Does your company require you to update your passwords with designated complexity requirements at least every three to six months?

Can the general public access your company’s building without using an ID card?

Do you use multi-factor authentication (MFA) for system access? This may include mobile two-factor authentication (2FA), one-time passwords (OTP), and authenticator applications.

Is there regular cybersecurity training for all employees?

Are all software and operating systems on network devices kept up to date?

Are there controls in place to manage access to sensitive data?

Can employees dispose of sensitive information in unsecured bins?

Does your company have an updated cybersecurity policy in place?

Are you compliant with relevant cybersecurity regulations and standards in your industry?

Does your company use firewalls and intrusion detection/prevention systems?

Are your networks segmented to limit the spread of breaches?

Have you conducted a third-party vulnerability assessment or penetration testing within the last year?

Do you require vendors and third parties to comply with your security standards?

Are antivirus programs installed and active on all endpoints?

Do you use a secure email gateway to filter out phishing attempts and malicious content?

Do you encrypt sensitive information both in storage and when you send it electronically?

Does your company regularly back up critical information and systems?