Protection Checklist for Businesses & Individuals
Business email compromises cost American companies over $2.7 billion annually, with small businesses and professional services firms particularly vulnerable. According to the FBI's Internet Crime Complaint Center, wire transfer fraud attempts have increased 65% in the past two years, with attackers frequently impersonating trusted business contacts.
Cybercriminals target small firms because they often lack dedicated IT security staff while handling significant financial transactions and sensitive client data. A single successful breach can result in substantial financial loss, regulatory penalties, reputational damage, and potential malpractice claims.
This checklist provides essential security measures every small business should implement immediately to protect its business, clients, and reputation.
IMMEDIATE ACTION ITEMS
The following items require your direct action. Complete these in order of priority.
1. Password Security. THIS IS YOUR HIGHEST PRIORITY
According to Verizon's 2024 Data Breach Investigations Report, 81% of hacking-related breaches involve stolen or weak passwords. Complex passwords are essential, but most people struggle with creating and managing them across dozens of accounts.
ACTION ITEMS: Update passwords for all of your
business, financial, and personal accounts. For accounts we manage on
your behalf, we'll update passwords and provide them to you
securely.
Important: Never send or allow to be sent to you
passwords by email or text. Use an end-to-end encryption service like
signal.org. Otherwise, your passwords may be exposed to
cybercriminals.
Generate strong passwords automatically using a password generator.
Free tool: Bitwarden Password Generator. Set length to at least 16 characters with uppercase, lowercase, numbers, and symbols.Use a password manager to securely store all passwords. A password manager is a secure vault that remembers all your passwords so you don't have to. You create one master password to access the vault, and it handles everything else.
Recommended service: Bitwarden (free for personal use, Premium is $10/year). Bitwarden syncs across all devices and automatically fills passwords on websites.
Setup steps:
Create a Bitwarden account at Bitwarden.com
Choose a strong master password (write it down and store it securely)
Install the browser extension for Chrome, Safari, or Edge
Install the mobile app on your phone
Update critical passwords first with unique passwords for each account.
Generate and save new unique passwords for:
Primary email accounts
Banking and financial accounts
Payment processing accounts
Client management systems
Important: Each account must have a completely unique password. Never reuse passwords across sites.
2. Multi-Factor Authentication (MFA)
Multi-factor authentication requires two forms of verification to access an account: something you know (password) and something you have (phone, security key, or authentication app). Even if criminals steal your password, they cannot access your account without the second factor.
According to Microsoft's security research, MFA blocks 99.9% of automated attacks. This single measure provides more protection than any other security control.
ACTION ITEM: You'll enable MFA directly on each account. Most services provide setup instructions under security settings. Contact us if you need assistance.
Enable MFA on all accounts that support it, prioritizing:
Email accounts (Microsoft 365, Gmail, etc.)
Banking and investment accounts
Payment processors (PayPal, Stripe, etc.)
Cloud storage (Dropbox, Google Drive, OneDrive)
Password manager (Bitwarden)
Use an authenticator app rather than SMS when possible.
Recommended apps: Microsoft Authenticator, Google Authenticator, or Authy. SMS codes are acceptable but less secure than authenticator apps.
3. Identity Protection and Monitoring
Once your personal information appears on the dark web, criminals can open accounts, file fraudulent tax returns, or impersonate you to clients, sometimes for years before discovery. Business principals and anyone with access to sensitive client information or financial accounts require comprehensive identity monitoring.
ACTION ITEM: Visit the link below, select the appropriate plan, and complete enrollment. Enrollment and management are handled directly by you through the service provider.
Enroll in comprehensive identity monitoring for all business principals.
Recommended service: Aura Identity Protection offers comprehensive monitoring, including credit reports from all three bureaus, dark web surveillance, and up to $1 million identity theft insurance. Plans start around $12-15 per month per person.
4. Device Protection
Comprehensive antivirus and antimalware software provides real-time protection against viruses, ransomware, spyware, and other threats. Modern solutions go beyond traditional antivirus to include behavior monitoring, exploit protection, and web filtering.
ACTION ITEM: Purchase and install security software on all devices. Ensure automatic updates are enabled.
Install comprehensive security software on all business devices.
Recommended solution: Bitdefender Total Security consistently ranks highest for threat detection while maintaining low system impact. It covers Windows, Mac, iOS, and Android devices. Plans start around $40-50 per year for multiple devices.Enable automatic updates for operating systems and all software.
Most breaches exploit known vulnerabilities that have available patches. Configure Windows Update, macOS Software Update, and mobile device updates to install automatically.
5. Secure Communications
Standard email and text messages are not encrypted and can be intercepted or spoofed. Wire transfer instructions, sensitive client information, and confidential business communications require encrypted channels and verification protocols.
ACTION ITEMS: Install Signal on all devices and establish verification protocols with your team.
Use encrypted messaging for sensitive communications.
Recommended app: Signal provides end-to-end encryption for messages, voice calls, and video calls. It's free and works on all devices. Use Signal for any discussion involving financial transactions, client confidential information, or sensitive business matters.Implement mandatory verification protocols for wire transfers and payment changes.
Required protocol for all wire transfers and account changes:
NEVER act on emailed wire instructions without verification
Call the sender using a known phone number (not one provided in the email)
Confirm instructions verbally before processing
Question any last-minute changes to payment instructions
This protocol is mandatory for all staff. No exceptions. Wire transfer fraud typically succeeds because recipients trust email communications without verification.
6. Network Security
Public Wi-Fi networks at coffee shops, hotels, and airports are inherently insecure. Criminals can intercept unencrypted traffic, capture passwords, or redirect you to fake websites. Home and office routers also require proper configuration to prevent unauthorized access.
ACTION ITEM: Install VPN software and configure your routers. Contact your internet provider if you need assistance with router configuration.
Use a VPN when connecting to any public Wi-Fi network.
A VPN encrypts all internet traffic between your device and the destination. Recommended service: NordVPN provides reliable protection with servers worldwide. Plans start around $3-5 per month.Secure your home and office routers.
Basic router security measures:
Change the default administrator password
Use WPA3 or WPA2 encryption for Wi-Fi
Create a strong Wi-Fi password
Disable remote management unless specifically needed
Keep router firmware updated
7. Ongoing Vigilance
Technical controls provide essential protection, but human vigilance remains the final defense. Most successful attacks exploit trust rather than technical vulnerabilities.
ACTION ITEM: Maintain awareness of evolving threats and ensure all team members understand verification protocols.
Recognize phishing attempts and suspicious emails.
Warning signs of phishing emails:
Urgent requests for action or payment
Sender address that doesn't match the claimed organization
Generic greetings instead of your name
Requests to click links or download attachments
Poor grammar or unusual phrasing
Unexpected changes to established procedures
When in doubt, please forward the communication to us for review. Call using known contact information rather than responding to the suspicious email.
Conduct quarterly security reviews with all staff. Review current threats, reinforce protocols, and verify that security measures remain in place. Security is not a one-time project but an ongoing practice.
TECHNICAL SECURITY SERVICES WE PROVIDE
While you implement the action items above, we can help secure your technical infrastructure. These services work at the DNS, email, and hosting level to prevent spoofing, hijacking, and other technical attacks. If you're a current client, contact us to review which of these protections are currently in place. If you're not yet a client, we can implement these measures for you.
Email Authentication Configuration
We can configure and monitor email authentication protocols that prevent criminals from sending emails that appear to come from your domain:
DMARC (Domain-based Message Authentication, Reporting, and Conformance): The primary defense against email spoofing attacks. We configure strict DMARC policies and set up reporting so you're notified of spoofing attempts.
SPF (Sender Policy Framework): Specifies which mail servers are authorized to send email on behalf of your domain.
DKIM (DomainKeys Identified Mail): Adds digital signatures to outgoing emails to verify authenticity and prevent tampering.
Note: While we configure these DNS records, we don't provide email hosting services. We work with your existing email provider (Microsoft 365, Google Workspace, etc.) to properly configure authentication for your domain.
DNS Management and Security
We manage DNS services for most of our clients through enterprise providers such as Cloudflare. Proper DNS management includes:
Secure access controls with strong authentication
Monitoring for unauthorized changes to DNS records
Documentation of all authorized changes
Regular audits to verify record accuracy
DNS hijacking can redirect your email or website to malicious servers without your knowledge. Proper DNS security prevents these attacks.
Website and Hosting Security
For clients whose websites we host and manage, we implement multiple layers of security:
SSL/TLS certificates for encrypted connections (HTTPS)
Web application firewall (WAF) to block malicious traffic
Regular security updates and patches
Secure file permissions and access controls
Regular backups with offsite storage
Malware scanning and removal
DDoS protection
Security headers and best practice configurations
These measures protect your website from common attacks, including SQL injection, cross-site scripting, brute force attacks, and malware infections.
Email Setup and Support
While we don't provide email hosting services, we assist clients with setup and configuration of Microsoft 365, Google Workspace, and other email platforms. This includes proper authentication configuration, security settings, and integration with your domain.
QUESTIONS AND SUPPORT
We understand that implementing these security measures may raise questions or require assistance. We're available to:
Answer questions about any of these recommendations
Provide guidance on setting up password managers and MFA
Help establish security protocols for your team
Coordinate with your IT vendors if needed
Contact us anytime if you need assistance. Implementing these protections is not optional; they represent the minimum standard of care for protecting your business and your clients.
Notice: provided for informational purposes only; not legal, financial, or professional advice.
Notice: The information provided in this document is for informational purposes only and does not constitute legal, financial, or professional advice. All materials and guidance offered by Generose Corporation dba Risingline are subject to its Client Services Agreement and are provided without warranty as to accuracy, completeness, or applicability to any specific situation. While Risingline takes reasonable precautions to ensure the reliability of the information presented, compliance with regulatory requirements varies based on specific circumstances, jurisdiction, and evolving standards. Recipients are encouraged to conduct independent due diligence and consult with qualified professionals before implementing any recommendations. Generose Corporation dba Risingline expressly disclaims any liability for actions taken or not taken based on this document. Receipt of this information does not establish a client, advisory, or fiduciary relationship between Risingline and the recipient.