Small-Business Security Readiness Checklist
← All resources · Download the two-page checklist (PDF)
A practical conversation, not a security score.
For each prompt, mark yes / no / unknown, the person responsible, and the next action. An unknown is a useful finding. This checklist does not assess compliance, certify security, or replace a risk assessment. Do not send passwords, recovery codes, incident evidence, or confidential records through a sales inquiry.
Know what matters
- Can someone name the systems and data the business depends on most?
- Is there an owner for security decisions, vendors, and the budget to address priority gaps?
- Is there a current list of devices, key applications, administrator accounts, and outside providers?
Protect daily access
- Is multi-factor authentication in place for email, administrator access, and other important accounts where supported?
- Are new accounts approved and departing users’ access removed through a repeatable process?
- Are devices and software updated through a defined routine, with unsupported systems identified?
- Are staff taught how to report suspicious messages or unusual account activity?
Prepare for disruption
- Does an owner know what data is backed up, how it is protected, and what is not covered?
- Has a restore been tested for a business-critical workflow, with the result documented?
- Is there a written first-response path for a suspected incident: who to call, who decides, and what information to preserve?
- Are important vendor and insurance contacts available outside a potentially affected system?
Decide the next three actions
Choose one ownership gap, one technical gap, and one recovery or response gap. For each, record the owner, a due date, and what evidence would show it is done. You can talk through your priorities with WOLFTRAXX SYSTEMS or explore cybersecurity services; any assessment or ongoing service needs separately agreed scope.
This original checklist is organized around small-business risk-management themes in the NIST Cybersecurity Framework 2.0 Small Business Quick Start Guide and CISA small-business resources. It does not reproduce another MSP’s checklist or imply NIST/CISA endorsement.