Tools to help your team prepare, ask better questions, and take a clear next step.
Cyber readiness check
Know what needs your attention.
Ten practical questions about the safeguards behind your security program. Get a readiness snapshot, priorities you can act on, and a PDF to share with your team.
About 5 minutes · No email required · Answers stay in this tab
Question 1 of 10Identity
How consistently is multifactor authentication enforced on email, remote access, and privileged accounts?
Choose the highest level that accurately describes your organization today.
Use your organization’s response plan and qualified responders. Protect life and essential services first; coordinate changes to operational or safety-critical systems with their operators.
01
Activate your response team.
Name an incident lead. Use a trusted phone or other channel outside affected systems. Bring in your technical responders and notify the appropriate leadership and insurer contacts.
02
Contain affected systems.
Coordinate isolation of affected IT devices or networks. Keep devices powered on where safe to preserve volatile evidence. If isolation is impossible and ransomware is spreading, responders may need to power them down.
03
Record and preserve evidence.
Record times and time zones, affected assets, alerts, and actions taken. Preserve relevant logs, messages, and system evidence. Avoid wiping, reimaging, or deleting files before responders capture what they need.
04
Assess the scope and impact.
Identify affected services, accounts, data, and dependencies. Separate confirmed facts from assumptions. Reassess containment as responders learn more about the incident.
05
Secure access and recovery assets.
Have responders address compromised accounts and sessions from a known-clean device. Protect backups and their administration paths. Preserve clean recovery copies before making changes.
06
Coordinate communications.
Agree on one source of status updates. Work with leadership, counsel, and your insurer to determine notifications and reporting to authorities. Share approved facts through trusted channels.
07
Restore in a controlled sequence.
Have responders validate containment and address the entry path before reconnecting systems. Restore from known-good sources, verify essential services, and monitor closely for renewed activity.
08
Capture lessons and assign owners.
Document the timeline, decisions, and recovery results. Assign owners and dates to improvements. Update your response plan and exercise the changes.
A pop-up says your computer is infected, an alarm is sounding, and there's a phone number for "Microsoft Support." That's scareware. These pages are built to make people panic and then call, click, or pay before they stop to think.
As part of Cybersecurity Awareness Month, we put together this one-page guide for staff at the organizations we support. It covers how these scams start, the warning signs, and what to do if one appears on your screen. Print it, post it, and share it with your team.