(208) 352-0775

Cybersecurity Essentials

Protection Checklist for Businesses & Individuals

Business email compromises cost American companies over $2.7 billion annually, with small businesses and professional services firms particularly vulnerable. According to the FBI's Internet Crime Complaint Center, wire transfer fraud attempts have increased 65% in the past two years, with attackers frequently impersonating trusted business contacts.

Cybercriminals target small firms because they often lack dedicated IT security staff while handling significant financial transactions and sensitive client data. A single successful breach can result in substantial financial loss, regulatory penalties, reputational damage, and potential malpractice claims.

This checklist provides essential security measures every small business should implement immediately to protect its business, clients, and reputation.

IMMEDIATE ACTION ITEMS

The following items require your direct action. Complete these in order of priority.

1. Password Security. THIS IS YOUR HIGHEST PRIORITY

According to Verizon's 2024 Data Breach Investigations Report, 81% of hacking-related breaches involve stolen or weak passwords. Complex passwords are essential, but most people struggle with creating and managing them across dozens of accounts.

ACTION ITEMS: Update passwords for all of your business, financial, and personal accounts. For accounts we manage on your behalf, we'll update passwords and provide them to you securely.
Important: Never send or allow to be sent to you passwords by email or text. Use an end-to-end encryption service like signal.org. Otherwise, your passwords may be exposed to cybercriminals.

  • Generate strong passwords automatically using a password generator.
    Free tool: Bitwarden Password Generator. Set length to at least 16 characters with uppercase, lowercase, numbers, and symbols.

  • Use a password manager to securely store all passwords. A password manager is a secure vault that remembers all your passwords so you don't have to. You create one master password to access the vault, and it handles everything else.
    Recommended service: Bitwarden (free for personal use, Premium is $10/year). Bitwarden syncs across all devices and automatically fills passwords on websites.

Setup steps:

  1. Create a Bitwarden account at Bitwarden.com

  2. Choose a strong master password (write it down and store it securely)

  3. Install the browser extension for Chrome, Safari, or Edge

  4. Install the mobile app on your phone

  • Update critical passwords first with unique passwords for each account.

Generate and save new unique passwords for:

  1. Primary email accounts

  2. Banking and financial accounts

  3. Payment processing accounts

  4. Client management systems

Important: Each account must have a completely unique password. Never reuse passwords across sites.

2. Multi-Factor Authentication (MFA)

Multi-factor authentication requires two forms of verification to access an account: something you know (password) and something you have (phone, security key, or authentication app). Even if criminals steal your password, they cannot access your account without the second factor.

According to Microsoft's security research, MFA blocks 99.9% of automated attacks. This single measure provides more protection than any other security control.

ACTION ITEM: You'll enable MFA directly on each account. Most services provide setup instructions under security settings. Contact us if you need assistance.

  • Enable MFA on all accounts that support it, prioritizing:

  1. Email accounts (Microsoft 365, Gmail, etc.)

  2. Banking and investment accounts

  3. Payment processors (PayPal, Stripe, etc.)

  4. Cloud storage (Dropbox, Google Drive, OneDrive)

  5. Password manager (Bitwarden)

  • Use an authenticator app rather than SMS when possible.
    Recommended apps: Microsoft Authenticator, Google Authenticator, or Authy. SMS codes are acceptable but less secure than authenticator apps.

3. Identity Protection and Monitoring

Once your personal information appears on the dark web, criminals can open accounts, file fraudulent tax returns, or impersonate you to clients, sometimes for years before discovery. Business principals and anyone with access to sensitive client information or financial accounts require comprehensive identity monitoring.

ACTION ITEM: Visit the link below, select the appropriate plan, and complete enrollment. Enrollment and management are handled directly by you through the service provider.

  • Enroll in comprehensive identity monitoring for all business principals.
    Recommended service: Aura Identity Protection offers comprehensive monitoring, including credit reports from all three bureaus, dark web surveillance, and up to $1 million identity theft insurance. Plans start around $12-15 per month per person.

4. Device Protection

Comprehensive antivirus and antimalware software provides real-time protection against viruses, ransomware, spyware, and other threats. Modern solutions go beyond traditional antivirus to include behavior monitoring, exploit protection, and web filtering.

ACTION ITEM: Purchase and install security software on all devices. Ensure automatic updates are enabled.

  • Install comprehensive security software on all business devices.
    Recommended solution: Bitdefender Total Security consistently ranks highest for threat detection while maintaining low system impact. It covers Windows, Mac, iOS, and Android devices. Plans start around $40-50 per year for multiple devices.

  • Enable automatic updates for operating systems and all software.

Most breaches exploit known vulnerabilities that have available patches. Configure Windows Update, macOS Software Update, and mobile device updates to install automatically.

5. Secure Communications

Standard email and text messages are not encrypted and can be intercepted or spoofed. Wire transfer instructions, sensitive client information, and confidential business communications require encrypted channels and verification protocols.

ACTION ITEMS: Install Signal on all devices and establish verification protocols with your team.

  • Use encrypted messaging for sensitive communications.
    Recommended app: Signal provides end-to-end encryption for messages, voice calls, and video calls. It's free and works on all devices. Use Signal for any discussion involving financial transactions, client confidential information, or sensitive business matters.

  • Implement mandatory verification protocols for wire transfers and payment changes.

Required protocol for all wire transfers and account changes:

  1. NEVER act on emailed wire instructions without verification

  2. Call the sender using a known phone number (not one provided in the email)

  3. Confirm instructions verbally before processing

  4. Question any last-minute changes to payment instructions

This protocol is mandatory for all staff. No exceptions. Wire transfer fraud typically succeeds because recipients trust email communications without verification.

6. Network Security

Public Wi-Fi networks at coffee shops, hotels, and airports are inherently insecure. Criminals can intercept unencrypted traffic, capture passwords, or redirect you to fake websites. Home and office routers also require proper configuration to prevent unauthorized access.

ACTION ITEM: Install VPN software and configure your routers. Contact your internet provider if you need assistance with router configuration.

  • Use a VPN when connecting to any public Wi-Fi network.
    A VPN encrypts all internet traffic between your device and the destination. Recommended service: NordVPN provides reliable protection with servers worldwide. Plans start around $3-5 per month.

  • Secure your home and office routers.

Basic router security measures:

  1. Change the default administrator password

  2. Use WPA3 or WPA2 encryption for Wi-Fi

  3. Create a strong Wi-Fi password

  4. Disable remote management unless specifically needed

  5. Keep router firmware updated

7. Ongoing Vigilance

Technical controls provide essential protection, but human vigilance remains the final defense. Most successful attacks exploit trust rather than technical vulnerabilities.

ACTION ITEM: Maintain awareness of evolving threats and ensure all team members understand verification protocols.

  • Recognize phishing attempts and suspicious emails.

Warning signs of phishing emails:

  1. Urgent requests for action or payment

  2. Sender address that doesn't match the claimed organization

  3. Generic greetings instead of your name

  4. Requests to click links or download attachments

  5. Poor grammar or unusual phrasing

  6. Unexpected changes to established procedures

When in doubt, please forward the communication to us for review. Call using known contact information rather than responding to the suspicious email.

  • Conduct quarterly security reviews with all staff. Review current threats, reinforce protocols, and verify that security measures remain in place. Security is not a one-time project but an ongoing practice.

TECHNICAL SECURITY SERVICES WE PROVIDE

While you implement the action items above, we can help secure your technical infrastructure. These services work at the DNS, email, and hosting level to prevent spoofing, hijacking, and other technical attacks. If you're a current client, contact us to review which of these protections are currently in place. If you're not yet a client, we can implement these measures for you.

Email Authentication Configuration

We can configure and monitor email authentication protocols that prevent criminals from sending emails that appear to come from your domain:

  • DMARC (Domain-based Message Authentication, Reporting, and Conformance): The primary defense against email spoofing attacks. We configure strict DMARC policies and set up reporting so you're notified of spoofing attempts.

  • SPF (Sender Policy Framework): Specifies which mail servers are authorized to send email on behalf of your domain.

  • DKIM (DomainKeys Identified Mail): Adds digital signatures to outgoing emails to verify authenticity and prevent tampering.

Note: While we configure these DNS records, we don't provide email hosting services. We work with your existing email provider (Microsoft 365, Google Workspace, etc.) to properly configure authentication for your domain.

DNS Management and Security

We manage DNS services for most of our clients through enterprise providers such as Cloudflare. Proper DNS management includes:

  • Secure access controls with strong authentication

  • Monitoring for unauthorized changes to DNS records

  • Documentation of all authorized changes

  • Regular audits to verify record accuracy

DNS hijacking can redirect your email or website to malicious servers without your knowledge. Proper DNS security prevents these attacks.

Website and Hosting Security

For clients whose websites we host and manage, we implement multiple layers of security:

  • SSL/TLS certificates for encrypted connections (HTTPS)

  • Web application firewall (WAF) to block malicious traffic

  • Regular security updates and patches

  • Secure file permissions and access controls

  • Regular backups with offsite storage

  • Malware scanning and removal

  • DDoS protection

  • Security headers and best practice configurations

These measures protect your website from common attacks, including SQL injection, cross-site scripting, brute force attacks, and malware infections.

Email Setup and Support

While we don't provide email hosting services, we assist clients with setup and configuration of Microsoft 365, Google Workspace, and other email platforms. This includes proper authentication configuration, security settings, and integration with your domain.

QUESTIONS AND SUPPORT

We understand that implementing these security measures may raise questions or require assistance. We're available to:

  • Answer questions about any of these recommendations

  • Provide guidance on setting up password managers and MFA

  • Help establish security protocols for your team

  • Coordinate with your IT vendors if needed

Contact us anytime if you need assistance. Implementing these protections is not optional; they represent the minimum standard of care for protecting your business and your clients.

Notice: provided for informational purposes only; not legal, financial, or professional advice.

Notice: The information provided in this document is for informational purposes only and does not constitute legal, financial, or professional advice. All materials and guidance offered by Generose Corporation dba Risingline are subject to its Client Services Agreement and are provided without warranty as to accuracy, completeness, or applicability to any specific situation. While Risingline takes reasonable precautions to ensure the reliability of the information presented, compliance with regulatory requirements varies based on specific circumstances, jurisdiction, and evolving standards. Recipients are encouraged to conduct independent due diligence and consult with qualified professionals before implementing any recommendations. Generose Corporation dba Risingline expressly disclaims any liability for actions taken or not taken based on this document. Receipt of this information does not establish a client, advisory, or fiduciary relationship between Risingline and the recipient.

All articles