Phenicie Business Management

Business Security Checklist

A practical starting point for reviewing accounts, devices, backups, and incident readiness for Montana businesses.

Use this list to identify questions and owners. It is not a completed assessment or proof of compliance. Questions? Contact our security team.

Accounts and access

  • List business accounts, administrators, and vendor access. Assign an owner to each.
  • Verify multifactor authentication and recovery methods for email and critical applications.
  • Use unique passwords and an approved password manager; do not email passwords.
  • Remove access promptly when staff or vendors leave.

Computers and networks

  • Keep an inventory of supported devices, applications, and network equipment.
  • Verify updates and endpoint protection are operating, and assign someone to investigate failures.
  • Separate guest Wi-Fi and connected devices from sensitive business systems.
  • Document remote access and restrict it to authorized people and services.

Backups and recovery

  • Identify the files and applications needed to resume operations.
  • Confirm backup coverage, retention, access protection, and failure alerts.
  • Test representative restores and record the date, result, and recovery steps.
  • Keep support contacts and recovery instructions available if email or the office is unavailable.

Email and payment safety

  • Verify unusual payment or bank-detail changes using a trusted contact method.
  • Teach staff how to report phishing and unexpected authentication prompts.
  • Review business-domain email authentication with your provider.
  • Use approved channels for sensitive client information.

Incident preparation

  • Document who to contact for a suspected compromise, outage, or lost device.
  • Agree on response responsibilities and escalation with your IT provider.
  • Preserve suspicious messages and relevant evidence; avoid unapproved cleanup tools.
  • Review the plan with staff and assign owners to unresolved actions.

Business oversight

  • Review service agreements, insurance requirements, and relevant compliance obligations.
  • Check website ownership, renewal responsibilities, form delivery, and backups.
  • Record verified controls separately from items that still need evidence.
  • Agree scope, cost, and timing before remediation or additional technical work.