The readiness checklist: twelve things to do before an attack
This is the list to work through once the panic of reading about incidents has passed. It has twelve items, each tied to a published recommendation, in an order that puts the cheapest and most valuable work first.
Last reviewed 10 October 2026.
How to use the list
Do not try to finish it in a day. Print it, give each line an owner and a date, and tick items off as you verify them rather than as you intend them. A line counts as done when you can show someone the evidence: a screenshot of the setting, a printed contact sheet, a restore log. If you cannot show it, it is not done.
The list is deliberately small. The full CISA and FBI guide runs to dozens of recommendations written for organisations of all sizes, and several concern domain controllers and hypervisors that a ten-person office may not have. We have kept the items that apply almost everywhere, and flagged where the guide goes deeper.
The twelve items
| # | Item | Why it matters in a recovery | Source |
|---|---|---|---|
| 1 | Write down every device and who owns it | You cannot isolate or restore what you did not know existed | CISA and FBI guide: asset management |
| 2 | List your critical systems in restore order | Triage is faster when the decision is made in advance | CISA and FBI guide: prioritise restoration by critical asset list |
| 3 | Keep at least one offline, encrypted backup | Attackers target backups they can reach | CISA and FBI guide: offline backups |
| 4 | Run a restore test | An untested backup is a hope, not a plan | NCSC backups page; CISA guide |
| 5 | Turn on multi-factor sign-in for email and remote access | Compromised credentials are a common way in | CISA and FBI guide: phishing-resistant MFA |
| 6 | Close or protect remote desktop | Exposed remote services are a common route for attackers | CISA and FBI guide: do not expose RDP |
| 7 | Keep software and devices updated | Fixes close holes attackers use | NCSC devices page; CISA guide |
| 8 | Use separate admin and everyday accounts | A phished everyday account should not be an admin | CISA and FBI guide: separate administrator accounts |
| 9 | Run centrally managed protection on every computer | You need visibility across the fleet | CISA and FBI guide: centrally managed antivirus; EDR or allowlisting |
| 10 | Keep logs for as long as you can | Investigators need history to find the way in | CISA and FBI guide: retain logs, a year where possible |
| 11 | Write an incident plan and print it | Your digital copy may be unreachable | CISA and FBI guide: hard copy and offline version |
| 12 | Fill in a contact sheet | Calls in the first hour go faster with numbers ready | CISA and FBI guide: response contacts table |
Notes on the trickier items
Remote access and credentials
The CISA guide treats compromised credentials and exposed remote services as two of the main routes in. It recommends phishing-resistant multi-factor authentication for all services, particularly email, VPNs and accounts that touch critical systems, and says that if MFA is not available on a VPN, teleworkers should use passwords of at least fifteen characters. It also advises auditing which systems use remote desktop, closing unused ports, enforcing lockouts and logging attempts. If you do one thing in this section, enable MFA on email first, because email is how password resets reach every other account.
Updates and old devices
The NCSC says the best protection against malware, including ransomware, is to keep all devices and apps up to date, and recommends replacing devices that no longer receive updates. It adds that you do not need the latest model, only one that is still supported.
Admin rights
The CISA guide advises applying least privilege so users only have the access they need, because attackers often use privileged accounts for network-wide attacks. In a small office this usually means two accounts for your IT person, one for email and browsing and one for administration, and a rule that nobody runs everyday work as an administrator.
Protection software and visibility
CISA recommends a centrally managed antivirus solution and, for stronger control, application allowlisting or endpoint detection and response on all assets, noting that ransomware can follow earlier malware infections. Buying advice belongs elsewhere, and Endpoint Index publishes a buyer's guide for small businesses. For now, the practical question is whether you can see all your computers from one place. If not, put that first.
Logs
The CISA guide asks you to retain and secure logs from network devices, local hosts and cloud services, and to keep and back up logs for critical systems for a minimum of one year, if possible. For a small office, that might simply mean checking how long your email provider and firewall keep records and extending it where there is a setting. Logs are what answers the question "how did they get in".
A suggested four-week order
If you want a sequence, here is one that front-loads the quick wins. This ordering is our suggestion.
- Week one: items 1, 2, 5. A spreadsheet, a short list, and a settings change on email.
- Week two: items 3, 4. Set up the offline backup and run the restore test from the previous page.
- Week three: items 6, 7, 8. Remote access, updates and admin separation, which often need a short conversation with your IT provider.
- Week four: items 9 to 12. Check protection coverage, log retention, and print the plan and contact sheet.
When you have finished, go back to the self-check on the start page and see which answers have changed. Then put a reminder in the calendar to repeat the process, because systems drift, people join and leave, and a plan that was true last spring may not be true this autumn.
Evidence to keep as you go
For each item, keep one piece of evidence in a folder: a dated screenshot of the setting, the exported list, the signed-off plan. It sounds bureaucratic, but it pays off three times. It lets a new colleague see what exists, it makes insurance questionnaires quick to answer, and it shows you quickly when something has quietly changed. Stick to what you can verify, and write "not done" next to anything that is not, because a checklist that claims everything is green is worse than none. See the wider list at StopRansomware.gov, the government hub that the CISA guide points to for further resources.
What to do if you share IT with a provider
Many small businesses rely on a managed service provider. The CISA guide notes that managed service providers have been an infection route in ransomware incidents affecting many client organisations, and advises setting least-privilege access and writing security requirements into contracts, particularly if the provider holds your backups. Ask your provider three questions: who can reach our backups, how is that access protected, and when did you last restore something for a client? Their answers will tell you more than a certificate on the wall.
How we compiled this page
Methodology: we extracted the recommendations that apply to offices without servers, domain controllers or hypervisors from Part 1 of the CISA and FBI guide and cross-checked the device and backup items against the NCSC's protecting your devices page. The ordering and the four-week plan are our own judgement. Where the guides give a number, we quote it; where they do not, we do not invent one.