When we onboard a business we run the same assessment, because the difference between a survivable incident and a fatal one comes down to a short list of things that were either done or not done months earlier.
Backup and recovery
- At least one backup copy is off-site and cannot be deleted with production credentials.
- Somebody has performed a real restore in the last twelve months and recorded how long it took.
- Backups include the line-of-business database, not just user documents.
- Sync tools like OneDrive are not being counted as backup.
Identity
- MFA is enforced on email, VPN and remote access — with no legacy authentication exceptions left open.
- Nobody works day-to-day in an account with domain or global admin rights.
- Accounts for departed staff are disabled the same day, every time.
- Service accounts have documented owners and rotated credentials.
Surface area
- No RDP or management interface is published directly to the internet.
- Patching is automated and reported, with compliance above 95%.
- Cameras, printers and IoT devices sit on their own network segment.
- There is a written incident response plan naming who calls whom, in what order.
Most new clients pass six or seven of the twelve. The gaps are rarely exotic — they're the boring items that nobody owned. Assigning ownership is most of the fix.