Blog

How ready is your business for a cyberattack?

The 7-Point Cybersecurity Readiness Check Every Business Should Run

August 31, 20264 min read

You're onboarding a new hire and pulling up the shared drive to set up her access. That's when you notice it: an employee who left six months ago still has an active login. You don't know how long it's been sitting there, unused and unwatched, or whether anyone else on your team has the same problem waiting to be found.

Most businesses don't discover a weak spot in their security posture until something like that surfaces by accident. A readiness check finds it on your terms instead of an attacker's. Here are the 7 points worth checking on your own business this week.

1. Multi-factor authentication on every account

If you haven't enabled MFA everywhere, this is where to start. CISA notes that using MFA makes you up to 99% less likely to have an account compromised. Check that it's required, not optional, on email, remote access, and anything tied to sensitive data.

2. Password and account hygiene

Confirm you're not reusing passwords across accounts and that former employees no longer have working logins anywhere in your systems. A password manager makes this easier to enforce across your whole team.

3. Email and endpoint protection

Check that every device connecting to your network, laptops, phones, remote workstations, has active endpoint protection, and that your email filtering is catching more than obvious spam.

4. Patching and updates

Unpatched software remains one of the easiest ways into your systems. Confirm you have a regular patching schedule, not an occasional one, for both your servers and everyday employee devices.

5. Access permissions

Review who has access to what, and whether that access still matches their current role. The employee login you found by accident is a common story. A regular access review catches it before it becomes a problem.

6. Backup and recovery testing

Having backups isn't the same as knowing they work. Test a real restore on a regular schedule so you're not finding out your backup failed in the middle of an actual incident.

7. Incident response planning

If a breach happened to you tomorrow, would you know who to call first? The FTC's data breach response guidance outlines the steps every business should have ready before an incident, not during one. A written plan turns a chaotic first hour into a controlled one.

What this checklist adds up to

None of these 7 points are complicated on their own, and that's exactly the point. You don't need a massive budget or a dedicated security team to work through this list, you need an hour and the willingness to look closely at what you might have set up once and never revisited. The businesses that get hit hardest usually aren't the ones missing something exotic. They're the ones with one of these seven ordinary items left unchecked for too long.

Watch Tech Tips: Eye of the Firewall - A Mid-Year IT Review

Get your full checklist on September 16

We'll be walking through all 7 points in detail, and handing out a downloadable version of this checklist, at Think Before the Breach: Building a Cyber-Aware Workplace on September 16.

Register now to save your seat and get your copy.

FAQ: Running Your Own Readiness Check

How often should you run a readiness check like this?

At minimum twice a year, and any time you have significant staff turnover, a new vendor relationship, or a change to how your team works remotely.

What if you don't have an IT team to run this for you?

A managed security provider can run this assessment for you and show you exactly where your holes are without requiring in-house expertise you don't have.

Which of these 7 points matters most if you can only fix one?

Multi-factor authentication. It's the fastest to implement and closes the door on the largest share of common attacks, including most account takeovers.

How do you know if your backups would work in a real incident?

The only way to know is to test a real restore, not just confirm a backup job completed. Schedule this quarterly so you're never finding out for the first time during an emergency.

What belongs in your incident response plan?

Who to call first, both internally and externally, what systems to isolate, how you'll communicate with employees and customers, and who is authorized to make decisions under pressure.

Back to Blog

We Can Help

Call us at (585) 257-2898 or fill out the form below.

Enroll in Our Email Course

Learn How a No-Nonsense IT Strategy Benefits Your Company:
  • Strategies to allocate your IT budget efficiently

  • Enhance cybersecurity defenses on a budget

  • Ensure your technology investments continue to serve your business as it grows