PLANET IT

Free Resource

The 10-Point IT Security Checklist

The same baseline our engineers check on day one with every new client. Work through it in an afternoon — no security team required.

01

Multi-factor authentication on every admin account

Passwords alone are not enough. Require MFA for email, cloud consoles, VPN, and any account with elevated privileges first.

02

Backups you've actually tested

A backup you haven't restored is a guess. Schedule a quarterly test restore and confirm recovery time meets your needs.

03

Patch management with no forgotten systems

Inventory every device and application, including end-of-life software that no longer receives security updates.

04

Least-privilege access review

Audit who has admin rights and why. Remove standing access that isn't tied to a current job function.

05

A written incident response plan

Know who to call, what to isolate first, and how to communicate internally before an incident happens — not during one.

06

Endpoint protection on every device

Laptops, servers, and mobile devices all need active monitoring — not just antivirus that runs a scan once a week.

07

Network segmentation for critical systems

Keep guest Wi-Fi, IoT devices, and finance systems on separate network segments so a breach in one doesn't spread to all.

08

Encryption at rest and in transit

Confirm sensitive data is encrypted on disk and every connection handling it uses TLS — no exceptions for "internal only" traffic.

09

Security awareness training, on a schedule

Run phishing simulations at least quarterly. Most breaches start with a person clicking a link, not a firewall failing.

10

A short list of third-party risk

List every vendor with access to your systems or data. Confirm each one has reasonable security practices of their own.

← Want help working through this list? Talk to an engineer