DFW Cybersecurity Readiness Checklist
A plain-language checklist any North Texas business can run against itself. No jargon and no scare tactics, just the fundamentals that stop most incidents.
Most security incidents at small and mid-sized businesses have unglamorous causes. They come from missing fundamentals: phishing, stolen passwords, unpatched systems, backups nobody ever tested. Those account for the bulk of real-world damage. This checklist walks the fundamentals in order. Go through it honestly, and treat anything you can’t confidently check off as a candidate for attention. It is a starting point, and it doesn’t replace a full assessment.
1. Identity and access
- Multifactor authentication (MFA) is on for email, remote access, and every critical application, and it covers every user, admins included.
- Unique passwords, managed properly in a password manager, so nobody is reusing one login or keeping it on a sticky note.
- Least privilege. People have access to what their job needs and no more, and admin rights stay tightly held.
- Offboarding is prompt. When someone leaves, their access is gone the same day, shared accounts included.
2. Devices and patching
- Every device is inventoried. You actually know what connects to your network.
- Operating systems and software are patched on a set schedule that doesn’t depend on someone remembering.
- Modern endpoint protection is deployed everywhere, a real step up from basic antivirus.
- No unsupported systems running end-of-life Windows or software exposed to the network.
3. Email and phishing
- Email security filtering is in place against phishing, spoofing, and malicious attachments.
- Anti-spoofing records (SPF, DKIM, DMARC) are configured for your domain.
- Staff have had phishing awareness training. Your people are the layer attackers aim at first.
4. Backup and recovery
- Backups follow the 3-2-1 rule: three copies, two media types, one kept off-site or immutable.
- Backups are tested by restoring them. Until you have restored one, it is an assumption you are hoping holds up.
- You know your recovery objectives: how much data and how much time you can afford to lose (RPO and RTO).
5. Monitoring and response
- Someone is watching. Logs and alerts get monitored in something close to real time, ideally around the clock.
- You have a written incident response plan that names who to call and what to do, in what order.
- Contacts are current. You know how to reach your provider, your cyber-insurance carrier, and your legal contact before the day you need them.
6. Compliance and insurance
- You know which frameworks apply to you, whether that is HIPAA, PCI DSS, CMMC, or SOC 2, based on your industry and contracts.
- Cyber-insurance requirements are met. Many policies now mandate MFA and other controls, and a gap can void your coverage when you file.
7. People and culture
- Security has an owner. Someone internal, or your provider, is accountable for it by name.
- Staff know how to report something suspicious without fear of blame.
- Leadership reviews security on a schedule, not only after an incident.
What to do with your results
Count the items you couldn’t check off. A handful of gaps is normal and fixable. A long list spread across several sections is a sign it’s worth a structured assessment. Start with identity (MFA), tested backups, and email security, since those three head off the largest share of real-world incidents for a North Texas business.
Frequently asked questions
We're a small DFW business. Are we really a target?
If we can only do three things from this checklist, what should they be?
What's the difference between antivirus and modern endpoint protection?
How often should we run through a checklist like this?
Related
Want a second set of eyes on your gaps?
Book a free 30-minute conversation. We'll walk this checklist with you and give you an honest read on where your North Texas business stands. No scare tactics.