Security Baseline Checklist

A practical first-pass checklist for smaller businesses that do not have an internal security owner.

Goal: identify what is covered, what is missing, and who owns the next step before an incident, customer question, or insurance renewal forces the conversation.

1. Identity and access

2. Devices and patching

3. Email and phishing protection

4. Backups and recovery

5. Monitoring and response

6. Evidence to keep

EvidenceWhy it mattersSuggested cadence
MFA coverage reportShows whether account protection is actually enforced.Monthly or before renewals
Endpoint protection statusProves devices are covered and unhealthy devices are visible.Monthly
Backup restore testShows recovery is real, not assumed.Quarterly
Admin access reviewReduces blast radius and supports customer/insurance questions.Quarterly
Open-risk roadmapKeeps improvement tied to business decisions and budget.Monthly owner review
Use this as a baseline, not a certification claim. Regulated frameworks can be layered later when the business needs them. The first step is making security ownership, evidence, and remediation visible.