The readiness checklist: twelve things to do before an attack

This is the list to work through once the panic of reading about incidents has passed. It has twelve items, each tied to a published recommendation, in an order that puts the cheapest and most valuable work first.

Last reviewed 10 October 2026.

How to use the list

Do not try to finish it in a day. Print it, give each line an owner and a date, and tick items off as you verify them rather than as you intend them. A line counts as done when you can show someone the evidence: a screenshot of the setting, a printed contact sheet, a restore log. If you cannot show it, it is not done.

The list is deliberately small. The full CISA and FBI guide runs to dozens of recommendations written for organisations of all sizes, and several concern domain controllers and hypervisors that a ten-person office may not have. We have kept the items that apply almost everywhere, and flagged where the guide goes deeper.

The twelve items

Twelve readiness items
#ItemWhy it matters in a recoverySource
1Write down every device and who owns itYou cannot isolate or restore what you did not know existedCISA and FBI guide: asset management
2List your critical systems in restore orderTriage is faster when the decision is made in advanceCISA and FBI guide: prioritise restoration by critical asset list
3Keep at least one offline, encrypted backupAttackers target backups they can reachCISA and FBI guide: offline backups
4Run a restore testAn untested backup is a hope, not a planNCSC backups page; CISA guide
5Turn on multi-factor sign-in for email and remote accessCompromised credentials are a common way inCISA and FBI guide: phishing-resistant MFA
6Close or protect remote desktopExposed remote services are a common route for attackersCISA and FBI guide: do not expose RDP
7Keep software and devices updatedFixes close holes attackers useNCSC devices page; CISA guide
8Use separate admin and everyday accountsA phished everyday account should not be an adminCISA and FBI guide: separate administrator accounts
9Run centrally managed protection on every computerYou need visibility across the fleetCISA and FBI guide: centrally managed antivirus; EDR or allowlisting
10Keep logs for as long as you canInvestigators need history to find the way inCISA and FBI guide: retain logs, a year where possible
11Write an incident plan and print itYour digital copy may be unreachableCISA and FBI guide: hard copy and offline version
12Fill in a contact sheetCalls in the first hour go faster with numbers readyCISA and FBI guide: response contacts table

Notes on the trickier items

Remote access and credentials

The CISA guide treats compromised credentials and exposed remote services as two of the main routes in. It recommends phishing-resistant multi-factor authentication for all services, particularly email, VPNs and accounts that touch critical systems, and says that if MFA is not available on a VPN, teleworkers should use passwords of at least fifteen characters. It also advises auditing which systems use remote desktop, closing unused ports, enforcing lockouts and logging attempts. If you do one thing in this section, enable MFA on email first, because email is how password resets reach every other account.

Updates and old devices

The NCSC says the best protection against malware, including ransomware, is to keep all devices and apps up to date, and recommends replacing devices that no longer receive updates. It adds that you do not need the latest model, only one that is still supported.

Admin rights

The CISA guide advises applying least privilege so users only have the access they need, because attackers often use privileged accounts for network-wide attacks. In a small office this usually means two accounts for your IT person, one for email and browsing and one for administration, and a rule that nobody runs everyday work as an administrator.

Protection software and visibility

CISA recommends a centrally managed antivirus solution and, for stronger control, application allowlisting or endpoint detection and response on all assets, noting that ransomware can follow earlier malware infections. Buying advice belongs elsewhere, and Endpoint Index publishes a buyer's guide for small businesses. For now, the practical question is whether you can see all your computers from one place. If not, put that first.

Logs

The CISA guide asks you to retain and secure logs from network devices, local hosts and cloud services, and to keep and back up logs for critical systems for a minimum of one year, if possible. For a small office, that might simply mean checking how long your email provider and firewall keep records and extending it where there is a setting. Logs are what answers the question "how did they get in".

A suggested four-week order

If you want a sequence, here is one that front-loads the quick wins. This ordering is our suggestion.

  1. Week one: items 1, 2, 5. A spreadsheet, a short list, and a settings change on email.
  2. Week two: items 3, 4. Set up the offline backup and run the restore test from the previous page.
  3. Week three: items 6, 7, 8. Remote access, updates and admin separation, which often need a short conversation with your IT provider.
  4. Week four: items 9 to 12. Check protection coverage, log retention, and print the plan and contact sheet.

When you have finished, go back to the self-check on the start page and see which answers have changed. Then put a reminder in the calendar to repeat the process, because systems drift, people join and leave, and a plan that was true last spring may not be true this autumn.

Evidence to keep as you go

For each item, keep one piece of evidence in a folder: a dated screenshot of the setting, the exported list, the signed-off plan. It sounds bureaucratic, but it pays off three times. It lets a new colleague see what exists, it makes insurance questionnaires quick to answer, and it shows you quickly when something has quietly changed. Stick to what you can verify, and write "not done" next to anything that is not, because a checklist that claims everything is green is worse than none. See the wider list at StopRansomware.gov, the government hub that the CISA guide points to for further resources.

What to do if you share IT with a provider

Many small businesses rely on a managed service provider. The CISA guide notes that managed service providers have been an infection route in ransomware incidents affecting many client organisations, and advises setting least-privilege access and writing security requirements into contracts, particularly if the provider holds your backups. Ask your provider three questions: who can reach our backups, how is that access protected, and when did you last restore something for a client? Their answers will tell you more than a certificate on the wall.

How we compiled this page

Methodology: we extracted the recommendations that apply to offices without servers, domain controllers or hypervisors from Part 1 of the CISA and FBI guide and cross-checked the device and backup items against the NCSC's protecting your devices page. The ordering and the four-week plan are our own judgement. Where the guides give a number, we quote it; where they do not, we do not invent one.

Previous: Backups Next: Reporting