Cybersecurity Advisory Services

Cybersecurity Policy Checklist

A simple starting point for small and mid-sized businesses. You don’t need everything—start with what matters most.

Core Policies

Policy Description In Place
Acceptable UseHow employees use systems, email, and internet
Password / MFAPassword rules and multi-factor authentication
Access ControlWho has access to what systems and data
Device SecurityLaptops, phones, and endpoint protection

Data & Risk

Data ProtectionHow sensitive data is stored and handled
Backup & RecoveryBackup frequency and restore capability
Vendor ManagementTracking and evaluating third-party risk
Risk ManagementIdentifying and tracking key risks

Incident Readiness

Incident ResponseSteps to take during a security event
Security AwarenessBasic employee training (phishing, etc.)
Logging & MonitoringAbility to detect suspicious activity

Notes / Gaps