Free Resource
Cyber readiness checklist for growing businesses.
A practical self review for checking your governance, business email, staff scam awareness, device access, data handling, backups, cloud tools, vendors, incident response, website, and public business accounts.
Quick Review
71 checks across 9 areas
This checklist now works like a live self assessment. As users tick or untick a box, their total score, category result, and red flags update automatically.
How to use it
Tick only what is already properly in place today. Do not tick something because you plan to fix it later. The goal is to measure your current readiness honestly.
How the score works
Every checked item increases the score. Every unchecked item lowers the score and can create a red flag. Each category also updates separately so you know where the biggest gap is.
Print friendly result
The print button prepares a clean checklist document with your selected ticks, live score, category scores, and top issues to fix. The mobile footer and website navigation are removed from the print version. It does not print the full website page.
The Checklist
Tick each item your business already has in place.
Your score, category result, and red flags update immediately as you tick or untick each item. The print button prepares a clean checklist report instead of printing the full website page.
Governance and Ownership
0/7 checked · 0%
Security works better when ownership is clear. Many SME incidents become worse because nobody knows who owns accounts, backups, vendors, or emergency decisions.
Email and Accounts
0/8 checked · 0%
Email is where invoices, payment instructions, passwords, approvals, and client conversations happen. One weak mailbox can expose the whole business.
Staff Awareness and Payment Fraud
0/8 checked · 0%
Many attacks against small teams begin with a link, fake message, fake invoice, or pressure tactic. Staff need practical rules they can remember under pressure.
Devices and Access Control
0/8 checked · 0%
Business files often sit on staff laptops, phones, personal emails, and shared folders. If access is not controlled, sensitive data can leave the business easily.
Data Protection and Privacy
0/8 checked · 0%
Customer records, staff records, payment details, and business documents should not be scattered without ownership, purpose, access control, or safe sharing rules.
Backup and Recovery
0/8 checked · 0%
Backups are what help a business recover after device loss, accidental deletion, ransomware, cloud lockout, or staff mistakes.
Website and Public Channels
0/8 checked · 0%
Your website, domain, forms, WhatsApp, Google profile, and social media pages are part of your public trust. If they are neglected, customers can be misled.
Cloud Tools and Vendors
0/8 checked · 0%
SMEs often depend on cloud drives, email platforms, vendors, accountants, developers, HR tools, payment tools, and outsourced support without tracking access properly.
Incident Response Readiness
0/8 checked · 0%
When something goes wrong, speed and clarity matter. A simple response plan can reduce confusion, financial loss, and reputational damage.
Dynamic Red Flags
These update based on what is still unticked.
Governance and Ownership
The business has one person responsible for cyber and IT decisions
Security ownership and accountability need to be clearer.
Governance and Ownership
Management reviews cyber and IT risks at least once every quarter
Security ownership and accountability need to be clearer.
Governance and Ownership
There is a written list of business critical systems and accounts
Security ownership and accountability need to be clearer.
Governance and Ownership
There is a basic acceptable use policy for staff devices, email, and internet use
Security ownership and accountability need to be clearer.
Governance and Ownership
Staff know who to contact when there is a security or IT issue
Security ownership and accountability need to be clearer.
Governance and Ownership
New staff and exiting staff follow a documented access checklist
Security ownership and accountability need to be clearer.
Governance and Ownership
Cybersecurity responsibilities are not left only to informal assumptions
Security ownership and accountability need to be clearer.
Email and Accounts
Multi factor authentication is enabled on business email accounts
Email or account controls may expose the business to account takeover or payment fraud.
Email and Accounts
Admin accounts are separate from normal daily user accounts
Email or account controls may expose the business to account takeover or payment fraud.
Email and Accounts
Admin access is limited to only trusted and necessary people
Email or account controls may expose the business to account takeover or payment fraud.
Email and Accounts
Strong passwords are required and reused passwords are discouraged
Email or account controls may expose the business to account takeover or payment fraud.
Email and Accounts
Recovery emails and phone numbers are owned by the business, not random personal accounts
Email or account controls may expose the business to account takeover or payment fraud.
0 to 24 checked
High attention needed
Core protections are missing. Focus first on email MFA, payment verification, former staff access, backups, and emergency contacts.
25 to 41 checked
Partly ready
Some protections exist, but the business still needs stronger ownership, staff awareness, access control, and recovery planning.
42 to 56 checked
Good progress
The business is making progress. Use the red flags to close the most important remaining gaps and formalize responsibilities.
57 to 71 checked
Strong basic readiness
The foundation is strong. A formal review can confirm evidence, test assumptions, and prepare a practical improvement roadmap.
Need Help Reviewing This?
NodeVera can turn this checklist into a practical assessment.
If several items are unclear or missing, book a consultation and we will help you identify the most important next step.

Free Resource
Cyber Readiness Checklist
NodeVera · Securing Businesses. Building Trust.
Governance and Ownership 0/7
Security works better when ownership is clear. Many SME incidents become worse because nobody knows who owns accounts, backups, vendors, or emergency decisions.
| □ | 1. The business has one person responsible for cyber and IT decisions | Notes: ________________________ |
| □ | 2. Management reviews cyber and IT risks at least once every quarter | Notes: ________________________ |
| □ | 3. There is a written list of business critical systems and accounts | Notes: ________________________ |
| □ | 4. There is a basic acceptable use policy for staff devices, email, and internet use | Notes: ________________________ |
| □ | 5. Staff know who to contact when there is a security or IT issue | Notes: ________________________ |
| □ | 6. New staff and exiting staff follow a documented access checklist | Notes: ________________________ |
| □ | 7. Cybersecurity responsibilities are not left only to informal assumptions | Notes: ________________________ |
Email and Accounts 0/8
Email is where invoices, payment instructions, passwords, approvals, and client conversations happen. One weak mailbox can expose the whole business.
| □ | 1. Multi factor authentication is enabled on business email accounts | Notes: ________________________ |
| □ | 2. Admin accounts are separate from normal daily user accounts | Notes: ________________________ |
| □ | 3. Admin access is limited to only trusted and necessary people | Notes: ________________________ |
| □ | 4. Strong passwords are required and reused passwords are discouraged | Notes: ________________________ |
| □ | 5. Recovery emails and phone numbers are owned by the business, not random personal accounts | Notes: ________________________ |
| □ | 6. Former staff email and cloud accounts are disabled immediately after exit | Notes: ________________________ |
| □ | 7. Shared mailboxes and group emails have clear owners | Notes: ________________________ |
| □ | 8. Business email security records such as SPF, DKIM, and DMARC have been reviewed | Notes: ________________________ |
Staff Awareness and Payment Fraud 0/8
Many attacks against small teams begin with a link, fake message, fake invoice, or pressure tactic. Staff need practical rules they can remember under pressure.
| □ | 1. Staff can identify phishing links, fake login pages, and suspicious attachments | Notes: ________________________ |
| □ | 2. Finance and admin staff verify bank account changes by phone before payment | Notes: ________________________ |
| □ | 3. Staff know not to share OTPs, passwords, or verification codes | Notes: ________________________ |
| □ | 4. There is a simple process for reporting suspicious emails, WhatsApp messages, or calls | Notes: ________________________ |
| □ | 5. New staff receive basic cyber safety guidance during onboarding | Notes: ________________________ |
| □ | 6. Staff have been warned about fake invoices and impersonation of directors or vendors | Notes: ________________________ |
| □ | 7. Payment approval requires more than one person for sensitive or unusual transactions | Notes: ________________________ |
| □ | 8. Staff know how to pause and verify urgent requests before acting | Notes: ________________________ |
Devices and Access Control 0/8
Business files often sit on staff laptops, phones, personal emails, and shared folders. If access is not controlled, sensitive data can leave the business easily.
| □ | 1. Work laptops and phones have screen locks or biometric locks enabled | Notes: ________________________ |
| □ | 2. Important devices receive operating system and application updates regularly | Notes: ________________________ |
| □ | 3. Antivirus or endpoint protection is active on work devices | Notes: ________________________ |
| □ | 4. Only necessary people can access sensitive folders, systems, or documents | Notes: ________________________ |
| □ | 5. Business files are not stored only on one personal laptop or phone | Notes: ________________________ |
| □ | 6. Lost or stolen devices can be locked, wiped, or disconnected from business accounts | Notes: ________________________ |
| □ | 7. USB drives and personal storage devices are controlled for sensitive work | Notes: ________________________ |
| □ | 8. Staff do not use personal email accounts for official business documents | Notes: ________________________ |
Data Protection and Privacy 0/8
Customer records, staff records, payment details, and business documents should not be scattered without ownership, purpose, access control, or safe sharing rules.
| □ | 1. The business knows what customer, staff, and vendor data it collects | Notes: ________________________ |
| □ | 2. The business can explain why each type of personal data is collected | Notes: ________________________ |
| □ | 3. Sensitive files are not freely shared in public WhatsApp groups or personal chats | Notes: ________________________ |
| □ | 4. Customer and staff records are stored in a controlled location | Notes: ________________________ |
| □ | 5. Access to personal data is limited to staff who need it for their work | Notes: ________________________ |
| □ | 6. The business has a simple privacy notice or data handling statement | Notes: ________________________ |
| □ | 7. Old records are deleted, archived, or protected instead of being kept carelessly | Notes: ________________________ |
| □ | 8. Documents containing personal or financial information are shared securely | Notes: ________________________ |
Backup and Recovery 0/8
Backups are what help a business recover after device loss, accidental deletion, ransomware, cloud lockout, or staff mistakes.
| □ | 1. Important business files are backed up regularly | Notes: ________________________ |
| □ | 2. Backups are stored in more than one location or cloud account | Notes: ________________________ |
| □ | 3. At least one backup is protected from accidental deletion or ransomware | Notes: ________________________ |
| □ | 4. The business has tested that important files can actually be restored | Notes: ________________________ |
| □ | 5. Critical contacts, invoices, reports, and records are not stored only on one device | Notes: ________________________ |
| □ | 6. There is a plan for continuing work if a laptop, phone, or cloud account becomes unavailable | Notes: ________________________ |
| □ | 7. Backup responsibility is assigned to a named person | Notes: ________________________ |
| □ | 8. The business knows which systems must be restored first after an incident | Notes: ________________________ |
Website and Public Channels 0/8
Your website, domain, forms, WhatsApp, Google profile, and social media pages are part of your public trust. If they are neglected, customers can be misled.
| □ | 1. Website admin login is protected with strong credentials and limited admin users | Notes: ________________________ |
| □ | 2. Website forms are tested and messages are monitored | Notes: ________________________ |
| □ | 3. Domain, hosting, and SSL renewal dates are known and documented | Notes: ________________________ |
| □ | 4. Social media admin access is controlled and not shared carelessly | Notes: ________________________ |
| □ | 5. Public business information is consistent across the website, Google profile, and social pages | Notes: ________________________ |
| □ | 6. Website backups or restore options are available | Notes: ________________________ |
| □ | 7. Old web developers or former staff no longer have unnecessary access | Notes: ________________________ |
| □ | 8. Customers have a trusted way to confirm official payment and contact details | Notes: ________________________ |
Cloud Tools and Vendors 0/8
SMEs often depend on cloud drives, email platforms, vendors, accountants, developers, HR tools, payment tools, and outsourced support without tracking access properly.
| □ | 1. The business keeps a list of software, cloud tools, and vendors it depends on | Notes: ________________________ |
| □ | 2. Vendor accounts are registered with business owned email addresses | Notes: ________________________ |
| □ | 3. Only approved staff can add new users to cloud tools | Notes: ________________________ |
| □ | 4. Important subscriptions and renewals are tracked | Notes: ________________________ |
| □ | 5. Vendor access is removed when a project ends | Notes: ________________________ |
| □ | 6. The business knows where key client files are stored across cloud tools | Notes: ________________________ |
| □ | 7. Sensitive documents are not shared with public links unless necessary | Notes: ________________________ |
| □ | 8. There is a basic review before giving vendors access to business data | Notes: ________________________ |
Incident Response Readiness 0/8
When something goes wrong, speed and clarity matter. A simple response plan can reduce confusion, financial loss, and reputational damage.
| □ | 1. Staff know what to do if an email, WhatsApp account, or device is compromised | Notes: ________________________ |
| □ | 2. The business has a list of emergency contacts for IT, bank, hosting, and key vendors | Notes: ________________________ |
| □ | 3. There is a simple incident log for recording what happened and actions taken | Notes: ________________________ |
| □ | 4. The business knows how to quickly change passwords and revoke suspicious sessions | Notes: ________________________ |
| □ | 5. There is a process for warning affected staff, customers, or partners when necessary | Notes: ________________________ |
| □ | 6. Finance staff know what to do if a suspicious payment instruction is received | Notes: ________________________ |
| □ | 7. The business can identify which systems or accounts are most urgent to recover | Notes: ________________________ |
| □ | 8. A basic post incident review is done after serious mistakes or security events | Notes: ________________________ |
Result Summary
Overall readiness level: High attention needed
Several foundational protections are missing. Start with email access, payment verification, former staff access, backups, and incident contacts.
| Area | Score | Status |
|---|---|---|
| Governance and Ownership | 0/7 | High risk |
| Email and Accounts | 0/8 | High risk |
| Staff Awareness and Payment Fraud | 0/8 | High risk |
| Devices and Access Control | 0/8 | High risk |
| Data Protection and Privacy | 0/8 | High risk |
| Backup and Recovery | 0/8 | High risk |
| Website and Public Channels | 0/8 | High risk |
| Cloud Tools and Vendors | 0/8 | High risk |
| Incident Response Readiness | 0/8 | High risk |
Top issues to fix first:
- Governance and Ownership: The business has one person responsible for cyber and IT decisions
- Governance and Ownership: Management reviews cyber and IT risks at least once every quarter
- Governance and Ownership: There is a written list of business critical systems and accounts
- Governance and Ownership: There is a basic acceptable use policy for staff devices, email, and internet use
- Governance and Ownership: Staff know who to contact when there is a security or IT issue
Recommended next step: assign owners for the top issues, fix the highest risk gaps within 30 days, then repeat the checklist monthly until the business reaches a stable readiness level.
