Small-Business Security Readiness Checklist

← All resources · Download the two-page checklist (PDF)

A practical conversation, not a security score.

For each prompt, mark yes / no / unknown, the person responsible, and the next action. An unknown is a useful finding. This checklist does not assess compliance, certify security, or replace a risk assessment. Do not send passwords, recovery codes, incident evidence, or confidential records through a sales inquiry.

Know what matters

  • Can someone name the systems and data the business depends on most?
  • Is there an owner for security decisions, vendors, and the budget to address priority gaps?
  • Is there a current list of devices, key applications, administrator accounts, and outside providers?

Protect daily access

  • Is multi-factor authentication in place for email, administrator access, and other important accounts where supported?
  • Are new accounts approved and departing users’ access removed through a repeatable process?
  • Are devices and software updated through a defined routine, with unsupported systems identified?
  • Are staff taught how to report suspicious messages or unusual account activity?

Prepare for disruption

  • Does an owner know what data is backed up, how it is protected, and what is not covered?
  • Has a restore been tested for a business-critical workflow, with the result documented?
  • Is there a written first-response path for a suspected incident: who to call, who decides, and what information to preserve?
  • Are important vendor and insurance contacts available outside a potentially affected system?

Decide the next three actions

Choose one ownership gap, one technical gap, and one recovery or response gap. For each, record the owner, a due date, and what evidence would show it is done. You can talk through your priorities with WOLFTRAXX SYSTEMS or explore cybersecurity services; any assessment or ongoing service needs separately agreed scope.

This original checklist is organized around small-business risk-management themes in the NIST Cybersecurity Framework 2.0 Small Business Quick Start Guide and CISA small-business resources. It does not reproduce another MSP’s checklist or imply NIST/CISA endorsement.