Cyber Security Checklist

The controls that stop most real-world attacks.

Checklist steps

  1. Enforce MFA everywhere

    Especially email, admin panels and finance systems.

  2. Patch systems on a schedule

    Operating systems, browsers and plugins.

  3. Verify backups and restores

    Offline copy tested at least quarterly.

  4. Review user access

    Remove leavers, drop unused admin rights.

  5. Run phishing awareness training

    Simulate and coach, do not punish.

  6. Secure devices

    Disk encryption, screen lock, antivirus or EDR.

  7. Write and test the incident plan

    Who to call, in what order, with what evidence.

Frequently asked questions

How long does this take?

Around 345 minutes end to end once the team knows the steps. Times per step are listed above.

Can I edit this checklist?

Yes. Save it to LemPlates and you can add, remove or reorder steps, assign owners and set due dates.

How often should this be run?

Run it every time the process happens and review the steps at least every six months.