consoles, VPN, and any account with elevated privileges first.
A backup you haven't restored is a guess. Schedule a quarterly test restore and confirm recovery time meets your needs.
Inventory every device and application, including end-of-life software that no longer receives security updates.
Audit who has admin rights and why. Remove standing access that isn't tied to a current job function.
Know who to call, what to isolate first, and how to communicate internally before an incident happens — not during one.
Laptops, servers, and mobile devices all need active monitoring — not just antivirus that runs a scan once a week.
Keep guest Wi-Fi, IoT devices, and finance systems on separate network segments so a breach in one doesn't spread to all.
Confirm sensitive data is encrypted on disk and every connection handling it uses TLS — no exceptions for "internal only" traffic.
Run phishing simulations at least quarterly. Most breaches start with a person clicking a link, not a firewall failing.
List every vendor with access to your systems or data. Confirm each one has reasonable security practices of their own.
Tip: use your browser's Print → Save as PDF to keep an offline copy.
← Want help working through this list? Talk to an engineer