Phenicie Business Management

Business Security Checklist

A practical, operations-ready checklist covering web security, identity, compliance, and incident response for Montana businesses.

Use this list during quarterly reviews, tabletop exercises, or when onboarding new staff. Questions? Contact our security team.

Website & Hosting Security

  • SSL/TLS enabled and auto-renewed (verify Cloudflare settings).
  • Strict Content-Security-Policy with no unsafe-inline or unsafe-eval directives.
  • All scripts sourced from trusted domains with no mixed content warnings.
  • Cloudflare Bot Management enabled and tuned for your traffic patterns.
  • Regular vulnerability scans completed through Detectify and the PBM AI scan pipeline.
  • Dark web exposure monitored via Have I Been Pwned, AbuseIPDB, and VirusTotal.
  • Backup retention policy verified with Axcient for restore readiness.
  • Administrative interfaces protected with MFA and IP restrictions.
  • Web application firewall (WAF) rules reviewed and tested monthly.
  • Google Analytics 4 and contact forms configured to anonymize user IP data.

Endpoint & Network Security

  • Atera device inventory reviewed weekly to ensure every endpoint checks in.
  • Huntress agent installed and reporting on all workstations and servers.
  • IronScales and Microsoft Defender policies synchronized.
  • No external RDP or VPN access is permitted without MFA.
  • Firewall firmware (SonicWall or Ubiquiti) kept fully up to date.
  • Network segmentation implemented for office, guest, and server VLANs.
  • Local Wi-Fi credentials rotated at least quarterly.
  • Axcient backup jobs tested quarterly for successful restores.

Identity & Access Management

  • All user accounts provisioned on business domains (no personal email accounts).
  • Microsoft 365 Conditional Access and MFA enforced for every user.
  • Administrative roles audited monthly to maintain least privilege.
  • Passwords rotated regularly or stored inside an enterprise password manager.
  • Departed user accounts disabled immediately and licenses reclaimed.
  • Audit logs retained and reviewed monthly for anomalous activity.

Data Protection & Compliance

  • Data classification policy published for confidential, internal, and public data.
  • Encryption in transit (TLS 1.2+) and at rest applied across Cloudflare and Microsoft 365.
  • Client data is never stored locally without strong encryption controls.
  • Privacy Policy disclosures include Cloudflare, GA4, and form usage for transparency.
  • Compliance mappings for HIPAA, SOC 2, and PCI tracked within Prisma or Supabase.
  • Data retention policy reviewed and approved annually.
  • Client data deletion process exercised at least once per year.

Email & Communication Security

  • SPF, DKIM, and DMARC aligned for phenicie.com with monitoring for failures.
  • SocketLabs SMTP and Injection API credentials stored securely and rotated as needed.
  • IronScales phishing simulations executed quarterly with user scoring.
  • Report Phish button functional in Outlook and routed to security response.
  • External email banner enabled to highlight messages from unknown senders.
  • Sensitive information shared via encrypted channels rather than plain email.

Incident Response & Monitoring

  • SOC dashboards (Huntress, Atera, IronScales) reviewed daily for alerts.
  • Incident response runbook stored in Microsoft Teams and updated quarterly.
  • 24/7 monitoring confirmed for Huntress, Atera, and IronScales agents.
  • Axcient backup failures configured to alert immediately.
  • Breach notification contact tree validated with current phone and email details.
  • Tabletop exercises conducted periodically to rehearse breach response.

Physical & Administrative Security

  • Office access controlled with cameras and badge or key systems.
  • Server and network hardware secured in locked, labeled enclosures.
  • Visitor log maintained for all non-employees entering secure areas.
  • Disaster recovery plan stored offsite and verified.
  • Insurance and cyber liability policies reviewed annually with your broker.
  • Drug and alcohol policy enforced for all field technicians.

Client-Facing Assurance

  • Security scan privacy disclosure posted at phenicie.com/security-scan.
  • Terms of Service and Privacy Policy linked globally in the site footer.
  • Free Security Scan workflow validated with anonymized logging.
  • Client security summary reports delivered quarterly.
  • Client portal requires MFA before access to reports or tickets.