Serving North Texas since 2017 817 · 366 · 5829 Contact
Checklist · North Texas IT

DFW Cybersecurity Readiness Checklist

A plain-language checklist any North Texas business can run against itself. No jargon and no scare tactics, just the fundamentals that stop most incidents.

Most security incidents at small and mid-sized businesses have unglamorous causes. They come from missing fundamentals: phishing, stolen passwords, unpatched systems, backups nobody ever tested. Those account for the bulk of real-world damage. This checklist walks the fundamentals in order. Go through it honestly, and treat anything you can’t confidently check off as a candidate for attention. It is a starting point, and it doesn’t replace a full assessment.

1. Identity and access

  • Multifactor authentication (MFA) is on for email, remote access, and every critical application, and it covers every user, admins included.
  • Unique passwords, managed properly in a password manager, so nobody is reusing one login or keeping it on a sticky note.
  • Least privilege. People have access to what their job needs and no more, and admin rights stay tightly held.
  • Offboarding is prompt. When someone leaves, their access is gone the same day, shared accounts included.

2. Devices and patching

  • Every device is inventoried. You actually know what connects to your network.
  • Operating systems and software are patched on a set schedule that doesn’t depend on someone remembering.
  • Modern endpoint protection is deployed everywhere, a real step up from basic antivirus.
  • No unsupported systems running end-of-life Windows or software exposed to the network.

3. Email and phishing

  • Email security filtering is in place against phishing, spoofing, and malicious attachments.
  • Anti-spoofing records (SPF, DKIM, DMARC) are configured for your domain.
  • Staff have had phishing awareness training. Your people are the layer attackers aim at first.

4. Backup and recovery

  • Backups follow the 3-2-1 rule: three copies, two media types, one kept off-site or immutable.
  • Backups are tested by restoring them. Until you have restored one, it is an assumption you are hoping holds up.
  • You know your recovery objectives: how much data and how much time you can afford to lose (RPO and RTO).
Ransomware is the scenario that turns every other gap into a crisis. If you can confidently rebuild your business from clean, off-site, immutable backups, you have taken away most of an attacker’s hold over you. If you can’t, fix that before almost anything else on this list.

5. Monitoring and response

  • Someone is watching. Logs and alerts get monitored in something close to real time, ideally around the clock.
  • You have a written incident response plan that names who to call and what to do, in what order.
  • Contacts are current. You know how to reach your provider, your cyber-insurance carrier, and your legal contact before the day you need them.

6. Compliance and insurance

  • You know which frameworks apply to you, whether that is HIPAA, PCI DSS, CMMC, or SOC 2, based on your industry and contracts.
  • Cyber-insurance requirements are met. Many policies now mandate MFA and other controls, and a gap can void your coverage when you file.

7. People and culture

  • Security has an owner. Someone internal, or your provider, is accountable for it by name.
  • Staff know how to report something suspicious without fear of blame.
  • Leadership reviews security on a schedule, not only after an incident.

What to do with your results

Count the items you couldn’t check off. A handful of gaps is normal and fixable. A long list spread across several sections is a sign it’s worth a structured assessment. Start with identity (MFA), tested backups, and email security, since those three head off the largest share of real-world incidents for a North Texas business.

Frequently asked questions

We're a small DFW business. Are we really a target?
Yes. Most attacks are opportunistic and automated. They scan the internet for missing fundamentals and hit whatever turns up, whatever the company name. Small and mid-sized businesses get caught often precisely because attackers expect weaker defenses. Size is not protection.
If we can only do three things from this checklist, what should they be?
Turn on multifactor authentication everywhere, make sure backups are off-site, immutable, and tested by restoring from them, and put real email security and phishing training in place. Those three address the largest share of real-world incidents.
What's the difference between antivirus and modern endpoint protection?
Traditional antivirus matches known malware signatures. Modern endpoint protection adds behavior-based detection and response, so it can catch suspicious activity it has never seen before and help contain it. Against the threats now in circulation, signatures on their own leave too much through.
How often should we run through a checklist like this?
At least annually, and after any major change, new office, new system, staff turnover, or a new compliance obligation. Security drifts as the business changes, so periodic review keeps the fundamentals from quietly slipping.

Related

Want a second set of eyes on your gaps?

Book a free 30-minute conversation. We'll walk this checklist with you and give you an honest read on where your North Texas business stands. No scare tactics.