Phenicie Business Management
Business Security Checklist
A practical starting point for reviewing accounts, devices, backups, and incident readiness for Montana businesses.
Use this list to identify questions and owners. It is not a completed assessment or proof of compliance. Questions? Contact our security team.
Accounts and access
- List business accounts, administrators, and vendor access. Assign an owner to each.
- Verify multifactor authentication and recovery methods for email and critical applications.
- Use unique passwords and an approved password manager; do not email passwords.
- Remove access promptly when staff or vendors leave.
Computers and networks
- Keep an inventory of supported devices, applications, and network equipment.
- Verify updates and endpoint protection are operating, and assign someone to investigate failures.
- Separate guest Wi-Fi and connected devices from sensitive business systems.
- Document remote access and restrict it to authorized people and services.
Backups and recovery
- Identify the files and applications needed to resume operations.
- Confirm backup coverage, retention, access protection, and failure alerts.
- Test representative restores and record the date, result, and recovery steps.
- Keep support contacts and recovery instructions available if email or the office is unavailable.
Email and payment safety
- Verify unusual payment or bank-detail changes using a trusted contact method.
- Teach staff how to report phishing and unexpected authentication prompts.
- Review business-domain email authentication with your provider.
- Use approved channels for sensitive client information.
Incident preparation
- Document who to contact for a suspected compromise, outage, or lost device.
- Agree on response responsibilities and escalation with your IT provider.
- Preserve suspicious messages and relevant evidence; avoid unapproved cleanup tools.
- Review the plan with staff and assign owners to unresolved actions.
Business oversight
- Review service agreements, insurance requirements, and relevant compliance obligations.
- Check website ownership, renewal responsibilities, form delivery, and backups.
- Record verified controls separately from items that still need evidence.
- Agree scope, cost, and timing before remediation or additional technical work.