Cybersecurity Risk Assessment Checklist
A useful cybersecurity assessment looks beyond antivirus and firewalls. It evaluates how access is granted, how systems are maintained, how users work, how data is protected, and how the organization will recover.
Identity and access
- MFA is required for remote, cloud, and administrative access.
- Administrative accounts are separate, limited, and reviewed.
- Onboarding and offboarding are documented and timely.
- Emergency-access accounts are controlled and tested.
Endpoints and applications
- Supported operating systems and applications are patched.
- Endpoint protection or EDR is deployed and monitored.
- Encryption is enforced where appropriate.
- Device inventory, ownership, and lost-device response are documented.
Email and collaboration
- Anti-phishing and malicious-content protections are configured.
- External forwarding and risky sharing are controlled.
- Domain authentication and administrative roles are reviewed.
- Users receive practical security awareness training.
Network and remote access
- Firewalls and firmware are maintained.
- Guest, IoT, camera, voice, server, and management traffic are segmented where appropriate.
- VPN and remote access require strong authentication.
- Internet failover and critical network power are considered.
Backup and recovery
- Critical data and cloud services are included in the backup strategy.
- Backup access is protected and separated where possible.
- Representative restores are tested and documented.
- Recovery ownership, communication, and priorities are defined.
Vendors and governance
- Critical vendors, contracts, access, and dependencies are known.
- Policies reflect actual practices and responsible owners.
- Incident escalation and external contacts are documented.
- Leadership receives a prioritized risk and remediation plan.
This checklist supports readiness and planning; it is not a formal audit or compliance certification.
