CYBERSECURITY / PRACTICAL GUIDE

What to check in your business security

Questions to ask about account access, computer protection, backups, and security alerts. Geekland IT can help a business work toward HIPAA or another framework, and that help does not certify compliance.

Written policies matter, but check how your systems are actually configured and who manages them. These questions are a starting point for a security review.

Check the controls in use.

Review user accounts, managed computers, file sharing, and backups. Compare the settings with your security policies.

  • Who has access to important accounts and business files?
  • Which devices are managed and kept up to date?
  • What information is backed up, and how would it be restored?
  • Who reviews an alert and takes the next step?

Know who handles security alerts.

Ask who reviews alerts, what they investigate, and how staff report suspicious messages or activity.

Every security control needs someone responsible for managing it.

Prioritize the gaps.

List the gaps, assess their impact, and decide which improvements should come first. Assign responsibility and a timetable for each.

Back to resources