10 questions every small and growing business should answer before a security or operational problem becomes an incident
This checklist is a practical self-review, not a finding that your organization is vulnerable or compromised. Use it to identify areas that deserve a clearer owner, documented process, or deeper review.
Do all staff and contractors use individual business accounts rather than shared logins?
Why it matters: Individual identity makes access review, offboarding, and accountability possible.
Is MFA enabled on business email, administrator accounts, finance tools, and other high-impact systems?
Why it matters: MFA reduces the impact of stolen or reused passwords.
Can you quickly identify and remove access for people who no longer work with the business?
Why it matters: Dormant accounts and forgotten access increase avoidable exposure.
Are administrator privileges limited and separated from routine day-to-day accounts where practical?
Why it matters: Reducing standing privilege limits the impact of account compromise and mistakes.
Do you know who controls your domain, DNS, business email, and recovery methods?
Why it matters: Loss of control over these systems can disrupt customer communications and account recovery.
Does your business verify unusual payment, bank-detail, or wire-change requests through a second trusted channel?
Why it matters: Independent verification helps reduce business-email-compromise and payment-diversion risk.
Do you know which vendors and external tools can access business data or critical workflows?
Why it matters: Third-party dependencies can become operational and security dependencies.
Are critical files and systems backed up, and has the business confirmed it can restore what matters?
Why it matters: A backup is useful only when restoration is understood and tested.
Can you identify where customer, employee, financial, or other sensitive information is stored and who can access it?
Why it matters: Basic data visibility supports practical security and compliance decisions.
If one person, account, device, or online service became unavailable today, does the business have a workable fallback?
Why it matters: Operational single points of failure can turn small incidents into business interruptions.
Need help deciding what to fix first?
The GEM Business Security & Operations Review is a bounded $199 founding review for qualified small and growing businesses. It reviews access, public exposure, operational dependencies, incident readiness, and immediate priorities, then produces prioritized written findings and a 30-day action plan. It does not include destructive testing, unlimited remediation, legal advice, or automatic service activation.
Review the founding scope