← All insights

Practical checklist or tool

The One-Hour Cybersecurity Evidence Walkthrough for a Small Office

A time-boxed walkthrough that helps an owner or office manager turn security intentions into observable evidence.

The purpose of the walkthrough

A cybersecurity review should answer more than “Do we have antivirus?” The useful questions are: Which accounts can access important systems? Are updates occurring? Can the business restore its data? Would staff know what to do during a suspicious event?

This one-hour walkthrough is designed for a small office with limited technical staff. It is not a penetration test, audit, certification, or substitute for professional assessment. Its purpose is to identify obvious gaps and create a short action list.

Use a worksheet with five columns: check, evidence seen, owner, priority, and due date. Take notes without recording passwords or sensitive customer information.

Minutes 0–10: Identify the operating environment

  • List the business-critical services: email, accounting, payroll, file storage, scheduling, customer relationship management, payment processing, phones, and websites.
  • Record the administrator or business owner for each service.
  • Identify laptops, desktops, phones, tablets, servers, routers, and other devices used for business.
  • Mark systems that contain personal, health, financial, legal, payroll, or confidential business information.

Evidence may include a current asset list, vendor invoices, administrator screens, or a managed-service report. If a system is not on the list, treat that as a finding rather than assuming it is protected.

Minutes 10–20: Review accounts and access

  • Identify all global, tenant, domain, billing, banking, and backup administrators.
  • Look for former employees, shared accounts, generic accounts, and accounts that have not been used recently.
  • Confirm multifactor authentication for email, remote access, financial systems, administrator accounts, and cloud storage.
  • Check whether emergency or recovery methods are documented and protected.
  • Ask whether access is removed promptly when someone leaves or changes roles.

Evidence includes an access export, recent termination checklist, multifactor settings, and a list of privileged accounts. Do not accept “everyone has MFA” without checking the systems that matter most.

Minutes 20–30: Check devices and updates

  • Confirm that supported operating systems are still receiving security updates.
  • Review whether endpoint protection is active and reporting.
  • Check whether disk encryption is enabled on portable computers.
  • Confirm that screen locks and strong authentication are required.
  • Identify devices that are personally owned, unmanaged, or shared.

The goal is not to inspect every setting manually. It is to determine whether the business can see device status and whether someone is responsible for exceptions.

Minutes 30–40: Test backup understanding

Ask four questions:

  • What data is backed up?
  • How often does the backup run?
  • Can an attacker alter or delete the backup through the same administrator account?
  • When was the last successful restoration test?

Evidence should include backup status, retention settings, protection of the backup account, and a restoration record. A green dashboard is not proof that a file can be restored in a usable form.

Choose one ordinary file and one business-critical item for a controlled restoration test. Record the time, result, and any permissions or application issues.

Minutes 40–50: Review detection and response

  • Ask how suspicious email, account alerts, malware warnings, and payment changes are reported.
  • Confirm that someone receives important security alerts.
  • Review whether cloud audit logs or sign-in logs are retained long enough to investigate.
  • Locate the incident contact sheet.
  • Determine who can authorize account suspension, device isolation, vendor escalation, and customer communication.

Evidence includes a written reporting process, alert-routing configuration, and a recent exercise or incident record. If no one knows who makes the first decision, prioritize that gap.

Minutes 50–60: Prioritize and assign

Classify findings as urgent, important, or planned. Urgent items usually include an unprotected administrator account, an unknown former employee account, failed backups, unsupported internet-facing equipment, or suspected active compromise.

For each finding, assign one person and one date. Avoid action items such as “improve security.” Write “enable multifactor authentication for the billing administrator by Friday” or “complete a restoration test for the accounting database this month.”

What the walkthrough can and cannot prove

Confirmed: CISA recommends foundational practices including multifactor authentication, updates, logging, backups, and encryption. NIST provides a framework for organizing risk-management activities.

Uncertain: A one-hour review cannot prove that a business is secure, compliant, or free from compromise. It can reveal missing ownership, weak documentation, and controls that have never been tested.

Repeat the walkthrough quarterly and after major changes such as a new cloud platform, office move, merger, acquisition, or key employee departure.

The best checklist is one that produces decisions, evidence, and follow-through. A short review performed consistently is more valuable than a large assessment that no one can maintain.

Human-reviewed draft. This article is general information, not an audit or certification.

Sources