Do you require Multi-Factor Authentication (MFA) for business email and critical business applications?
Are your devices, operating systems, and applications regularly updated with security patches?
Do all employees use unique, strong passwords for work accounts?
Do you provide cybersecurity awareness training to employees at least annually?
Do you use antivirus, endpoint protection, or endpoint detection tools on company devices?
Are critical business data and systems backed up regularly?
Have you tested your ability to restore data from backups within the last 12 months?
Do employees have access only to the systems and data necessary for their jobs?
Do you monitor for suspicious account activity, unauthorized logins, or security alerts?
Do you have a documented process for responding to a cybersecurity incident or data breach?
Do you maintain an inventory of company devices, software, and cloud services?
Do you regularly review and remove unused accounts, devices, or software from your environment?