Skip to main content
GEMEnterprise
GEM readiness resource

10 questions every small and growing business should answer before a security or operational problem becomes an incident

This checklist is a practical self-review, not a finding that your organization is vulnerable or compromised. Use it to identify areas that deserve a clearer owner, documented process, or deeper review.

1

Do all staff and contractors use individual business accounts rather than shared logins?

Why it matters: Individual identity makes access review, offboarding, and accountability possible.

2

Is MFA enabled on business email, administrator accounts, finance tools, and other high-impact systems?

Why it matters: MFA reduces the impact of stolen or reused passwords.

3

Can you quickly identify and remove access for people who no longer work with the business?

Why it matters: Dormant accounts and forgotten access increase avoidable exposure.

4

Are administrator privileges limited and separated from routine day-to-day accounts where practical?

Why it matters: Reducing standing privilege limits the impact of account compromise and mistakes.

5

Do you know who controls your domain, DNS, business email, and recovery methods?

Why it matters: Loss of control over these systems can disrupt customer communications and account recovery.

6

Does your business verify unusual payment, bank-detail, or wire-change requests through a second trusted channel?

Why it matters: Independent verification helps reduce business-email-compromise and payment-diversion risk.

7

Do you know which vendors and external tools can access business data or critical workflows?

Why it matters: Third-party dependencies can become operational and security dependencies.

8

Are critical files and systems backed up, and has the business confirmed it can restore what matters?

Why it matters: A backup is useful only when restoration is understood and tested.

9

Can you identify where customer, employee, financial, or other sensitive information is stored and who can access it?

Why it matters: Basic data visibility supports practical security and compliance decisions.

10

If one person, account, device, or online service became unavailable today, does the business have a workable fallback?

Why it matters: Operational single points of failure can turn small incidents into business interruptions.

Need help deciding what to fix first?

The GEM Business Security & Operations Review is a bounded $199 founding review for qualified small and growing businesses. It reviews access, public exposure, operational dependencies, incident readiness, and immediate priorities, then produces prioritized written findings and a 30-day action plan. It does not include destructive testing, unlimited remediation, legal advice, or automatic service activation.

Review the founding scope