Cyber risk checklist

30-Point Cyber Risk Checklist

A practical cyber risk checklist for small businesses reviewing Microsoft 365, email security, vendors, backups, ransomware readiness, and AI use.

Last Reviewed: July 2026 | Author: Aaron House

Problem

Most small businesses do not fail because they ignored security completely. They fail because nobody has a simple way to see which basic controls are missing, stale, or assumed to be handled by someone else.

Why it matters in 2026

QR phishing, vendor questionnaires, cyber insurance reviews, AI adoption, and Microsoft 365 identity attacks are normal business pressure, not edge cases.

Who this affects

Step-by-step recipe

  1. Check MFA coverage for every user and administrator.
  2. Review email authentication: SPF, DKIM, and DMARC.
  3. Confirm backups are separate from daily user accounts.
  4. Identify vendors with access to email, files, finance, or customer data.
  5. Write down the first 24-hour incident response contacts.
  6. List AI tools in use and what data must never be pasted into them.

Common mistakes

Downloads and next steps

DIY next step

Start with MFA, email authentication, and backup ownership. Those three areas usually reveal whether the rest of the baseline is under control.

CyberHouse CTA

Want us to handle this for you? CyberHouse can help with Microsoft 365 protection, cyber risk cleanup, ransomware readiness, secure automation, and vendor-ready cyber baseline work.

Visit CyberHouse

Related Recipes