Your Free Cybersecurity Checklist

A step-by-step guide to protect your business from common cyber threats

  1. Strong, Unique Passwords

    Use a password manager to generate and store long, random passwords for every account. Never reuse passwords.

  2. Multi-Factor Authentication (MFA)

    Turn on MFA everywhere you can — email, bank portals, cloud services — to block attackers even if a password is stolen.

  3. Keep Software & Devices Updated

    Enable automatic updates for your OS, browsers, and key applications. Patches close security holes fast.

  4. 3-2-1 Data Backups

    Follow the 3-2-1 rule:

    • 3 copies of your data
    • 2 different media types (local drive + USB)
    • 1 copy offsite/offline
  5. Antivirus & Anti-Malware

    Install a reputable security suite on every workstation and server. Schedule daily scans and real-time protection.

  6. Firewall & Network Security

    Enable hardware or software firewalls to block unauthorized access. Segment guest Wi-Fi from your corporate network.

  7. Employee Training

    Run quarterly phishing drills. Teach staff to spot suspicious emails, links, and attachments before they click.

  8. Secure Remote Access

    Require VPN or zero-trust tools for offsite logins. Disable remote desktop unless absolutely necessary.

  9. Least Privilege Principle

    Give each user the minimum access they need. Remove admin rights from daily-use accounts.

  10. Encryption

    Encrypt sensitive files at rest (disk encryption) and in transit (HTTPS, SFTP) to keep data unreadable if intercepted.

  11. Incident Response Plan

    Document who to call, how to isolate systems, and where your offline backups live. Test the plan at least once a year.

  12. Vendor & Partner Security

    Require proof of security practices from any third party handling your data. Include cybersecurity clauses in contracts.

  13. Vulnerability Scanning & Audits

    Run monthly scans of your network and public-facing systems. Patch or remove any outdated services.

  14. Log Monitoring & Alerts

    Centralize system and access logs. Set up alerts for unusual login locations, repeated failures, or large file transfers.

  15. Policy Documentation & Review

    Write simple security policies (password rules, device usage, data classification). Review and update them every 6 months.

Tip: Tick off each item as you complete it, and revisit the checklist quarterly to stay ahead of evolving threats.