• Cyber Health Check

    In 5 minutes, see which client information, payment-change, access, and recovery risks your firm should look at first.
  • 10 practical questions

  • Can your business or practice quickly confirm who can access sensitive client files, matter records, tax documents, or patient records?*
  • Is there a documented phone or in-person verification step before changed payment instructions are accepted?*
  • If a mailbox looks compromised, can someone check forwarding rules, sign-ins, sent items, and suspicious apps quickly?*
  • Are MFA and administrator accounts enforced, limited, and reviewed across Microsoft 365?*
  • Does offboarding reliably remove access from Microsoft 365, devices, cloud apps, and practice systems?*
  • Has your business or practice tested restore for email, files, or key systems recently enough to trust it under deadline pressure?*
  • Could your team keep working if file access, the client portal, internet, or a core app failed during a deadline?*
  • Are laptops and workstations covered by managed protection, updates, encryption, and lost-device controls?*
  • Do staff know which AI tools are approved and what client, patient, or business information must not be entered into public tools?*
  • When something looks wrong, is it clear who acts first, who escalates, and who contacts the IT provider?*
  • MFA and sign-in protections for all Microsoft 365 users, especially admins*
  • Administrator accounts named, limited, reviewed regularly*
  • Ability to quickly check forwarding rules, sign-ins, and message risk after suspicious email or changed payment instruction*
  • Email security controls such as filtering, impersonation protection, and domain authentication actively reviewed*
  • Workstations covered by managed endpoint protection, patching, and update checks*
  • Lost, retired, or unmanaged devices can be identified and blocked from business or practice data*
  • Email, files, and critical cloud data backed up outside normal recycle-bin retention*
  • Successful restore test for email, files, or key systems in the last 90 days*
  • Repeatable process for granting and removing user access across Microsoft 365, devices, and core systems*
  • Known ownership for core systems, vendors, passwords, renewals, and escalation paths*
  • Clear response owner for lockouts, mailbox compromise, or device alert*
  • Staff guidance on approved AI tools and prohibited client, patient, business, or practice data use in public tools*
  • Lead Capture

    Your details are used to send the checklist and respond to the next step you choose.
  • Format: (000) 000-0000.
  • How would you like to use the checklist?*
  • Hidden Metadata

  • Should be Empty: