NodeVera Cyber IT & Services logo
Back to Home

Free Resource

Cyber readiness checklist for growing businesses.

A practical self review for checking your governance, business email, staff scam awareness, device access, data handling, backups, cloud tools, vendors, incident response, website, and public business accounts.

Quick Review

71 checks across 9 areas

This checklist now works like a live self assessment. As users tick or untick a box, their total score, category result, and red flags update automatically.

Governance and Ownership
Email and Accounts
Staff Awareness and Payment Fraud
Devices and Access Control
Data Protection and Privacy
Backup and Recovery
Website and Public Channels
Cloud Tools and Vendors
Incident Response Readiness

How to use it

Tick only what is already properly in place today. Do not tick something because you plan to fix it later. The goal is to measure your current readiness honestly.

How the score works

Every checked item increases the score. Every unchecked item lowers the score and can create a red flag. Each category also updates separately so you know where the biggest gap is.

Print friendly result

The print button prepares a clean checklist document with your selected ticks, live score, category scores, and top issues to fix. The mobile footer and website navigation are removed from the print version. It does not print the full website page.

The Checklist

Tick each item your business already has in place.

Your score, category result, and red flags update immediately as you tick or untick each item. The print button prepares a clean checklist report instead of printing the full website page.

Governance and Ownership

0/7 checked · 0%

Security works better when ownership is clear. Many SME incidents become worse because nobody knows who owns accounts, backups, vendors, or emergency decisions.

First practical step: Assign one accountable owner, list your critical systems, and create a simple onboarding and offboarding access checklist.

Email and Accounts

0/8 checked · 0%

Email is where invoices, payment instructions, passwords, approvals, and client conversations happen. One weak mailbox can expose the whole business.

First practical step: Start with MFA on admin and finance accounts, then review recovery details, former staff access, shared passwords, and email security records.

Staff Awareness and Payment Fraud

0/8 checked · 0%

Many attacks against small teams begin with a link, fake message, fake invoice, or pressure tactic. Staff need practical rules they can remember under pressure.

First practical step: Teach staff to pause before clicking, verify payment changes by phone, report suspicious messages quickly, and never share OTPs or passwords.

Devices and Access Control

0/8 checked · 0%

Business files often sit on staff laptops, phones, personal emails, and shared folders. If access is not controlled, sensitive data can leave the business easily.

First practical step: Lock devices, remove former staff access, keep devices updated, and limit sensitive folders to only people who truly need them.

Data Protection and Privacy

0/8 checked · 0%

Customer records, staff records, payment details, and business documents should not be scattered without ownership, purpose, access control, or safe sharing rules.

First practical step: List the data you collect, where it is stored, who can access it, why you keep it, and how it should be shared or deleted.

Backup and Recovery

0/8 checked · 0%

Backups are what help a business recover after device loss, accidental deletion, ransomware, cloud lockout, or staff mistakes.

First practical step: Identify your most important files, back them up in more than one place, and test that you can restore them before an emergency happens.

Website and Public Channels

0/8 checked · 0%

Your website, domain, forms, WhatsApp, Google profile, and social media pages are part of your public trust. If they are neglected, customers can be misled.

First practical step: Secure admin access, document renewal dates, remove old vendor access, test forms, and publish one trusted payment and contact confirmation process.

Cloud Tools and Vendors

0/8 checked · 0%

SMEs often depend on cloud drives, email platforms, vendors, accountants, developers, HR tools, payment tools, and outsourced support without tracking access properly.

First practical step: Create a vendor and software register, confirm who has access, remove old vendors, and stop sharing sensitive files with public links.

Incident Response Readiness

0/8 checked · 0%

When something goes wrong, speed and clarity matter. A simple response plan can reduce confusion, financial loss, and reputational damage.

First practical step: Create a one page incident response contact list and write the first actions for email compromise, payment fraud, lost device, and website issues.

Dynamic Red Flags

These update based on what is still unticked.

Governance and Ownership

The business has one person responsible for cyber and IT decisions

Security ownership and accountability need to be clearer.

Governance and Ownership

Management reviews cyber and IT risks at least once every quarter

Security ownership and accountability need to be clearer.

Governance and Ownership

There is a written list of business critical systems and accounts

Security ownership and accountability need to be clearer.

Governance and Ownership

There is a basic acceptable use policy for staff devices, email, and internet use

Security ownership and accountability need to be clearer.

Governance and Ownership

Staff know who to contact when there is a security or IT issue

Security ownership and accountability need to be clearer.

Governance and Ownership

New staff and exiting staff follow a documented access checklist

Security ownership and accountability need to be clearer.

Governance and Ownership

Cybersecurity responsibilities are not left only to informal assumptions

Security ownership and accountability need to be clearer.

Email and Accounts

Multi factor authentication is enabled on business email accounts

Email or account controls may expose the business to account takeover or payment fraud.

Email and Accounts

Admin accounts are separate from normal daily user accounts

Email or account controls may expose the business to account takeover or payment fraud.

Email and Accounts

Admin access is limited to only trusted and necessary people

Email or account controls may expose the business to account takeover or payment fraud.

Email and Accounts

Strong passwords are required and reused passwords are discouraged

Email or account controls may expose the business to account takeover or payment fraud.

Email and Accounts

Recovery emails and phone numbers are owned by the business, not random personal accounts

Email or account controls may expose the business to account takeover or payment fraud.

0 to 24 checked

High attention needed

Core protections are missing. Focus first on email MFA, payment verification, former staff access, backups, and emergency contacts.

25 to 41 checked

Partly ready

Some protections exist, but the business still needs stronger ownership, staff awareness, access control, and recovery planning.

42 to 56 checked

Good progress

The business is making progress. Use the red flags to close the most important remaining gaps and formalize responsibilities.

57 to 71 checked

Strong basic readiness

The foundation is strong. A formal review can confirm evidence, test assumptions, and prepare a practical improvement roadmap.

Need Help Reviewing This?

NodeVera can turn this checklist into a practical assessment.

If several items are unclear or missing, book a consultation and we will help you identify the most important next step.

Book Review