[{"data":1,"prerenderedAt":4233},["ShallowReactive",2],{"resource-guide-list":3},[4,1303,1931,2895,3595],{"id":5,"title":6,"audience":7,"author":8,"body":9,"category":1245,"ctaDescription":1246,"ctaLabel":1247,"ctaUrl":633,"date":1248,"description":1249,"draft":1250,"estimatedTime":1251,"extension":1252,"featured":1250,"guideInputs":1253,"guideOutputs":1257,"lastReviewed":1261,"meta":1262,"navigation":279,"path":1263,"relatedResources":1264,"reviewStatus":1277,"scopeNote":1278,"seo":1279,"seoTitle":1280,"sources":1281,"stem":1301,"__hash__":1302},"guides\u002Fguides\u002Fpersonal-cyber-foundations.md","Personal Cyber Foundations Guide","Executives, business owners, high-risk individuals, households, and the trusted people who help manage their affairs","Trawvid Sec",{"type":10,"value":11,"toc":1213},"minimark",[12,17,21,24,33,41,46,65,68,83,87,90,93,97,121,130,134,262,268,306,310,313,322,325,328,356,360,446,450,483,487,490,493,496,519,523,591,595,628,636,640,643,652,655,681,685,772,776,809,813,816,824,827,850,854,919,923,956,959,962,965,969,1065,1069,1102,1105,1109,1112,1192,1198],[13,14,16],"h2",{"id":15},"start-with-the-checklist","Start with the checklist",[18,19,20],"p",{},"Personal cybersecurity is not a shopping list. It is the way email, phones, financial portals, cloud files, devices, family members, assistants, and professional advisors connect to one another.",[18,22,23],{},"That system usually grows one convenience at a time. A spouse knows one password. An assistant receives statements. A bookkeeper can prepare a payment. An old email address still resets a brokerage account. A phone number is the recovery method for almost everything. Each choice may have been reasonable by itself. The trouble starts when nobody can see the full chain.",[18,25,26,27,32],{},"Begin with the ",[28,29,31],"a",{"href":30},"\u002Ftools\u002Fpersonal-cyber-risk-checklist","Personal Cyber Risk Checklist",". It scores ten areas privately in your browser. Do not complete every section of this guide just because it exists. Use the result to choose the modules that match a weak score, an open critical flag, or a consequence you cannot accept.",[18,34,35,36,40],{},"If something suspicious is happening now, skip to ",[28,37,39],{"href":38},"#module-6-write-the-first-hour-plan","Module 6: Write the first-hour plan"," and contact the relevant bank, carrier, provider, or emergency service through a known channel.",[42,43,45],"h3",{"id":44},"the-five-moves-that-matter-most","The five moves that matter most",[47,48,49,53,56,59,62],"ol",{},[50,51,52],"li",{},"Protect the primary email, recovery email, password manager, and phone carrier account.",[50,54,55],{},"Put a separate verification step around wires, payees, payment changes, and urgent financial requests.",[50,57,58],{},"Replace informal password sharing with named, removable access for family members, assistants, and advisors.",[50,60,61],{},"Secure and back up the devices that can approve payments, reset accounts, or open sensitive records.",[50,63,64],{},"Write down what happens first if a phone is lost, email is hacked, money moves fraudulently, or an identity is misused.",[18,66,67],{},"Use a controlled copy of this guide. Record account names and decisions, not passwords, recovery codes, seed phrases, private keys, full account numbers, Social Security numbers, or other secrets.",[18,69,70,71,75,76,82],{},"If the map gets complicated, use the help links on this page as an escape hatch. ",[28,72,74],{"href":73},"mailto:n@trawvidsec.net","Email Trawvid Sec"," or ",[28,77,81],{"href":78,"rel":79},"https:\u002F\u002Fcalendar.app.google\u002FqT8vtwaEDG2Pt51o8",[80],"nofollow","book a 30-minute introductory call"," before making a change that could lock someone out or disrupt a financial workflow.",[13,84,86],{"id":85},"module-1-protect-root-accounts-and-recovery","Module 1: Protect root accounts and recovery",[18,88,89],{},"Start with accounts that can reset or unlock other accounts. Primary email is often the real master key. Recovery email, the password manager, the phone carrier, and a trusted device may each provide another route around the protection on that mailbox.",[18,91,92],{},"Map the chain before changing it. Otherwise, it is easy to improve one login while leaving an old recovery address or phone number in control.",[42,94,96],{"id":95},"what-to-do","What to do",[98,99,100,103,106,109,112,115,118],"ul",{},[50,101,102],{},"List the primary email, recovery email, password manager, phone carrier, important financial portals, cloud storage, and business-adjacent accounts.",[50,104,105],{},"Mark any account that can reset another account, approve identity changes, move money, or expose sensitive records.",[50,107,108],{},"Remove stale recovery addresses, former phone numbers, unknown trusted devices, and old authorized users.",[50,110,111],{},"Use unique credentials or passkeys for critical accounts.",[50,113,114],{},"Turn on the strongest practical multifactor authentication offered by the provider. For root accounts, prefer passkeys, security keys, or authenticator applications over text messages when the recovery process is understood.",[50,116,117],{},"Store backup codes outside the account they recover. Do not leave the only copy in ordinary email, photos, or the same password vault.",[50,119,120],{},"Test one recovery path on paper. Know what remains available if the main phone is lost.",[18,122,123,124,129],{},"The ",[28,125,128],{"href":126,"rel":127},"https:\u002F\u002Fwww.cisa.gov\u002Fresources-tools\u002Ftraining\u002Fcyb3rsmrt-use-password-manager-create-and-remember-strong-passwords",[80],"CISA password manager guidance"," is a useful product-selection and recovery reference. The operating rule is simpler: one reputable vault, unique credentials, strong protection on the vault itself, and no circular recovery chain that depends on the unavailable account.",[42,131,133],{"id":132},"root-account-map","Root account map",[135,136,137,162],"table",{},[138,139,140],"thead",{},[141,142,143,147,150,153,156,159],"tr",{},[144,145,146],"th",{},"Account",[144,148,149],{},"Why it matters",[144,151,152],{},"Current recovery path",[144,154,155],{},"Protection in place",[144,157,158],{},"Change needed",[144,160,161],{},"Owner",[163,164,165,182,198,214,230,246],"tbody",{},[141,166,167,171,174,176,178,180],{},[168,169,170],"td",{},"Primary email",[168,172,173],{},"Resets other accounts",[168,175],{},[168,177],{},[168,179],{},[168,181],{},[141,183,184,187,190,192,194,196],{},[168,185,186],{},"Recovery email",[168,188,189],{},"Can bypass primary email protection",[168,191],{},[168,193],{},[168,195],{},[168,197],{},[141,199,200,203,206,208,210,212],{},[168,201,202],{},"Password manager",[168,204,205],{},"Stores critical credentials",[168,207],{},[168,209],{},[168,211],{},[168,213],{},[141,215,216,219,222,224,226,228],{},[168,217,218],{},"Phone carrier",[168,220,221],{},"Controls number and text-message recovery",[168,223],{},[168,225],{},[168,227],{},[168,229],{},[141,231,232,235,238,240,242,244],{},[168,233,234],{},"Financial portal",[168,236,237],{},"Moves money or exposes records",[168,239],{},[168,241],{},[168,243],{},[168,245],{},[141,247,248,251,254,256,258,260],{},[168,249,250],{},"Cloud or business-adjacent account",[168,252,253],{},"Stores records or controls business access",[168,255],{},[168,257],{},[168,259],{},[168,261],{},[18,263,264],{},[265,266,267],"strong",{},"Move on when:",[98,269,272,282,288,294,300],{"className":270},[271],"contains-task-list",[50,273,276,281],{"className":274},[275],"task-list-item",[277,278],"input",{"disabled":279,"type":280},true,"checkbox"," Primary and recovery email accounts use unique credentials and strong sign-in protection.",[50,283,285,287],{"className":284},[275],[277,286],{"disabled":279,"type":280}," Old recovery methods and unknown trusted devices have been reviewed.",[50,289,291,293],{"className":290},[275],[277,292],{"disabled":279,"type":280}," The password manager has a recovery plan that does not depend only on itself.",[50,295,297,299],{"className":296},[275],[277,298],{"disabled":279,"type":280}," Backup codes are protected outside this guide.",[50,301,303,305],{"className":302},[275],[277,304],{"disabled":279,"type":280}," At least one root-account recovery path has been walked through without guessing.",[13,307,309],{"id":308},"module-2-protect-money-and-the-phone-number","Module 2: Protect money and the phone number",[18,311,312],{},"A phone number is not just a communication tool. It may receive account-recovery codes, confirm identity, approve transactions, or serve as the trusted contact for financial institutions. Protect the carrier account as part of the financial system.",[18,314,315,316,321],{},"Ask the carrier which protections are available. Names vary, but useful controls may include an account PIN, number lock, port-out lock, transfer lock, and notifications for subscriber identity module or number-transfer changes. The ",[28,317,320],{"href":318,"rel":319},"https:\u002F\u002Fconsumer.ftc.gov\u002Fconsumer-alerts\u002F2019\u002F10\u002Fsim-swap-scams-how-protect-yourself",[80],"FTC SIM swap guidance"," explains why text messages should not be the only protection on sensitive accounts.",[18,323,324],{},"Money movement also needs a rule that exists outside email. A believable message from an executive, family member, attorney, advisor, or vendor is still just a message until it is verified through a known second channel.",[42,326,96],{"id":327},"what-to-do-1",[98,329,330,333,336,339,342,345,348],{},[50,331,332],{},"Set a unique carrier account PIN and enable available transfer protections.",[50,334,335],{},"Review carrier account owners, authorized users, recovery email, and notifications.",[50,337,338],{},"Move high-consequence accounts away from text-message-only sign-in or recovery when stronger options are available.",[50,340,341],{},"List portals that can move money, create payees, change contact details, access credit, or expose tax and financial records.",[50,343,344],{},"Turn on useful alerts for sign-ins, profile changes, password resets, new payees, transfers, withdrawals, and large purchases.",[50,346,347],{},"Require out-of-band verification for new wires, changed payment instructions, new payees, urgent requests, and account changes. Use a known number or contact path, not the contact information in the request.",[50,349,350,351,355],{},"Place and maintain credit freezes when appropriate. The ",[28,352,354],{"href":353},"\u002Fblog\u002Fwhat-a-credit-freeze-does-and-how-to-set-one-up","credit-freeze guide"," links directly to Equifax, Experian, and TransUnion.",[42,357,359],{"id":358},"money-and-carrier-control-record","Money and carrier control record",[135,361,362,380],{},[138,363,364],{},[141,365,366,369,372,375,377],{},[144,367,368],{},"Area",[144,370,371],{},"Current safeguard",[144,373,374],{},"Required verification or alert",[144,376,161],{},[144,378,379],{},"Next action",[163,381,382,394,407,420,433],{},[141,383,384,386,388,390,392],{},[168,385,218],{},[168,387],{},[168,389],{},[168,391],{},[168,393],{},[141,395,396,399,401,403,405],{},[168,397,398],{},"Bank and credit accounts",[168,400],{},[168,402],{},[168,404],{},[168,406],{},[141,408,409,412,414,416,418],{},[168,410,411],{},"Brokerage or investment portal",[168,413],{},[168,415],{},[168,417],{},[168,419],{},[141,421,422,425,427,429,431],{},[168,423,424],{},"Payroll, payment, or business-adjacent portal",[168,426],{},[168,428],{},[168,430],{},[168,432],{},[141,434,435,438,440,442,444],{},[168,436,437],{},"Credit freezes and identity monitoring",[168,439],{},[168,441],{},[168,443],{},[168,445],{},[18,447,448],{},[265,449,267],{},[98,451,453,459,465,471,477],{"className":452},[271],[50,454,456,458],{"className":455},[275],[277,457],{"disabled":279,"type":280}," Carrier ownership, authorized users, PIN, and transfer protections are known.",[50,460,462,464],{"className":461},[275],[277,463],{"disabled":279,"type":280}," High-risk accounts do not rely only on the phone number for access or recovery.",[50,466,468,470],{"className":467},[275],[277,469],{"disabled":279,"type":280}," Financial alerts reach a person who will act on them.",[50,472,474,476],{"className":473},[275],[277,475],{"disabled":279,"type":280}," New or changed payment instructions require verification through a known second channel.",[50,478,480,482],{"className":479},[275],[277,481],{"disabled":279,"type":280}," Someone knows what to do if the phone suddenly loses service.",[13,484,486],{"id":485},"module-3-control-files-family-access-and-professional-helpers","Module 3: Control files, family access, and professional helpers",[18,488,489],{},"Family members, assistants, bookkeepers, attorneys, accountants, wealth managers, household staff, and technology providers may need legitimate access. The problem is not that they help. The problem is access that is shared informally, never reviewed, and difficult to remove.",[18,491,492],{},"Separate the verbs. Viewing a statement is not the same as changing contact information. Preparing a payment is not the same as releasing it. Emergency access is not the same as permanent access.",[42,494,96],{"id":495},"what-to-do-2",[98,497,498,501,504,507,510,513,516],{},[50,499,500],{},"Choose an approved storage location for sensitive tax, estate, identity, insurance, health, property, legal, and business records.",[50,502,503],{},"Review public links, old collaborators, automatic email forwarding, shared folders, and exported copies.",[50,505,506],{},"Give each helper a named account or controlled share where practical. Avoid sending live passwords by email or text.",[50,508,509],{},"Record whether a person may view, prepare, change, approve, or release.",[50,511,512],{},"Define who removes access when a role, firm, employment relationship, household relationship, or advisor changes.",[50,514,515],{},"Review family sharing for location, photos, calendars, subscriptions, cloud storage, purchases, and devices.",[50,517,518],{},"Keep emergency access narrow. A person who may need an estate document someday does not necessarily need continuous access to every financial portal.",[42,520,522],{"id":521},"delegated-access-register","Delegated-access register",[135,524,525,546],{},[138,526,527],{},[141,528,529,532,535,538,541,544],{},[144,530,531],{},"Person or firm",[144,533,534],{},"What they can access",[144,536,537],{},"Allowed actions",[144,539,540],{},"Access method",[144,542,543],{},"Removal trigger",[144,545,161],{},[163,547,548,563,577],{},[141,549,550,552,554,557,559,561],{},[168,551],{},[168,553],{},[168,555,556],{},"View \u002F prepare \u002F change \u002F approve \u002F release",[168,558],{},[168,560],{},[168,562],{},[141,564,565,567,569,571,573,575],{},[168,566],{},[168,568],{},[168,570,556],{},[168,572],{},[168,574],{},[168,576],{},[141,578,579,581,583,585,587,589],{},[168,580],{},[168,582],{},[168,584,556],{},[168,586],{},[168,588],{},[168,590],{},[18,592,593],{},[265,594,267],{},[98,596,598,604,610,616,622],{"className":597},[271],[50,599,601,603],{"className":600},[275],[277,602],{"disabled":279,"type":280}," Sensitive files have an approved home and a named owner.",[50,605,607,609],{"className":606},[275],[277,608],{"disabled":279,"type":280}," Shared links, old collaborators, and forwarding rules have been reviewed.",[50,611,613,615],{"className":612},[275],[277,614],{"disabled":279,"type":280}," Helpers have named, removable access where practical.",[50,617,619,621],{"className":618},[275],[277,620],{"disabled":279,"type":280}," Payment preparation and approval are not treated as the same authority.",[50,623,625,627],{"className":624},[275],[277,626],{"disabled":279,"type":280}," Family and emergency sharing is intentional rather than assumed.",[18,629,630,631,635],{},"If several people touch the same accounts and nobody can explain who can approve what, pause before changing access one account at a time. ",[28,632,634],{"href":633},"\u002Fservices\u002Fpersonal-cyber-risk-review","Trawvid Sec can help map the workflow"," without taking possession of passwords.",[13,637,639],{"id":638},"module-4-harden-high-risk-devices-backups-and-the-home-network","Module 4: Harden high-risk devices, backups, and the home network",[18,641,642],{},"Do not boil the ocean. Start with the phone and computers that can approve payments, reset root accounts, open sensitive files, or act as trusted sign-in devices. A streaming stick and the laptop used for email, banking, and the password manager do not deserve equal attention.",[18,644,645,646,651],{},"Encryption protects data on a lost device. Backups protect against loss, failure, malware, and mistakes. Neither control helps if recovery keys are unavailable or nobody has tested a restore. The ",[28,647,650],{"href":648,"rel":649},"https:\u002F\u002Fwww.cisa.gov\u002Fresources-tools\u002Ftraining\u002Fhow-protect-data-stored-your-devices",[80],"CISA device-data guidance"," provides a useful baseline.",[42,653,96],{"id":654},"what-to-do-3",[98,656,657,660,663,666,669,672,675,678],{},[50,658,659],{},"Enable supported operating system and application updates on high-risk devices.",[50,661,662],{},"Use device encryption, a strong screen lock, automatic locking, and supported biometric protection.",[50,664,665],{},"Turn on trusted locate, lock, and erase features. Confirm those controls are reachable from another trusted path.",[50,667,668],{},"Replace unsupported devices or routers when their role makes the exposure meaningful.",[50,670,671],{},"Back up important photos, contacts, records, and working files.",[50,673,674],{},"Restore one small file. A green backup icon is not proof that recovery works.",[50,676,677],{},"Change default router administrator credentials, apply updates, use WPA2 or WPA3, disable unneeded remote administration, and remove unknown devices.",[50,679,680],{},"Put guest and connected-home devices on a separate guest or Internet-of-Things network when the router supports it.",[42,682,684],{"id":683},"device-and-backup-record","Device and backup record",[135,686,687,705],{},[138,688,689],{},[141,690,691,694,697,700,703],{},[144,692,693],{},"Device or data",[144,695,696],{},"Security and backup method",[144,698,699],{},"Last checked",[144,701,702],{},"Restore or recovery result",[144,704,161],{},[163,706,707,720,733,746,759],{},[141,708,709,712,714,716,718],{},[168,710,711],{},"Primary phone",[168,713],{},[168,715],{},[168,717],{},[168,719],{},[141,721,722,725,727,729,731],{},[168,723,724],{},"Primary computer",[168,726],{},[168,728],{},[168,730],{},[168,732],{},[141,734,735,738,740,742,744],{},[168,736,737],{},"Sensitive files and records",[168,739],{},[168,741],{},[168,743],{},[168,745],{},[141,747,748,751,753,755,757],{},[168,749,750],{},"Photos and family records",[168,752],{},[168,754],{},[168,756],{},[168,758],{},[141,760,761,764,766,768,770],{},[168,762,763],{},"Home router and wireless network",[168,765],{},[168,767],{},[168,769],{},[168,771],{},[18,773,774],{},[265,775,267],{},[98,777,779,785,791,797,803],{"className":778},[271],[50,780,782,784],{"className":781},[275],[277,783],{"disabled":279,"type":280}," High-risk devices are supported, updated, encrypted, and strongly locked.",[50,786,788,790],{"className":787},[275],[277,789],{"disabled":279,"type":280}," Locate, lock, or erase features can be reached without the missing device.",[50,792,794,796],{"className":793},[275],[277,795],{"disabled":279,"type":280}," Important data has a backup owner and a tested restore.",[50,798,800,802],{"className":799},[275],[277,801],{"disabled":279,"type":280}," Router administration uses a unique credential and current software.",[50,804,806,808],{"className":805},[275],[277,807],{"disabled":279,"type":280}," Guest or connected-device separation has been considered.",[13,810,812],{"id":811},"module-5-reduce-public-exposure","Module 5: Reduce public exposure",[18,814,815],{},"The objective is not to disappear from the internet. Public records, professional biographies, business roles, and old information may never vanish completely. Reduce the details that make impersonation, account-recovery abuse, doxxing, harassment, or a believable payment request easier.",[18,817,123,818,823],{},[28,819,822],{"href":820,"rel":821},"https:\u002F\u002Fconsumer.ftc.gov\u002Farticles\u002Fwhat-know-about-people-search-sites-sell-your-information",[80],"FTC people-search guidance"," explains how these services assemble public records, social data, and brokered information. Opt-outs can help, but information may return. Treat this as maintenance, not a one-time cleanup.",[42,825,96],{"id":826},"what-to-do-4",[98,828,829,832,835,838,841,844,847],{},[50,830,831],{},"Search the person's name, common name variations, email addresses, phone numbers, and home address while signed out.",[50,833,834],{},"Note what a stranger could learn in 30 minutes about roles, relationships, locations, travel, authority, and likely verification questions.",[50,836,837],{},"Remove unnecessary birth dates, family details, location patterns, personal contact details, and old profiles where practical.",[50,839,840],{},"Submit opt-outs to the highest-exposure people-search sites and set a recheck date.",[50,842,843],{},"Review executive biographies, company pages, speaking profiles, family posts, shared albums, calendars, and travel details.",[50,845,846],{},"Tell family members, staff, and advisors how to verify an unusual request through a known channel.",[50,848,849],{},"Treat stalking, domestic violence, credible threats, or immediate physical safety concerns as a safety matter requiring qualified support, not an ordinary privacy project.",[42,851,853],{"id":852},"exposure-register","Exposure register",[135,855,856,872],{},[138,857,858],{},[141,859,860,863,866,869],{},[144,861,862],{},"Source",[144,864,865],{},"Useful detail exposed",[144,867,868],{},"Decision",[144,870,871],{},"Owner and recheck date",[163,873,874,886,897,908],{},[141,875,876,879,881,884],{},[168,877,878],{},"Search results",[168,880],{},[168,882,883],{},"Remove \u002F reduce \u002F accept",[168,885],{},[141,887,888,891,893,895],{},[168,889,890],{},"Business or professional profile",[168,892],{},[168,894,883],{},[168,896],{},[141,898,899,902,904,906],{},[168,900,901],{},"Social or family account",[168,903],{},[168,905,883],{},[168,907],{},[141,909,910,913,915,917],{},[168,911,912],{},"People-search site",[168,914],{},[168,916,883],{},[168,918],{},[18,920,921],{},[265,922,267],{},[98,924,926,932,938,944,950],{"className":925},[271],[50,927,929,931],{"className":928},[275],[277,930],{"disabled":279,"type":280}," Public searches have been reviewed from an outsider's perspective.",[50,933,935,937],{"className":934},[275],[277,936],{"disabled":279,"type":280}," The most useful details for impersonation or recovery abuse have been reduced where practical.",[50,939,941,943],{"className":940},[275],[277,942],{"disabled":279,"type":280}," Public contact information is not automatically trusted for sensitive verification.",[50,945,947,949],{"className":946},[275],[277,948],{"disabled":279,"type":280}," Likely recipients know how to verify an unusual request.",[50,951,953,955],{"className":952},[275],[277,954],{"disabled":279,"type":280}," A recheck date exists.",[13,957,39],{"id":958},"module-6-write-the-first-hour-plan",[18,960,961],{},"The first hour is not the time to search for the carrier's fraud number or decide who can call the bank. Keep this plan short enough to use and store it somewhere available when the main email, phone, or cloud account is unavailable.",[18,963,964],{},"Name one response coordinator and a backup. Save trusted contact methods for the carrier, financial institutions, technology providers, and relevant advisors. Record facts, times, case numbers, and actions, but never passwords or recovery secrets.",[42,966,968],{"id":967},"first-hour-action-card","First-hour action card",[135,970,971,987],{},[138,972,973],{},[141,974,975,978,981,984],{},[144,976,977],{},"Event",[144,979,980],{},"First actions",[144,982,983],{},"Who must be contacted",[144,985,986],{},"Evidence to preserve",[163,988,989,1003,1017,1031,1051],{},[141,990,991,994,997,1000],{},[168,992,993],{},"Email compromise",[168,995,996],{},"Use a known-clean device; regain control; change the credential; review recovery methods, forwarding rules, active sessions, trusted devices, and recent messages; warn affected contacts through another channel.",[168,998,999],{},"Email provider, affected contacts, business support if company access overlaps",[168,1001,1002],{},"Alerts, notices, suspicious messages, forwarding rules, session details, case numbers",[141,1004,1005,1008,1011,1014],{},[168,1006,1007],{},"Fraudulent payment or wire request",[168,1009,1010],{},"Call the financial institution through a known number; ask about recall or reversal; pause related payments; preserve the request and transaction details.",[168,1012,1013],{},"Bank or brokerage fraud department, payment owner, relevant advisor",[168,1015,1016],{},"Original request, transaction confirmation, call notes, case numbers",[141,1018,1019,1022,1025,1028],{},[168,1020,1021],{},"Lost phone or computer",[168,1023,1024],{},"Use trusted locate or lock controls; contact the carrier if a phone is involved; protect root accounts; revoke sessions when warranted; warn contacts if impersonation is possible.",[168,1026,1027],{},"Carrier, device provider, business support when company data is present",[168,1029,1030],{},"Device details, last known location, alerts, support case",[141,1032,1033,1036,1045,1048],{},[168,1034,1035],{},"Identity misuse or new-account fraud",[168,1037,1038,1039,1044],{},"Freeze credit if needed; contact affected businesses; preserve notices; use ",[28,1040,1043],{"href":1041,"rel":1042},"https:\u002F\u002Fwww.identitytheft.gov\u002FSteps",[80],"IdentityTheft.gov"," for a recovery plan.",[168,1046,1047],{},"Affected institution, credit bureaus, insurer or qualified advisor as appropriate",[168,1049,1050],{},"Credit reports, notices, fraudulent account details, reports and correspondence",[141,1052,1053,1056,1059,1062],{},[168,1054,1055],{},"Impersonation, doxxing, or harassment",[168,1057,1058],{},"Preserve messages, profiles, links, dates, and screenshots; warn likely recipients; report through relevant platforms or authorities; address physical safety first.",[168,1060,1061],{},"Likely recipients, platform, qualified safety or legal support when needed",[168,1063,1064],{},"Messages, links, account names, screenshots, reports and case numbers",[18,1066,1067],{},[265,1068,267],{},[98,1070,1072,1078,1084,1090,1096],{"className":1071},[271],[50,1073,1075,1077],{"className":1074},[275],[277,1076],{"disabled":279,"type":280}," A primary and backup response coordinator are named.",[50,1079,1081,1083],{"className":1080},[275],[277,1082],{"disabled":279,"type":280}," Trusted contacts are accessible without the primary phone or email.",[50,1085,1087,1089],{"className":1086},[275],[277,1088],{"disabled":279,"type":280}," Someone has authority to pause payments, contact institutions, and protect devices and accounts.",[50,1091,1093,1095],{"className":1092},[275],[277,1094],{"disabled":279,"type":280}," First actions exist for the events that would cause the most harm.",[50,1097,1099,1101],{"className":1098},[275],[277,1100],{"disabled":279,"type":280}," The plan contains no secrets.",[18,1103,1104],{},"If an event is active, do not wait for Trawvid Sec before contacting emergency services, the financial institution, carrier, provider, insurer, law enforcement, or another qualified professional when appropriate. Trawvid Sec does not provide 24\u002F7 monitoring or guaranteed emergency response.",[13,1106,1108],{"id":1107},"finish-the-highest-value-work-in-30-days","Finish the highest-value work in 30 days",[18,1110,1111],{},"Do not turn this into a 70-item someday list. Close the root-account and money-movement gaps first, then reduce the ways those controls can be bypassed.",[135,1113,1114,1130],{},[138,1115,1116],{},[141,1117,1118,1121,1124,1127],{},[144,1119,1120],{},"Priority",[144,1122,1123],{},"Action",[144,1125,1126],{},"Owner and target date",[144,1128,1129],{},"Proof it is complete",[163,1131,1132,1144,1156,1168,1180],{},[141,1133,1134,1137,1140,1142],{},[168,1135,1136],{},"1",[168,1138,1139],{},"Protect primary email, recovery email, password manager, and carrier account",[168,1141],{},[168,1143],{},[141,1145,1146,1149,1152,1154],{},[168,1147,1148],{},"2",[168,1150,1151],{},"Publish the separate verification rule for wires, payees, and account changes",[168,1153],{},[168,1155],{},[141,1157,1158,1161,1164,1166],{},[168,1159,1160],{},"3",[168,1162,1163],{},"Review delegated access, shared files, family sharing, and recovery authority",[168,1165],{},[168,1167],{},[141,1169,1170,1173,1176,1178],{},[168,1171,1172],{},"4",[168,1174,1175],{},"Harden high-risk devices and test one backup restore",[168,1177],{},[168,1179],{},[141,1181,1182,1185,1188,1190],{},[168,1183,1184],{},"5",[168,1186,1187],{},"Store the first-hour plan outside the primary phone and email",[168,1189],{},[168,1191],{},[18,1193,1194,1195,1197],{},"Repeat the ",[28,1196,31],{"href":30}," after material changes, when a family or advisor relationship changes, after a serious scare, and at least annually. A strong score is useful, but an unresolved critical flag still deserves attention.",[18,1199,1200,1201,1204,1205,1208,1209,1212],{},"This guide should leave you with fewer unknowns, not a false promise that compromise is impossible. If recovery paths, advisor relationships, household sharing, or business overlap are difficult to untangle, ",[28,1202,1203],{"href":73},"email Trawvid Sec",", ",[28,1206,81],{"href":78,"rel":1207},[80],", or review the ",[28,1210,1211],{"href":633},"Personal Cyber Risk Review service",". Bring the decisions you cannot confidently close. Do not send passwords, recovery codes, financial secrets, or sensitive family documents.",{"title":1214,"searchDepth":1215,"depth":1215,"links":1216},"",2,[1217,1221,1225,1229,1233,1237,1241,1244],{"id":15,"depth":1215,"text":16,"children":1218},[1219],{"id":44,"depth":1220,"text":45},3,{"id":85,"depth":1215,"text":86,"children":1222},[1223,1224],{"id":95,"depth":1220,"text":96},{"id":132,"depth":1220,"text":133},{"id":308,"depth":1215,"text":309,"children":1226},[1227,1228],{"id":327,"depth":1220,"text":96},{"id":358,"depth":1220,"text":359},{"id":485,"depth":1215,"text":486,"children":1230},[1231,1232],{"id":495,"depth":1220,"text":96},{"id":521,"depth":1220,"text":522},{"id":638,"depth":1215,"text":639,"children":1234},[1235,1236],{"id":654,"depth":1220,"text":96},{"id":683,"depth":1220,"text":684},{"id":811,"depth":1215,"text":812,"children":1238},[1239,1240],{"id":826,"depth":1220,"text":96},{"id":852,"depth":1220,"text":853},{"id":958,"depth":1215,"text":39,"children":1242},[1243],{"id":967,"depth":1220,"text":968},{"id":1107,"depth":1215,"text":1108},"Personal cybersecurity","If account recovery, household sharing, delegated access, money movement, or incident planning is difficult to untangle, Trawvid Sec can help turn the unknowns into a practical hardening sequence.","Get help with your personal cyber plan","2026-08-04","A checklist-directed guide for protecting critical accounts, money movement, shared access, devices, backups, privacy, and personal cyber recovery.",false,"Allow 30 to 45 minutes for the first pass. Then work only the weak or high-consequence areas identified by the Personal Cyber Risk Checklist.","md",[1254,1255,1256],"The Personal Cyber Risk Checklist result, including weak sections and open critical flags.","The names of important email, financial, cloud, phone, and business-adjacent accounts. Do not record passwords or recovery secrets.","A short list of people who help manage accounts, files, payments, devices, or household affairs.",[1258,1259,1260],"A prioritized map of root accounts, recovery paths, financial workflows, delegated access, devices, backups, and public exposure.","A short first-hour recovery plan for account compromise, fraud, lost devices, identity misuse, or impersonation.","A realistic 30-day hardening plan focused on the changes that reduce the most risk.","2026-08-05",{},"\u002Fguides\u002Fpersonal-cyber-foundations",[1265,1267,1270,1274],{"label":31,"url":30,"description":1266},"Use the private guided assessment to identify weak areas, open critical flags, and the sections of this guide that deserve attention first.",{"label":1268,"url":633,"description":1269},"Personal Cyber Risk Review","Get practical help validating personal exposure, sequencing hardening work, and coordinating household or advisor workflows without handing over passwords.",{"label":1271,"url":1272,"description":1273},"Why Ordinary People Get Hacked","\u002Fblog\u002Fwhy-ordinary-people-get-hacked","Understand why ordinary accounts, recovery paths, and payment workflows are useful to criminals even when a person does not think of themselves as a target.",{"label":1275,"url":353,"description":1276},"What a Credit Freeze Does and How to Set One Up","Use the step-by-step companion article to place and maintain freezes at the three nationwide credit bureaus.","Current","This is a non-exhaustive educational guide for personal cybersecurity planning and configuration guidance. It is not managed IT, legal advice, financial advice, insurance advice, tax advice, digital forensics, emergency response, or 24\u002F7 monitoring. Trawvid Sec does not need or retain client passwords, recovery codes, seed phrases, private keys, or financial secrets. No checklist, configuration, or advisory engagement can guarantee that compromise, identity theft, fraud, harassment, or data loss will not occur. Product features and recovery processes change; confirm current instructions with each provider before making a material change.",{"title":6,"description":1249},"Personal Cybersecurity Guide for Executives and Households",[1282,1285,1287,1289,1291,1294,1297,1299],{"label":1283,"url":1284},"CISA Secure Our World","https:\u002F\u002Fwww.cisa.gov\u002Fsecure-our-world",{"label":1286,"url":126},"CISA: Use a Password Manager to Create and Remember Strong Passwords",{"label":1288,"url":648},"CISA: How to Protect Data Stored on Your Devices",{"label":1290,"url":318},"FTC: SIM Swap Scams and How to Protect Yourself",{"label":1292,"url":1293},"FBI: Business Email Compromise","https:\u002F\u002Fwww.fbi.gov\u002Fhow-we-can-help-you\u002Fscams-and-safety\u002Fcommon-frauds-and-scams\u002Fbusiness-email-compromise",{"label":1295,"url":1296},"FTC: Credit Freezes and Fraud Alerts","https:\u002F\u002Fconsumer.ftc.gov\u002Farticles\u002Fcredit-freezes-and-fraud-alerts",{"label":1298,"url":820},"FTC: What to Know About People Search Sites",{"label":1300,"url":1041},"IdentityTheft.gov Recovery Steps","guides\u002Fpersonal-cyber-foundations","1HepXSa1Rh7PTq_AwZdL-6en7AmIzQ2ZJoOvvEr5sbk",{"id":1304,"title":1305,"audience":1306,"author":8,"body":1307,"category":1883,"ctaDescription":1884,"ctaLabel":1885,"ctaUrl":1662,"date":1248,"description":1886,"draft":1250,"estimatedTime":1887,"extension":1252,"featured":1250,"guideInputs":1888,"guideOutputs":1892,"lastReviewed":1261,"meta":1896,"navigation":279,"path":1897,"relatedResources":1898,"reviewStatus":1277,"scopeNote":1910,"seo":1911,"seoTitle":1912,"sources":1913,"stem":1929,"__hash__":1930},"guides\u002Fguides\u002Fsafe-business-ai-use-and-approval.md","Safe Business AI Use and Approval Guide","Small-business owners, managers, employees, and internal technology leads",{"type":10,"value":1308,"toc":1867},[1309,1313,1316,1319,1322,1326,1329,1335,1338,1342,1345,1390,1393,1410,1413,1417,1420,1424,1427,1430,1434,1437,1441,1444,1447,1451,1454,1457,1496,1499,1503,1506,1532,1535,1568,1576,1580,1583,1609,1612,1615,1618,1657,1665,1669,1672,1675,1698,1701,1704,1736,1781,1784,1823,1827,1830,1833,1856,1864],[13,1310,1312],{"id":1311},"start-with-one-use-not-all-of-ai","Start with one use, not all of AI",[18,1314,1315],{},"A small business does not need a committee and a 40-page policy before an employee can draft a public event description. It also should not approve every possible use because one harmless demo looked useful.",[18,1317,1318],{},"Approve a specific task using a specific product, plan, and account. Name what information goes in, what comes out, who checks it, and whether the tool can reach or change anything else.",[18,1320,1321],{},"That is the workable boundary.",[42,1323,1325],{"id":1324},"the-employee-rule","The employee rule",[18,1327,1328],{},"A useful rule should fit on one page and make sense while somebody is working:",[1330,1331,1332],"blockquote",{},[18,1333,1334],{},"Use approved AI products through approved business accounts and for approved business purposes. Do not enter passwords, recovery codes, private keys, payment instructions, regulated information, confidential customer or employee records, or other restricted material unless the exact use has written approval. Verify important facts, calculations, citations, code, commitments, and decisions before the business relies on them. Do not connect mail, files, customer systems, code repositories, finance tools, browsers, or automation without approval. Report an unexpected disclosure, unsafe output, excessive access, or unapproved use promptly.",[18,1336,1337],{},"Change the examples to fit the business. Keep the five ideas intact: approved account, approved use, information boundary, human verification, and prompt reporting.",[13,1339,1341],{"id":1340},"step-1-describe-the-real-use","Step 1: Describe the real use",[18,1343,1344],{},"Do not approve \"ChatGPT,\" \"Copilot,\" or \"AI\" as a category. Describe the task another manager could recognize.",[135,1346,1347,1372],{},[138,1348,1349],{},[141,1350,1351,1354,1357,1360,1363,1366,1369],{},[144,1352,1353],{},"Product, plan, and account",[144,1355,1356],{},"Business task",[144,1358,1359],{},"Users",[144,1361,1362],{},"Information involved",[144,1364,1365],{},"Output destination",[144,1367,1368],{},"Human reviewer",[144,1370,1371],{},"Integrations or actions",[163,1373,1374],{},[141,1375,1376,1378,1380,1382,1384,1386,1388],{},[168,1377],{},[168,1379],{},[168,1381],{},[168,1383],{},[168,1385],{},[168,1387],{},[168,1389],{},[18,1391,1392],{},"Ask:",[98,1394,1395,1398,1401,1404,1407],{},[50,1396,1397],{},"What work is the person trying to complete?",[50,1399,1400],{},"Is the tool drafting, researching, analyzing, ranking, recommending, or acting?",[50,1402,1403],{},"What happens if the output is wrong, exposed, manipulated, or unavailable?",[50,1405,1406],{},"Will the output stay internal, reach a customer, change code, affect money, or influence a decision about a person?",[50,1408,1409],{},"Is a personal account, browser extension, or unapproved integration already being used?",[18,1411,1412],{},"If the business cannot name the task and accountable owner, do not move to product settings yet. The use is still too vague to approve.",[13,1414,1416],{"id":1415},"step-2-put-the-use-in-the-right-lane","Step 2: Put the use in the right lane",[18,1418,1419],{},"Classify the use, not the logo on the sign-in page.",[42,1421,1423],{"id":1422},"routine","Routine",[18,1425,1426],{},"Use this lane for reversible drafting with public or low-sensitivity information. A person reviews the result before it leaves draft status.",[18,1428,1429],{},"Examples include brainstorming public marketing ideas, improving the wording of a non-confidential email, or summarizing material already approved for public release.",[42,1431,1433],{"id":1432},"controlled","Controlled",[18,1435,1436],{},"Use this lane when the task involves internal information, customer-facing work, code, recurring analysis, an external commitment, or a connector. Complete the rest of this guide and keep the approval record.",[42,1438,1440],{"id":1439},"high-impact","High impact",[18,1442,1443],{},"Stop ordinary self-service approval when the output may materially affect employment, lending, insurance, healthcare, legal rights, safety, significant finance, regulated submissions, security action, or a critical business process.",[18,1445,1446],{},"Leadership and the appropriate legal, privacy, security, domain, fairness, safety, or compliance reviewers should define the operating boundary. This guide is not their approval.",[42,1448,1450],{"id":1449},"prohibited","Prohibited",[18,1452,1453],{},"Stop a use that requires passwords, authentication secrets, deceptive impersonation, unauthorized information, unlawful discrimination, evasion of safeguards, hidden material disclosure, or unsupervised action outside the business's authority.",[18,1455,1456],{},"Escalate out of the routine lane when any answer is yes:",[98,1458,1460,1466,1472,1478,1484,1490],{"className":1459},[271],[50,1461,1463,1465],{"className":1462},[275],[277,1464],{"disabled":279,"type":280}," The use receives confidential, regulated, privileged, contract-restricted, or highly sensitive personal information.",[50,1467,1469,1471],{"className":1468},[275],[277,1470],{"disabled":279,"type":280}," The output can affect a person, payment, contract, regulated submission, safety decision, or material customer commitment.",[50,1473,1475,1477],{"className":1474},[275],[277,1476],{"disabled":279,"type":280}," The tool can send, publish, purchase, approve, execute, change, or delete.",[50,1479,1481,1483],{"className":1480},[275],[277,1482],{"disabled":279,"type":280}," A connector can search broad mail, files, customer records, code, finance, or another important repository.",[50,1485,1487,1489],{"className":1486},[275],[277,1488],{"disabled":279,"type":280}," Failure could interrupt a critical operation or create a difficult recovery problem.",[50,1491,1493,1495],{"className":1492},[275],[277,1494],{"disabled":279,"type":280}," The business cannot meaningfully verify or challenge an important result.",[18,1497,1498],{},"Use the strictest lane that applies. Do not average a serious consequence into a comfortable score.",[13,1500,1502],{"id":1501},"step-3-set-the-information-boundary","Step 3: Set the information boundary",[18,1504,1505],{},"\"Do not enter sensitive data\" is too vague. Give employees categories they can recognize:",[98,1507,1508,1514,1520,1526],{},[50,1509,1510,1513],{},[265,1511,1512],{},"Public:"," Already approved for public release. Usually acceptable for an approved routine use.",[50,1515,1516,1519],{},[265,1517,1518],{},"Internal:"," Ordinary operating information that is not public but would not create material harm if disclosed. Use only within an approved business account and purpose.",[50,1521,1522,1525],{},[265,1523,1524],{},"Confidential:"," Customer or employee information, nonpublic financial data, contracts, code, strategy, security details, or material business records. Require review of the exact product and use before entry.",[50,1527,1528,1531],{},[265,1529,1530],{},"Restricted or secret:"," Passwords, authentication codes, recovery codes, access tokens, private keys, live payment instructions, privileged communications, controlled government information, or information the business has no right to disclose. Do not enter through ordinary AI use.",[18,1533,1534],{},"For the approved use:",[98,1536,1538,1544,1550,1556,1562],{"className":1537},[271],[50,1539,1541,1543],{"className":1540},[275],[277,1542],{"disabled":279,"type":280}," Remove information the task does not need.",[50,1545,1547,1549],{"className":1546},[275],[277,1548],{"disabled":279,"type":280}," Use excerpts, categories, ranges, de-identified examples, or synthetic data when they will answer the question.",[50,1551,1553,1555],{"className":1552},[275],[277,1554],{"disabled":279,"type":280}," Limit retrieval to a specific folder or source instead of an entire mailbox or drive where practical.",[50,1557,1559,1561],{"className":1558},[275],[277,1560],{"disabled":279,"type":280}," Decide where prompts, files, outputs, histories, and exports may be stored.",[50,1563,1565,1567],{"className":1564},[275],[277,1566],{"disabled":279,"type":280}," Name who can approve an exception.",[18,1569,1570,1571,1575],{},"The product, plan, settings, contract, support model, and integrations all affect data handling. The ",[28,1572,1574],{"href":1573},"\u002Fblog\u002Fhow-to-read-ai-product-data-privacy-terms","AI product terms guide"," explains how to check that exact boundary without assuming every service behaves the same way.",[13,1577,1579],{"id":1578},"step-4-check-the-product-and-the-human-handoff","Step 4: Check the product and the human handoff",[18,1581,1582],{},"Before approving a controlled use, answer these questions:",[47,1584,1585,1588,1591,1594,1597,1600,1603,1606],{},[50,1586,1587],{},"Is this the exact product and plan the business intends to buy?",[50,1589,1590],{},"Is it an approved business account with a known administrator and clean offboarding?",[50,1592,1593],{},"Do the terms and available settings fit the information being used?",[50,1595,1596],{},"Are training, retention, deletion, support access, and subprocessor expectations understood well enough for the consequence?",[50,1598,1599],{},"What must a person verify before the output is used?",[50,1601,1602],{},"Does the reviewer have enough knowledge, context, time, and authority to reject it?",[50,1604,1605],{},"Does any connector have more read or write access than the task needs?",[50,1607,1608],{},"Can the business disable the integration, revoke its credentials, and recover from a bad action?",[18,1610,1611],{},"\"Human in the loop\" is not an answer. Name the person and the check.",[18,1613,1614],{},"Ordinary business approvals still apply. AI does not bypass code review, payment approval, legal review, publication review, change approval, or a second set of eyes on a consequential decision.",[18,1616,1617],{},"For integrations and automated action:",[98,1619,1621,1627,1633,1639,1645,1651],{"className":1620},[271],[50,1622,1624,1626],{"className":1623},[275],[277,1625],{"disabled":279,"type":280}," Start read-only and with a limited dataset where possible.",[50,1628,1630,1632],{"className":1629},[275],[277,1631],{"disabled":279,"type":280}," Separate testing from production.",[50,1634,1636,1638],{"className":1635},[275],[277,1637],{"disabled":279,"type":280}," Require a person to confirm external, financial, privileged, destructive, or irreversible actions.",[50,1640,1642,1644],{"className":1641},[275],[277,1643],{"disabled":279,"type":280}," Keep useful logs for important actions and failures.",[50,1646,1648,1650],{"className":1647},[275],[277,1649],{"disabled":279,"type":280}," Confirm there is a disable, credential-revocation, rollback, or recovery path.",[50,1652,1654,1656],{"className":1653},[275],[277,1655],{"disabled":279,"type":280}," Treat instructions inside retrieved files, messages, and websites as untrusted input.",[18,1658,1659,1660,1664],{},"If the tool can act across mail, files, customer systems, finance, code, or production, a focused ",[28,1661,1663],{"href":1662},"\u002Fservices\u002Fsecurity-architecture-review","Security Architecture Review"," is more appropriate than stretching this short guide into an engineering assessment.",[13,1666,1668],{"id":1667},"step-5-test-the-work-and-record-the-decision","Step 5: Test the work and record the decision",[18,1670,1671],{},"A polished demonstration proves that a demonstration can look polished. Test the work the business will actually perform.",[18,1673,1674],{},"Use a small user group and a narrow task. Include:",[98,1676,1677,1680,1683,1686,1689,1692,1695],{},[50,1678,1679],{},"A normal example.",[50,1681,1682],{},"An ambiguous or incomplete request.",[50,1684,1685],{},"A request based on a false premise.",[50,1687,1688],{},"A case where a confident wrong answer would matter.",[50,1690,1691],{},"A request the tool should refuse or escalate.",[50,1693,1694],{},"A sensitive-data or access-boundary test when relevant.",[50,1696,1697],{},"A provider failure or unavailable-tool scenario when the workflow is important.",[18,1699,1700],{},"Measure value after review and rework, not before. A tool that saves ten minutes of drafting and creates twenty minutes of checking did not save time.",[18,1702,1703],{},"Choose one decision:",[98,1705,1706,1712,1718,1724,1730],{},[50,1707,1708,1711],{},[265,1709,1710],{},"Approve:"," The narrow use is understood and the controls fit.",[50,1713,1714,1717],{},[265,1715,1716],{},"Approve with conditions:"," The use may proceed after named settings, training, tests, or limitations are completed.",[50,1719,1720,1723],{},[265,1721,1722],{},"Revise and retest:"," The task, data, review, or integration boundary needs to change.",[50,1725,1726,1729],{},[265,1727,1728],{},"Do not approve:"," The risk, burden, or lack of value does not justify the use.",[50,1731,1732,1735],{},[265,1733,1734],{},"Escalate:"," The use needs qualified review beyond this guide.",[135,1737,1738,1763],{},[138,1739,1740],{},[141,1741,1742,1745,1748,1751,1754,1757,1760],{},[144,1743,1744],{},"Use",[144,1746,1747],{},"Lane and decision",[144,1749,1750],{},"Approved product, account, and purpose",[144,1752,1753],{},"Information allowed",[144,1755,1756],{},"Required reviewer",[144,1758,1759],{},"Conditions and owner",[144,1761,1762],{},"Next review trigger",[163,1764,1765],{},[141,1766,1767,1769,1771,1773,1775,1777,1779],{},[168,1768],{},[168,1770],{},[168,1772],{},[168,1774],{},[168,1776],{},[168,1778],{},[168,1780],{},[18,1782,1783],{},"The decision is usable when:",[98,1785,1787,1793,1799,1805,1811,1817],{"className":1786},[271],[50,1788,1790,1792],{"className":1789},[275],[277,1791],{"disabled":279,"type":280}," The approved task and users are narrow enough to explain.",[50,1794,1796,1798],{"className":1795},[275],[277,1797],{"disabled":279,"type":280}," The information rule is understandable during ordinary work.",[50,1800,1802,1804],{"className":1801},[275],[277,1803],{"disabled":279,"type":280}," Important output has a named verification method.",[50,1806,1808,1810],{"className":1807},[275],[277,1809],{"disabled":279,"type":280}," Integrations and actions stay within the approved boundary.",[50,1812,1814,1816],{"className":1813},[275],[277,1815],{"disabled":279,"type":280}," Employees know where to report a mistake.",[50,1818,1820,1822],{"className":1819},[275],[277,1821],{"disabled":279,"type":280}," Product, plan, data, integration, purpose, or consequence changes trigger review.",[13,1824,1826],{"id":1825},"make-mistakes-reportable","Make mistakes reportable",[18,1828,1829],{},"Employees will occasionally choose the wrong account, paste the wrong text, trust a bad answer, or discover that a connector reached more than expected. Fast reporting gives the business a chance to contain the mistake.",[18,1831,1832],{},"Tell employees to report:",[98,1834,1835,1838,1841,1844,1847,1850,1853],{},[50,1836,1837],{},"Sensitive information entered through the wrong account.",[50,1839,1840],{},"Unexpected sharing or public exposure.",[50,1842,1843],{},"A connector reaching more information than expected.",[50,1845,1846],{},"False, harmful, insecure, or dangerous output used or nearly used.",[50,1848,1849],{},"A generated citation, calculation, code change, or commitment that caused a problem.",[50,1851,1852],{},"An unapproved product, extension, account, integration, or automated action.",[50,1854,1855],{},"Suspicious instructions or unexpected account activity.",[18,1857,1858,1859,1863],{},"Do not make the first instruction \"delete everything.\" Preserve enough facts to understand what happened, reduce further exposure, and use ",[28,1860,1862],{"href":1861},"\u002Fresources\u002Fsmall-business-cyber-incident-first-actions","Small Business Cyber Incident First Actions"," when disclosure, compromise, fraud, or harmful action may be involved.",[18,1865,1866],{},"If the use remains difficult to classify or the connector boundary cannot be explained in plain language, use the email and booking options on this page. Bring the proposed task, product, and unanswered questions. Do not send confidential prompts, customer files, credentials, or access tokens.",{"title":1214,"searchDepth":1215,"depth":1215,"links":1868},[1869,1872,1873,1879,1880,1881,1882],{"id":1311,"depth":1215,"text":1312,"children":1870},[1871],{"id":1324,"depth":1220,"text":1325},{"id":1340,"depth":1215,"text":1341},{"id":1415,"depth":1215,"text":1416,"children":1874},[1875,1876,1877,1878],{"id":1422,"depth":1220,"text":1423},{"id":1432,"depth":1220,"text":1433},{"id":1439,"depth":1220,"text":1440},{"id":1449,"depth":1220,"text":1450},{"id":1501,"depth":1215,"text":1502},{"id":1578,"depth":1215,"text":1579},{"id":1667,"depth":1215,"text":1668},{"id":1825,"depth":1215,"text":1826},"Business cybersecurity","If the proposed use touches sensitive information, business-critical decisions, customer commitments, code, or broad integrations, test the boundary before rollout.","Discuss an AI use or integration","A practical guide for setting a usable employee AI rule, reviewing a specific business use, and knowing when an integration or high-impact decision needs deeper review.","Allow about 20 minutes for an ordinary use. Stop and obtain qualified review before approving high-impact decisions, sensitive data use, broad integrations, or automated action.",[1889,1890,1891],"The exact business task, intended users, product, plan, account type, and person accountable for the result.","The information the tool may receive and the place its output will go.","Any connector, extension, integration, or automated action the use requires.",[1893,1894,1895],"A short employee rule for ordinary AI use.","A routine, controlled, high-impact, or prohibited decision for the specific use.","An approval record with boundaries, reviewer, conditions, and next review trigger.",{},"\u002Fguides\u002Fsafe-business-ai-use-and-approval",[1899,1902,1906,1908],{"label":1900,"url":1573,"description":1901},"How to Read AI Product Terms","Check plan-specific terms, retention, training controls, contracts, and integrations before approving a product for sensitive work.",{"label":1903,"url":1904,"description":1905},"Small Business Vendor and IT Provider Security","\u002Fresources\u002Fsmall-business-vendor-it-provider-security","Use the provider guide when the AI product is becoming a material vendor or business dependency.",{"label":1862,"url":1861,"description":1907},"Use the incident guide if information was disclosed, an account was compromised, or an AI action caused harm.",{"label":1663,"url":1662,"description":1909},"Review a connector, agent, data flow, or automation when the technical boundary is not obvious.","This is a non-exhaustive guide to the AI-use questions most likely to matter for a small business. It is not legal, employment, privacy, intellectual-property, financial, regulatory, safety, or sector-specific advice. It does not certify a product or guarantee accurate, fair, secure, or lawful output. High-impact uses, regulated information, material decisions about people, and broad system integrations may require qualified review beyond this guide.",{"title":1305,"description":1886},"Small Business AI Use and Approval Guide",[1914,1917,1920,1923,1926],{"label":1915,"url":1916},"NIST Artificial Intelligence Risk Management Framework","https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fai-risk-management-framework",{"label":1918,"url":1919},"NIST AI 600-1: Generative Artificial Intelligence Profile","https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fartificial-intelligence-risk-management-framework-generative-artificial-intelligence",{"label":1921,"url":1922},"NIST AI Resource Center","https:\u002F\u002Fairc.nist.gov\u002F",{"label":1924,"url":1925},"NSA and CISA Joint Guidance: AI Data Security","https:\u002F\u002Fwww.nsa.gov\u002FPress-Room\u002FPress-Releases-Statements\u002FPress-Release-View\u002FArticle\u002F4192332\u002Fnsas-aisc-releases-joint-guidance-on-the-risks-and-best-practices-in-ai-data-se\u002F",{"label":1927,"url":1928},"FTC Privacy and Security Guidance","https:\u002F\u002Fwww.ftc.gov\u002Fbusiness-guidance\u002Fprivacy-security","guides\u002Fsafe-business-ai-use-and-approval","y61nMAUdIvx0AfXli_6qMyLqmqsdeqe1KYdKjH2zjJI",{"id":1932,"title":1933,"audience":1934,"author":8,"body":1935,"category":2846,"ctaDescription":2847,"ctaLabel":2848,"ctaUrl":2849,"date":1248,"description":2850,"draft":1250,"estimatedTime":2851,"extension":1252,"featured":279,"guideInputs":2852,"guideOutputs":2856,"lastReviewed":1261,"meta":2860,"navigation":279,"path":2861,"relatedResources":2862,"reviewStatus":1277,"scopeNote":2874,"seo":2875,"seoTitle":2876,"sources":2877,"stem":2893,"__hash__":2894},"guides\u002Fguides\u002Fsmall-business-cyber-incident-first-actions.md","Something Happened: Small Business Cyber Incident First Actions","Small-business owners, operations leaders, and technology contacts",{"type":10,"value":1936,"toc":2829},[1937,1941,1944,1948,1986,1989,2022,2025,2065,2068,2072,2076,2079,2136,2139,2143,2146,2197,2200,2204,2255,2259,2320,2323,2327,2372,2375,2379,2424,2428,2431,2512,2515,2518,2522,2525,2631,2634,2637,2641,2644,2712,2715,2754,2757,2761,2764,2790,2793,2826],[13,1938,1940],{"id":1939},"if-something-is-happening-now-start-here","If something is happening now, start here",[18,1942,1943],{},"Do not wait for a perfect diagnosis. The first job is to protect people, stop immediate loss, keep a useful record, and avoid making the event harder to investigate.",[42,1945,1947],{"id":1946},"the-universal-first-actions","The universal first actions",[47,1949,1950,1956,1962,1968,1974,1980],{},[50,1951,1952,1955],{},[265,1953,1954],{},"Protect people and physical operations."," Life safety and operational safety come before a computer.",[50,1957,1958,1961],{},[265,1959,1960],{},"Call the bank if money may have moved."," Use a known number and ask for the fraud or wire department. Request a recall or reversal and record the case number.",[50,1963,1964,1967],{},[265,1965,1966],{},"Limit active spread when it is safe."," Disconnect a clearly affected device from wired and wireless networks when malware appears to be spreading. Do not connect backups or random cleanup tools.",[50,1969,1970,1973],{},[265,1971,1972],{},"Move communication away from suspected systems."," If email or chat may be compromised, use a known-clean phone or another trusted channel.",[50,1975,1976,1979],{},[265,1977,1978],{},"Name one incident owner."," That person coordinates actions, times, facts, outside calls, and the next update. They do not need to perform every technical task.",[50,1981,1982,1985],{},[265,1983,1984],{},"Get qualified help when the business cannot confidently contain, preserve, scope, or recover."," A serious event is not the time to learn digital forensics through search results.",[18,1987,1988],{},"Avoid these common mistakes:",[98,1990,1992,1998,2004,2010,2016],{"className":1991},[271],[50,1993,1995,1997],{"className":1994},[275],[277,1996],{"disabled":279,"type":280}," Do not wipe, reimage, or broadly reset systems before useful evidence needs are understood.",[50,1999,2001,2003],{"className":2000},[275],[277,2002],{"disabled":279,"type":280}," Do not delete suspicious messages, logs, or files just because they look dangerous.",[50,2005,2007,2009],{"className":2006},[275],[277,2008],{"disabled":279,"type":280}," Do not coordinate through an account that may be compromised.",[50,2011,2013,2015],{"className":2012},[275],[277,2014],{"disabled":279,"type":280}," Do not make public or customer statements beyond the supported facts.",[50,2017,2019,2021],{"className":2018},[275],[277,2020],{"disabled":279,"type":280}," Do not delay a bank, emergency, insurer, legal, or law-enforcement call while waiting for Trawvid Sec to reply.",[18,2023,2024],{},"Open one simple control record:",[135,2026,2027,2049],{},[138,2028,2029],{},[141,2030,2031,2034,2037,2040,2043,2046],{},[144,2032,2033],{},"Incident or concern",[144,2035,2036],{},"Discovered date and time",[144,2038,2039],{},"Incident owner",[144,2041,2042],{},"Leadership decision-maker",[144,2044,2045],{},"Trusted communication channel",[144,2047,2048],{},"Next update",[163,2050,2051],{},[141,2052,2053,2055,2057,2059,2061,2063],{},[168,2054],{},[168,2056],{},[168,2058],{},[168,2060],{},[168,2062],{},[168,2064],{},[18,2066,2067],{},"Then use every scenario below that may apply. A fraudulent payment may also involve a compromised mailbox. A provider incident may also expose sensitive information.",[13,2069,2071],{"id":2070},"choose-the-scenario-actions-that-fit","Choose the scenario actions that fit",[42,2073,2075],{"id":2074},"payment-wire-payroll-or-invoice-fraud","Payment, wire, payroll, or invoice fraud",[18,2077,2078],{},"Act quickly. Recovery options get worse as time passes.",[98,2080,2082,2088,2094,2100,2106,2112,2118,2130],{"className":2081},[271],[50,2083,2085,2087],{"className":2084},[275],[277,2086],{"disabled":279,"type":280}," Call the originating financial institution through a known number.",[50,2089,2091,2093],{"className":2090},[275],[277,2092],{"disabled":279,"type":280}," Ask for the fraud or wire department and request a recall or reversal.",[50,2095,2097,2099],{"className":2096},[275],[277,2098],{"disabled":279,"type":280}," Record the case number, time, instructions, and next follow-up.",[50,2101,2103,2105],{"className":2102},[275],[277,2104],{"disabled":279,"type":280}," Verify the request with the intended vendor, employee, executive, or advisor through a known second channel.",[50,2107,2109,2111],{"className":2108},[275],[277,2110],{"disabled":279,"type":280}," Preserve the original request, invoice, message, email headers when available, and transaction confirmation.",[50,2113,2115,2117],{"className":2114},[275],[277,2116],{"disabled":279,"type":280}," Review related payments and recent changes during the suspected exposure window.",[50,2119,2121,2123,2124,2129],{"className":2120},[275],[277,2122],{"disabled":279,"type":280}," File promptly with ",[28,2125,2128],{"href":2126,"rel":2127},"https:\u002F\u002Fwww.ic3.gov\u002F",[80],"IC3"," when the event involves internet-enabled fraud.",[50,2131,2133,2135],{"className":2132},[275],[277,2134],{"disabled":279,"type":280}," Use the account-compromise path below if a mailbox or identity account may be involved.",[18,2137,2138],{},"Do not continue the suspicious thread to ask whether it is legitimate. Contact the known person another way.",[42,2140,2142],{"id":2141},"email-cloud-or-identity-account-compromise","Email, cloud, or identity account compromise",[18,2144,2145],{},"Use a known-clean device and administrative path when available.",[98,2147,2149,2155,2161,2167,2173,2179,2185,2191],{"className":2148},[271],[50,2150,2152,2154],{"className":2151},[275],[277,2153],{"disabled":279,"type":280}," Move response communication outside the suspected account.",[50,2156,2158,2160],{"className":2157},[275],[277,2159],{"disabled":279,"type":280}," Preserve available sign-in history, active sessions, forwarding rules, inbox rules, delegates, recovery changes, multifactor changes, and connected applications.",[50,2162,2164,2166],{"className":2163},[275],[277,2165],{"disabled":279,"type":280}," Block or suspend sign-in when the evidence and business impact support it.",[50,2168,2170,2172],{"className":2169},[275],[277,2171],{"disabled":279,"type":280}," Revoke active sessions and refresh tokens.",[50,2174,2176,2178],{"className":2175},[275],[277,2177],{"disabled":279,"type":280}," Reset the credential to a unique value from a known-clean device.",[50,2180,2182,2184],{"className":2181},[275],[277,2183],{"disabled":279,"type":280}," Remove unknown recovery methods, forwarding, delegates, and application permissions.",[50,2186,2188,2190],{"className":2187},[275],[277,2189],{"disabled":279,"type":280}," Re-establish the legitimate user and verify known devices.",[50,2192,2194,2196],{"className":2193},[275],[277,2195],{"disabled":279,"type":280}," Review which financial, payroll, cloud, customer, domain, social, and password-recovery workflows the account could influence.",[18,2198,2199],{},"Do not assume a password change ends the event. Sessions, forwarding rules, recovery methods, and connected applications may survive it.",[42,2201,2203],{"id":2202},"lost-or-stolen-phone-or-computer","Lost or stolen phone or computer",[98,2205,2207,2213,2219,2225,2231,2237,2243,2249],{"className":2206},[271],[50,2208,2210,2212],{"className":2209},[275],[277,2211],{"disabled":279,"type":280}," Record the device owner, type, identifying information, last known time, and location.",[50,2214,2216,2218],{"className":2215},[275],[277,2217],{"disabled":279,"type":280}," Determine whether the device was encrypted, locked, managed, and signed in to important accounts.",[50,2220,2222,2224],{"className":2221},[275],[277,2223],{"disabled":279,"type":280}," Preserve management records showing encryption, last check-in, and actions taken.",[50,2226,2228,2230],{"className":2227},[275],[277,2229],{"disabled":279,"type":280}," Use trusted locate, lock, or erase controls when the facts support that decision.",[50,2232,2234,2236],{"className":2233},[275],[277,2235],{"disabled":279,"type":280}," Revoke high-risk sessions and protect accounts available from the device.",[50,2238,2240,2242],{"className":2239},[275],[277,2241],{"disabled":279,"type":280}," For a phone, contact the carrier through a known number and check for a number transfer or SIM change.",[50,2244,2246,2248],{"className":2245},[275],[277,2247],{"disabled":279,"type":280}," Record whether sensitive, regulated, confidential, or contract-protected information may have been available.",[50,2250,2252,2254],{"className":2251},[275],[277,2253],{"disabled":279,"type":280}," Make a police report when theft is suspected and keep the report number.",[42,2256,2258],{"id":2257},"malware-ransomware-or-spreading-unusual-activity","Malware, ransomware, or spreading unusual activity",[98,2260,2262,2268,2274,2280,2286,2292,2298,2304],{"className":2261},[271],[50,2263,2265,2267],{"className":2264},[275],[277,2266],{"disabled":279,"type":280}," Disconnect confirmed or strongly suspected devices from networks when safe.",[50,2269,2271,2273],{"className":2270},[275],[277,2272],{"disabled":279,"type":280}," Coordinate broader isolation through network controls when many systems are involved.",[50,2275,2277,2279],{"className":2276},[275],[277,2278],{"disabled":279,"type":280}," Protect backup administration and known-good recovery points. Do not connect offline backups to test them.",[50,2281,2283,2285],{"className":2282},[275],[277,2284],{"disabled":279,"type":280}," Preserve ransom notes, screenshots, filenames, alerts, logs, and a representative affected-system list.",[50,2287,2289,2291],{"className":2288},[275],[277,2290],{"disabled":279,"type":280}," Contact qualified response support when the business cannot confidently contain or preserve the event.",[50,2293,2295,2297],{"className":2294},[275],[277,2296],{"disabled":279,"type":280}," Contact the cyber insurer according to the policy and confirm any vendor requirements before major expense when time permits.",[50,2299,2301,2303],{"className":2300},[275],[277,2302],{"disabled":279,"type":280}," Record who can stop operations, approve workarounds, and decide recovery order.",[50,2305,2307,2309,2310,2313,2314,2319],{"className":2306},[275],[277,2308],{"disabled":279,"type":280}," Report ransomware to a local FBI field office or ",[28,2311,2128],{"href":2126,"rel":2312},[80]," and consider reporting to ",[28,2315,2318],{"href":2316,"rel":2317},"https:\u002F\u002Fwww.cisa.gov\u002Freport",[80],"CISA",".",[18,2321,2322],{},"Do not download a decryptor or cleanup utility from a random search result. Do not treat an extortion payment like an ordinary purchase. The FBI does not support paying ransom, and payment does not guarantee recovery or deletion.",[42,2324,2326],{"id":2325},"sensitive-information-may-have-been-exposed","Sensitive information may have been exposed",[98,2328,2330,2336,2342,2348,2354,2360,2366],{"className":2329},[271],[50,2331,2333,2335],{"className":2332},[275],[277,2334],{"disabled":279,"type":280}," Stop additional access by restricting the folder, disabling the public link, removing the page, or isolating the source.",[50,2337,2339,2341],{"className":2338},[275],[277,2340],{"disabled":279,"type":280}," Preserve screenshots, settings, access history, logs, message headers, and timestamps before changing more than necessary.",[50,2343,2345,2347],{"className":2344},[275],[277,2346],{"disabled":279,"type":280}," Record what information was involved, whose information it was, and the likely exposure period.",[50,2349,2351,2353],{"className":2350},[275],[277,2352],{"disabled":279,"type":280}," Determine whether information was viewed, downloaded, altered, or only potentially available.",[50,2355,2357,2359],{"className":2356},[275],[277,2358],{"disabled":279,"type":280}," Identify affected systems, providers, contracts, customers, and business relationships.",[50,2361,2363,2365],{"className":2362},[275],[277,2364],{"disabled":279,"type":280}," Engage qualified counsel before making legal-notification conclusions or definitive external statements.",[50,2367,2369,2371],{"className":2368},[275],[277,2370],{"disabled":279,"type":280}," Assign someone to check for copies in recipient systems, search results, caches, or other locations.",[18,2373,2374],{},"Do not say \"no data was accessed\" merely because access has not yet been proven.",[42,2376,2378],{"id":2377},"a-vendor-or-technology-provider-reported-an-incident","A vendor or technology provider reported an incident",[98,2380,2382,2388,2394,2400,2406,2412,2418],{"className":2381},[271],[50,2383,2385,2387],{"className":2384},[275],[277,2386],{"disabled":279,"type":280}," Identify what the provider can access, administer, reset, export, delete, or interrupt.",[50,2389,2391,2393],{"className":2390},[275],[277,2392],{"disabled":279,"type":280}," Preserve the provider notice and your own relevant logs before retention periods close.",[50,2395,2397,2399],{"className":2396},[275],[277,2398],{"disabled":279,"type":280}," Ask for dates, affected services, customer impact, required actions, containment status, and the next update time.",[50,2401,2403,2405],{"className":2402},[275],[277,2404],{"disabled":279,"type":280}," Narrow unnecessary access or rotate affected credentials when the facts support it.",[50,2407,2409,2411],{"className":2408},[275],[277,2410],{"disabled":279,"type":280}," Verify remediation that matters to your environment rather than relying only on a general assurance.",[50,2413,2415,2417],{"className":2414},[275],[277,2416],{"disabled":279,"type":280}," Assign the customer, contract, insurance, legal, and regulatory questions to the appropriate people.",[50,2419,2421,2423],{"className":2420},[275],[277,2422],{"disabled":279,"type":280}," Record any decision to keep access active because immediate removal would create a larger safety or continuity problem.",[13,2425,2427],{"id":2426},"keep-one-running-record","Keep one running record",[18,2429,2430],{},"Do not create a different worksheet for every thought. Keep one timeline that separates facts, assumptions, actions, decisions, and open questions.",[135,2432,2433,2454],{},[138,2434,2435],{},[141,2436,2437,2440,2443,2446,2449,2451],{},[144,2438,2439],{},"Time",[144,2441,2442],{},"Fact, assumption, action, or decision",[144,2444,2445],{},"Source or person",[144,2447,2448],{},"Result or reason",[144,2450,161],{},[144,2452,2453],{},"Next action or update",[163,2455,2456,2470,2484,2498],{},[141,2457,2458,2460,2462,2464,2466,2468],{},[168,2459],{},[168,2461],{},[168,2463],{},[168,2465],{},[168,2467],{},[168,2469],{},[141,2471,2472,2474,2476,2478,2480,2482],{},[168,2473],{},[168,2475],{},[168,2477],{},[168,2479],{},[168,2481],{},[168,2483],{},[141,2485,2486,2488,2490,2492,2494,2496],{},[168,2487],{},[168,2489],{},[168,2491],{},[168,2493],{},[168,2495],{},[168,2497],{},[141,2499,2500,2502,2504,2506,2508,2510],{},[168,2501],{},[168,2503],{},[168,2505],{},[168,2507],{},[168,2509],{},[168,2511],{},[18,2513,2514],{},"Preserve original records before forwarding, editing, wiping, or reimaging. Store the incident record outside the suspected environment and limit access to people who have a role in the response.",[18,2516,2517],{},"A new responder should be able to read the timeline and understand what is known, what remains uncertain, what has been done, and what decision comes next.",[13,2519,2521],{"id":2520},"decide-who-needs-to-be-called","Decide who needs to be called",[18,2523,2524],{},"Not every event needs every outside party. Every material call should have an owner and a next follow-up.",[135,2526,2527,2545],{},[138,2528,2529],{},[141,2530,2531,2534,2537,2540,2542],{},[144,2532,2533],{},"Party",[144,2535,2536],{},"Call when",[144,2538,2539],{},"Trusted contact",[144,2541,161],{},[144,2543,2544],{},"Case number or next follow-up",[163,2546,2547,2561,2575,2589,2603,2617],{},[141,2548,2549,2552,2555,2557,2559],{},[168,2550,2551],{},"Bank or payment provider",[168,2553,2554],{},"Money moved or payment details may be fraudulent",[168,2556],{},[168,2558],{},[168,2560],{},[141,2562,2563,2566,2569,2571,2573],{},[168,2564,2565],{},"Technology or incident-response provider",[168,2567,2568],{},"The business cannot confidently contain, preserve, scope, or recover",[168,2570],{},[168,2572],{},[168,2574],{},[141,2576,2577,2580,2583,2585,2587],{},[168,2578,2579],{},"Insurer or broker",[168,2581,2582],{},"The policy may require notice or approved response vendors",[168,2584],{},[168,2586],{},[168,2588],{},[141,2590,2591,2594,2597,2599,2601],{},[168,2592,2593],{},"Qualified counsel",[168,2595,2596],{},"Personal, regulated, contract-protected, extortion, employee, or material notice questions may exist",[168,2598],{},[168,2600],{},[168,2602],{},[141,2604,2605,2608,2611,2613,2615],{},[168,2606,2607],{},"Law enforcement or government",[168,2609,2610],{},"Fraud, ransomware, theft, or another reportable crime may be involved",[168,2612],{},[168,2614],{},[168,2616],{},[141,2618,2619,2622,2625,2627,2629],{},[168,2620,2621],{},"Critical customer or partner",[168,2623,2624],{},"Supported facts show a material operational or contractual impact requiring coordinated communication",[168,2626],{},[168,2628],{},[168,2630],{},[18,2632,2633],{},"Give leadership the known business impact, uncertainty, decisions required, and next update time. Give technical responders the systems, accounts, indicators, evidence, actions, and dependencies. Give employees only the instructions they need to avoid more harm and continue approved work.",[18,2635,2636],{},"Technical staff should not guess legal duties. Legal reviewers should not guess technical facts. Keep the handoff explicit.",[13,2638,2640],{"id":2639},"recover-in-business-order","Recover in business order",[18,2642,2643],{},"Containment is not the finish line. Restore services according to business need, not whichever system is easiest to turn back on.",[135,2645,2646,2668],{},[138,2647,2648],{},[141,2649,2650,2653,2656,2659,2662,2665],{},[144,2651,2652],{},"Service or process",[144,2654,2655],{},"Business priority",[144,2657,2658],{},"Workaround",[144,2660,2661],{},"Technical owner",[144,2663,2664],{},"Business approver",[144,2666,2667],{},"Return criteria or remaining concern",[163,2669,2670,2684,2698],{},[141,2671,2672,2674,2676,2678,2680,2682],{},[168,2673],{},[168,2675],{},[168,2677],{},[168,2679],{},[168,2681],{},[168,2683],{},[141,2685,2686,2688,2690,2692,2694,2696],{},[168,2687],{},[168,2689],{},[168,2691],{},[168,2693],{},[168,2695],{},[168,2697],{},[141,2699,2700,2702,2704,2706,2708,2710],{},[168,2701],{},[168,2703],{},[168,2705],{},[168,2707],{},[168,2709],{},[168,2711],{},[18,2713,2714],{},"Before returning an affected service:",[98,2716,2718,2724,2730,2736,2742,2748],{"className":2717},[271],[50,2719,2721,2723],{"className":2720},[275],[277,2722],{"disabled":279,"type":280}," Address the suspected access path enough to avoid immediate recurrence.",[50,2725,2727,2729],{"className":2726},[275],[277,2728],{"disabled":279,"type":280}," Review affected credentials, sessions, keys, integrations, and administrator paths.",[50,2731,2733,2735],{"className":2732},[275],[277,2734],{"disabled":279,"type":280}," Confirm the restore source is appropriate.",[50,2737,2739,2741],{"className":2738},[275],[277,2740],{"disabled":279,"type":280}," Confirm required updates, logging, and monitoring are operating.",[50,2743,2745,2747],{"className":2744},[275],[277,2746],{"disabled":279,"type":280}," Test that the service performs the business function expected.",[50,2749,2751,2753],{"className":2750},[275],[277,2752],{"disabled":279,"type":280}," Record who approved the return, what remains uncertain, and how long heightened monitoring will continue.",[18,2755,2756],{},"Keep a service offline when the return criteria are not met and an approved workaround is safer.",[13,2758,2760],{"id":2759},"prepare-before-the-first-hour","Prepare before the first hour",[18,2762,2763],{},"Do this section when no incident is active.",[47,2765,2766,2769,2772,2775,2778,2781,2784,2787],{},[50,2767,2768],{},"Name the incident owner, leadership decision-maker, and backups.",[50,2770,2771],{},"Save known-clean contact methods for the technology provider, bank fraud team, insurer or broker, counsel, and critical vendors.",[50,2773,2774],{},"Decide where the incident timeline can be kept when company email or cloud storage is unavailable.",[50,2776,2777],{},"Record where asset, account, log, backup, insurance, and recovery information can be reached.",[50,2779,2780],{},"Choose a communication method outside company email.",[50,2782,2783],{},"List the business processes that must return first.",[50,2785,2786],{},"Walk through one realistic scenario for 20 minutes.",[50,2788,2789],{},"Fix the largest assumption the exercise exposes.",[18,2791,2792],{},"The preparation is usable when:",[98,2794,2796,2802,2808,2814,2820],{"className":2795},[271],[50,2797,2799,2801],{"className":2798},[275],[277,2800],{"disabled":279,"type":280}," The contact information works without company email.",[50,2803,2805,2807],{"className":2804},[275],[277,2806],{"disabled":279,"type":280}," Decision authority is clear.",[50,2809,2811,2813],{"className":2810},[275],[277,2812],{"disabled":279,"type":280}," The business knows where its basic records and recovery information live.",[50,2815,2817,2819],{"className":2816},[275],[277,2818],{"disabled":279,"type":280}," One scenario has been discussed.",[50,2821,2823,2825],{"className":2822},[275],[277,2824],{"disabled":279,"type":280}," Every discovered gap has an owner and date.",[18,2827,2828],{},"If the event is active and material, use the email and booking options on this page only as an additional advisory path. Do not delay emergency services, a financial institution, the phone carrier, an existing response provider, the insurer, qualified counsel, or law enforcement while waiting for a reply.",{"title":1214,"searchDepth":1215,"depth":1215,"links":2830},[2831,2834,2842,2843,2844,2845],{"id":1939,"depth":1215,"text":1940,"children":2832},[2833],{"id":1946,"depth":1220,"text":1947},{"id":2070,"depth":1215,"text":2071,"children":2835},[2836,2837,2838,2839,2840,2841],{"id":2074,"depth":1220,"text":2075},{"id":2141,"depth":1220,"text":2142},{"id":2202,"depth":1220,"text":2203},{"id":2257,"depth":1220,"text":2258},{"id":2325,"depth":1220,"text":2326},{"id":2377,"depth":1220,"text":2378},{"id":2426,"depth":1215,"text":2427},{"id":2520,"depth":1215,"text":2521},{"id":2639,"depth":1215,"text":2640},{"id":2759,"depth":1215,"text":2760},"Incident readiness","If the contact list, decision owners, evidence sources, or recovery order are unclear, build those answers before an incident forces the conversation.","Prepare for the first hour","\u002Fservices\u002Fincident-readiness","A practical first-hour guide for stopping immediate loss, choosing the right scenario actions, preserving useful facts, and calling the right people.","The universal first actions should take less than five minutes to read. Use only the scenario paths that fit the event. A preparation review normally takes about 30 minutes.",[2853,2854,2855],"A known-clean phone or communication channel that does not depend on the suspected system.","Current leadership, technology-provider, bank, insurer, legal, and critical-vendor contacts.","A safe place outside the suspected environment to record times, facts, actions, and case numbers.",[2857,2858,2859],"A named incident owner, trusted communication path, and next update time.","A short incident timeline with the relevant scenario actions and outside contacts.","A business-approved recovery order and open-action handoff.",{},"\u002Fguides\u002Fsmall-business-cyber-incident-first-actions",[2863,2866,2870],{"label":2864,"url":2849,"description":2865},"Incident Readiness Advisory","Clarify roles, escalation paths, evidence needs, communication expectations, and recovery decisions before an event.",{"label":2867,"url":2868,"description":2869},"Small Business Security Foundations","\u002Fresources\u002Fsmall-business-security-foundations","Build the account, device, backup, ownership, and contact basics that make the first hour less chaotic.",{"label":2871,"url":2872,"description":2873},"Cyber Insurance Is a Seatbelt, Not a Security Program","\u002Fblog\u002Fcyber-insurance-is-a-seatbelt-not-a-security-program","Understand what insurance may support and what the business still has to own.","This is a non-exhaustive first-actions guide, not a substitute for qualified incident response, digital forensics, legal advice, breach counsel, emergency services, managed IT, or 24\u002F7 monitoring. If people are in danger, call emergency services. If money may have moved, contact the financial institution immediately. Material incidents, ransomware, safety concerns, or possible exposure of regulated or contract-protected information may require urgent professional and legal support.",{"title":1933,"description":2850},"Small Business Cyber Incident Response: First Actions",[2878,2881,2884,2887,2890],{"label":2879,"url":2880},"NIST SP 800-61 Rev. 3: Incident Response Recommendations","https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Fsp\u002F800\u002F61\u002Fr3\u002Ffinal",{"label":2882,"url":2883},"CISA StopRansomware Guide","https:\u002F\u002Fwww.cisa.gov\u002Fstopransomware\u002Fransomware-guide",{"label":2885,"url":2886},"FTC Data Breach Response: A Guide for Business","https:\u002F\u002Fwww.ftc.gov\u002Fbusiness-guidance\u002Fresources\u002Fdata-breach-response-guide-business",{"label":2888,"url":2889},"FBI Internet Crime Complaint Center: Business Email Compromise","https:\u002F\u002Fwww.ic3.gov\u002FCrimeInfo\u002FBEC",{"label":2891,"url":2892},"FBI Ransomware Guidance","https:\u002F\u002Fwww.fbi.gov\u002Fhow-we-can-help-you\u002Fscams-and-safety\u002Fcommon-frauds-and-scams\u002Fransomware","guides\u002Fsmall-business-cyber-incident-first-actions","vEw4q567qxgl7fY1queOr0AUEIYDzD_EdAYQ8dK0ghc",{"id":2896,"title":2897,"audience":2898,"author":8,"body":2899,"category":1883,"ctaDescription":3550,"ctaLabel":3551,"ctaUrl":3535,"date":1248,"description":3552,"draft":1250,"estimatedTime":3553,"extension":1252,"featured":279,"guideInputs":3554,"guideOutputs":3558,"lastReviewed":1261,"meta":3562,"navigation":279,"path":3563,"relatedResources":3564,"reviewStatus":1277,"scopeNote":3575,"seo":3576,"seoTitle":3577,"sources":3578,"stem":3593,"__hash__":3594},"guides\u002Fguides\u002Fsmall-business-security-foundations.md","Small Business Security Foundations: What to Fix First","Small-business owners, operators, and internal technology leads",{"type":10,"value":2900,"toc":3541},[2901,2905,2908,2911,2914,2934,2942,2945,2949,2952,2955,3036,3039,3042,3069,3072,3076,3079,3082,3133,3141,3144,3148,3151,3165,3168,3171,3174,3214,3217,3244,3247,3251,3254,3257,3262,3265,3268,3343,3346,3349,3376,3382,3386,3389,3484,3487,3490,3517,3521,3524,3527,3530,3538],[13,2902,2904],{"id":2903},"start-here-the-minimum-path","Start here: the minimum path",[18,2906,2907],{},"A small business does not need to boil the ocean. It needs to close the gaps that make ordinary mistakes, account compromise, fraud, and downtime much harder to manage.",[18,2909,2910],{},"This guide is deliberately non-exhaustive. It focuses on the controls that usually reduce the most risk without requiring an enterprise security department.",[18,2912,2913],{},"If you do nothing else, do these six things:",[47,2915,2916,2919,2922,2925,2928,2931],{},[50,2917,2918],{},"Name one person who owns security decisions and follow-up.",[50,2920,2921],{},"Protect email, domain, banking, payroll, cloud administration, remote access, and backup administration with unique credentials and strong multifactor authentication.",[50,2923,2924],{},"Remove former users, unknown accounts, shared administrator access, and remote tools nobody can explain.",[50,2926,2927],{},"Confirm business computers are supported, updating, encrypted where appropriate, and covered by working endpoint protection.",[50,2929,2930],{},"Restore one important file or system from backup and confirm the result is usable.",[50,2932,2933],{},"Establish a separate verification rule for payment changes and a contact sheet that works without company email.",[18,2935,2936,2937,2941],{},"Use the ",[28,2938,2940],{"href":2939},"\u002Ftools\u002Fbusiness-security-checklist","Business Security Checklist"," first if you are unsure which of these is weakest. Unknown is a valid starting answer. Write it down and assign it rather than guessing.",[18,2943,2944],{},"Do not store passwords, recovery codes, private keys, customer records, or other secrets in this guide.",[13,2946,2948],{"id":2947},"step-1-know-what-the-business-cannot-afford-to-lose","Step 1: Know what the business cannot afford to lose",[18,2950,2951],{},"Start with work, not technology. Ask what must happen for the business to bill customers, pay people, deliver its product or service, communicate, and meet important obligations.",[18,2953,2954],{},"Choose five to ten activities. For each one, name the systems, information, providers, and people it depends on. Record a realistic workaround.",[135,2956,2957,2978],{},[138,2958,2959],{},[141,2960,2961,2964,2967,2970,2973,2975],{},[144,2962,2963],{},"Critical activity",[144,2965,2966],{},"Business owner",[144,2968,2969],{},"Systems, accounts, or provider",[144,2971,2972],{},"Tolerable interruption",[144,2974,2658],{},[144,2976,2977],{},"Largest unknown",[163,2979,2980,2994,3008,3022],{},[141,2981,2982,2984,2986,2988,2990,2992],{},[168,2983],{},[168,2985],{},[168,2987],{},[168,2989],{},[168,2991],{},[168,2993],{},[141,2995,2996,2998,3000,3002,3004,3006],{},[168,2997],{},[168,2999],{},[168,3001],{},[168,3003],{},[168,3005],{},[168,3007],{},[141,3009,3010,3012,3014,3016,3018,3020],{},[168,3011],{},[168,3013],{},[168,3015],{},[168,3017],{},[168,3019],{},[168,3021],{},[141,3023,3024,3026,3028,3030,3032,3034],{},[168,3025],{},[168,3027],{},[168,3029],{},[168,3031],{},[168,3033],{},[168,3035],{},[18,3037,3038],{},"Pay attention to single points of failure. One mailbox, one laptop, one provider, or one person should not quietly control the only recovery path for a critical process.",[18,3040,3041],{},"This map is complete enough when leadership can answer:",[98,3043,3045,3051,3057,3063],{"className":3044},[271],[50,3046,3048,3050],{"className":3047},[275],[277,3049],{"disabled":279,"type":280}," What stops billing, payroll, delivery, or customer communication?",[50,3052,3054,3056],{"className":3053},[275],[277,3055],{"disabled":279,"type":280}," Who owns each critical activity?",[50,3058,3060,3062],{"className":3059},[275],[277,3061],{"disabled":279,"type":280}," Which account, device, provider, or person is a dangerous single dependency?",[50,3064,3066,3068],{"className":3065},[275],[277,3067],{"disabled":279,"type":280}," What would the business do tomorrow if the primary system were unavailable?",[18,3070,3071],{},"Do not build a perfect asset inventory before moving forward. Record the critical items first and add detail as the business can maintain it.",[13,3073,3075],{"id":3074},"step-2-protect-the-master-keys","Step 2: Protect the master keys",[18,3077,3078],{},"Some accounts can reset or influence nearly everything else. Start with email, domain registration, password management, remote access, accounting, payroll, banking, cloud administration, and backup administration.",[18,3080,3081],{},"For each critical account:",[98,3083,3085,3091,3097,3103,3109,3115,3121,3127],{"className":3084},[271],[50,3086,3088,3090],{"className":3087},[275],[277,3089],{"disabled":279,"type":280}," Name the business owner and every administrator.",[50,3092,3094,3096],{"className":3093},[275],[277,3095],{"disabled":279,"type":280}," Use a unique credential stored in an approved password manager.",[50,3098,3100,3102],{"className":3099},[275],[277,3101],{"disabled":279,"type":280}," Enable strong multifactor authentication. Prefer passkeys or security keys for the highest-consequence accounts when practical.",[50,3104,3106,3108],{"className":3105},[275],[277,3107],{"disabled":279,"type":280}," Store recovery codes outside the mailbox or device they are meant to recover.",[50,3110,3112,3114],{"className":3111},[275],[277,3113],{"disabled":279,"type":280}," Replace personal recovery addresses and old phone numbers where practical.",[50,3116,3118,3120],{"className":3117},[275],[277,3119],{"disabled":279,"type":280}," Remove former users, stale access, and unnecessary administrators.",[50,3122,3124,3126],{"className":3123},[275],[277,3125],{"disabled":279,"type":280}," Use named administrator accounts instead of shared daily administration.",[50,3128,3130,3132],{"className":3129},[275],[277,3131],{"disabled":279,"type":280}," Record how access is approved and removed for employees, contractors, bookkeepers, and providers.",[18,3134,3135,3140],{},[28,3136,3139],{"href":3137,"rel":3138},"https:\u002F\u002Fpages.nist.gov\u002F800-63-4\u002Fsp800-63b.html",[80],"NIST SP 800-63B"," supports password managers and stronger authentication. The practical priority is not forcing arbitrary password changes. It is removing reuse, shared access, weak recovery, and missing multifactor authentication.",[18,3142,3143],{},"Stop if nobody can regain control of the domain, email tenant, password manager, or backup administration without one provider or one unavailable employee. That ownership problem deserves attention before another tool purchase.",[13,3145,3147],{"id":3146},"step-3-cover-devices-and-prove-recovery","Step 3: Cover devices and prove recovery",[18,3149,3150],{},"Ask the person or provider responsible for business computers for a plain answer to four questions:",[47,3152,3153,3156,3159,3162],{},[50,3154,3155],{},"Which computers are expected to be covered?",[50,3157,3158],{},"Which are actually reporting as updated and protected?",[50,3160,3161],{},"Which are missing, unsupported, or excepted?",[50,3163,3164],{},"Who is fixing each exception?",[18,3166,3167],{},"Business laptops and other devices holding sensitive information should use supported software, automatic updates where operationally safe, screen locks, encryption where appropriate, and working endpoint protection. Remote-access tools should be approved, strongly authenticated, and removable.",[18,3169,3170],{},"Do not accept a dashboard that says everything is green without asking what is excluded and when each device last checked in.",[18,3172,3173],{},"Then test recovery. Choose one file set or application the business cannot afford to lose. Restore a representative sample to a safe location and have the business owner confirm it is usable.",[135,3175,3176,3198],{},[138,3177,3178],{},[141,3179,3180,3183,3186,3189,3192,3195],{},[144,3181,3182],{},"Item restored",[144,3184,3185],{},"Backup source",[144,3187,3188],{},"Test date",[144,3190,3191],{},"Time required",[144,3193,3194],{},"Business owner confirmed usable?",[144,3196,3197],{},"Gap and owner",[163,3199,3200],{},[141,3201,3202,3204,3206,3208,3210,3212],{},[168,3203],{},[168,3205],{},[168,3207],{},[168,3209],{},[168,3211],{},[168,3213],{},[18,3215,3216],{},"Recovery is credible enough for this baseline when:",[98,3218,3220,3226,3232,3238],{"className":3219},[271],[50,3221,3223,3225],{"className":3222},[275],[277,3224],{"disabled":279,"type":280}," The business knows what is and is not backed up.",[50,3227,3229,3231],{"className":3228},[275],[277,3230],{"disabled":279,"type":280}," Backup administration is protected from ordinary account compromise or deletion where practical.",[50,3233,3235,3237],{"className":3234},[275],[277,3236],{"disabled":279,"type":280}," A representative restore was completed.",[50,3239,3241,3243],{"className":3240},[275],[277,3242],{"disabled":279,"type":280}," Failed instructions or missing data have an owner and date.",[18,3245,3246],{},"Synchronization and version history may help. Neither automatically replaces a tested backup.",[13,3248,3250],{"id":3249},"step-4-put-fraud-and-incident-basics-on-one-page","Step 4: Put fraud and incident basics on one page",[18,3252,3253],{},"The business needs a way to react before it needs a full incident plan.",[18,3255,3256],{},"Write one rule for changed bank details, payroll changes, new payees, wire instructions, and urgent executive requests:",[1330,3258,3259],{},[18,3260,3261],{},"Verify the change through a known second channel. Do not use a phone number, email address, or link supplied only in the change request.",[18,3263,3264],{},"Make sure finance and payroll staff can repeat that rule without opening this guide.",[18,3266,3267],{},"Then record the contacts and authority needed during a serious problem:",[135,3269,3270,3286],{},[138,3271,3272],{},[141,3273,3274,3277,3280,3283],{},[144,3275,3276],{},"Need",[144,3278,3279],{},"Primary person or organization",[144,3281,3282],{},"Backup",[144,3284,3285],{},"Trusted contact method outside company email",[163,3287,3288,3299,3310,3321,3332],{},[141,3289,3290,3293,3295,3297],{},[168,3291,3292],{},"Leadership decision",[168,3294],{},[168,3296],{},[168,3298],{},[141,3300,3301,3304,3306,3308],{},[168,3302,3303],{},"Technology or response help",[168,3305],{},[168,3307],{},[168,3309],{},[141,3311,3312,3315,3317,3319],{},[168,3313,3314],{},"Bank or payment fraud",[168,3316],{},[168,3318],{},[168,3320],{},[141,3322,3323,3326,3328,3330],{},[168,3324,3325],{},"Cyber insurer or broker, if applicable",[168,3327],{},[168,3329],{},[168,3331],{},[141,3333,3334,3337,3339,3341],{},[168,3335,3336],{},"Legal guidance, if needed",[168,3338],{},[168,3340],{},[168,3342],{},[18,3344,3345],{},"Run one 20-minute scenario: an owner mailbox takeover, fraudulent payment request, unavailable shared files, lost laptop, malware alert, or provider incident. Ask who notices, who decides, what gets isolated, how work continues, and who must be called.",[18,3347,3348],{},"This step is complete enough when:",[98,3350,3352,3358,3364,3370],{"className":3351},[271],[50,3353,3355,3357],{"className":3354},[275],[277,3356],{"disabled":279,"type":280}," The payment-change rule is understood by the people who can move money.",[50,3359,3361,3363],{"className":3360},[275],[277,3362],{"disabled":279,"type":280}," The contact sheet is available without company email.",[50,3365,3367,3369],{"className":3366},[275],[277,3368],{"disabled":279,"type":280}," Leadership and technical decision authority are clear.",[50,3371,3373,3375],{"className":3372},[275],[277,3374],{"disabled":279,"type":280}," One realistic scenario exposed at least one assumption or gap.",[18,3377,3378,3379,3381],{},"Use ",[28,3380,1862],{"href":1861}," for the live first-hour path and preparation details. Do not duplicate that response plan inside this baseline.",[13,3383,3385],{"id":3384},"step-5-choose-five-actions-not-fifty","Step 5: Choose five actions, not fifty",[18,3387,3388],{},"Review the unknowns and failures from the first four steps. Choose no more than five actions for the next 30 days. Put lower-consequence work into 60- or 90-day targets only when it still deserves attention.",[135,3390,3391,3412],{},[138,3392,3393],{},[141,3394,3395,3398,3401,3403,3406,3409],{},[144,3396,3397],{},"Priority action",[144,3399,3400],{},"Business reason",[144,3402,161],{},[144,3404,3405],{},"Target date",[144,3407,3408],{},"Evidence that closes it",[144,3410,3411],{},"30, 60, or 90 days",[163,3413,3414,3428,3442,3456,3470],{},[141,3415,3416,3418,3420,3422,3424,3426],{},[168,3417],{},[168,3419],{},[168,3421],{},[168,3423],{},[168,3425],{},[168,3427],{},[141,3429,3430,3432,3434,3436,3438,3440],{},[168,3431],{},[168,3433],{},[168,3435],{},[168,3437],{},[168,3439],{},[168,3441],{},[141,3443,3444,3446,3448,3450,3452,3454],{},[168,3445],{},[168,3447],{},[168,3449],{},[168,3451],{},[168,3453],{},[168,3455],{},[141,3457,3458,3460,3462,3464,3466,3468],{},[168,3459],{},[168,3461],{},[168,3463],{},[168,3465],{},[168,3467],{},[168,3469],{},[141,3471,3472,3474,3476,3478,3480,3482],{},[168,3473],{},[168,3475],{},[168,3477],{},[168,3479],{},[168,3481],{},[168,3483],{},[18,3485,3486],{},"A useful action is specific enough to finish. \"Improve security\" is not an action. \"Enable multifactor authentication on the payroll administrator account and store its recovery codes in the approved location by Friday\" is.",[18,3488,3489],{},"The plan is ready when:",[98,3491,3493,3499,3505,3511],{"className":3492},[271],[50,3494,3496,3498],{"className":3495},[275],[277,3497],{"disabled":279,"type":280}," Every immediate action has one owner and date.",[50,3500,3502,3504],{"className":3501},[275],[277,3503],{"disabled":279,"type":280}," Leadership approved the order of work.",[50,3506,3508,3510],{"className":3507},[275],[277,3509],{"disabled":279,"type":280}," Deferred risks include a reason and review date.",[50,3512,3514,3516],{"className":3513},[275],[277,3515],{"disabled":279,"type":280}," The next check-up is scheduled.",[13,3518,3520],{"id":3519},"keep-the-work-alive","Keep the work alive",[18,3522,3523],{},"A short monthly review is useful when the business can support it. Ask what changed, which open risk matters most, whether important backups and alerts still work, and what evidence shows the agreed work was completed.",[18,3525,3526],{},"If a monthly review is unrealistic, get a professional cybersecurity check-up at least once a year. Treat it like an annual health visit for the business. Review what changed, test the assumptions that matter, catch problems that are easy to miss internally, and leave with a prioritized plan.",[18,3528,3529],{},"Also schedule a check-up after a major provider change, rapid growth, acquisition, serious incident, new regulated or contract-sensitive work, or a material cyber-insurance change.",[18,3531,3532,3533,3537],{},"Trawvid Sec's ",[28,3534,3536],{"href":3535},"\u002Fsmall-business-cyber-resilience","Cyber Health Check"," is built for that practical minimum. It produces five priorities and a 30-, 60-, and 90-day plan without turning the review into an enterprise assessment.",[18,3539,3540],{},"If this guide exposes unclear ownership, missing records, or work that nobody can confidently prioritize, use the email and booking options on this page. Bring the unknowns and the business constraints. Do not send passwords, recovery codes, or sensitive customer information.",{"title":1214,"searchDepth":1215,"depth":1215,"links":3542},[3543,3544,3545,3546,3547,3548,3549],{"id":2903,"depth":1215,"text":2904},{"id":2947,"depth":1215,"text":2948},{"id":3074,"depth":1215,"text":3075},{"id":3146,"depth":1215,"text":3147},{"id":3249,"depth":1215,"text":3250},{"id":3384,"depth":1215,"text":3385},{"id":3519,"depth":1215,"text":3520},"If ownership is unclear, priorities are disputed, or the work keeps stalling, use a focused review to identify five practical next actions.","Schedule a Cyber Health Check","A practical, printable guide to the small-business security basics that usually deserve attention first, with a short baseline and a focused 30-, 60-, and 90-day plan.","Allow about 30 minutes for the first pass. Complete the highest-value changes over the next 30 days instead of trying to fix everything in one sitting.",[3555,3556,3557],"A business owner who can assign work and approve priorities.","The people or providers who manage email, devices, cloud services, backups, banking, payroll, and customer systems.","Current customer, contract, insurance, or regulatory requirements that may change the order of work.",[3559,3560,3561],"A short map of the activities and technology the business cannot afford to lose.","Verified account, device, recovery, payment, and incident basics.","No more than five prioritized actions with owners and dates.",{},"\u002Fguides\u002Fsmall-business-security-foundations",[3565,3567,3569,3571],{"label":2940,"url":2939,"description":3566},"Use the private guided assessment to identify the areas that deserve attention before working through this guide.",{"label":1862,"url":1861,"description":3568},"Build the first-hour response path without expanding this foundations guide into a full incident-response manual.",{"label":3536,"url":3535,"description":3570},"Turn unclear findings into five practical priorities and a 30-, 60-, and 90-day plan.",{"label":3572,"url":3573,"description":3574},"Security Program Development","\u002Fservices\u002Fsecurity-program-development","Build durable ownership, documentation, and operating routines when the business needs more than a baseline.","This is a non-exhaustive guide to the security basics most likely to matter for a small business. It is not a complete risk assessment, legal or compliance opinion, managed IT service, incident-response engagement, or guarantee that an incident cannot occur. Customer commitments, contracts, insurance terms, regulations, safety concerns, and active incidents may require different or additional work.",{"title":2897,"description":3552},"Small Business Cybersecurity Guide: What to Fix First",[3579,3582,3585,3587,3590],{"label":3580,"url":3581},"NIST Cybersecurity Framework 2.0 for Small Business","https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fsmallbusinesscyber\u002Fnist-cybersecurity-framework-0",{"label":3583,"url":3584},"NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide","https:\u002F\u002Ftsapps.nist.gov\u002Fpublication\u002Fget_pdf.cfm?pub_id=957322",{"label":3586,"url":3137},"NIST SP 800-63B: Authentication and Authenticator Management",{"label":3588,"url":3589},"CISA Small and Medium-Sized Business Resources","https:\u002F\u002Fwww.cisa.gov\u002Fsmall-and-medium-sized-business-resources",{"label":3591,"url":3592},"FTC Cybersecurity for Small Business","https:\u002F\u002Fwww.ftc.gov\u002Fbusiness-guidance\u002Fsmall-businesses\u002Fcybersecurity","guides\u002Fsmall-business-security-foundations","fSw5-0eY7plnrZEZiyCg6i9f7BQg2ik788EYIp3o-k8",{"id":3596,"title":3597,"audience":3598,"author":8,"body":3599,"category":1883,"ctaDescription":4189,"ctaLabel":4190,"ctaUrl":1662,"date":1248,"description":4191,"draft":1250,"estimatedTime":4192,"extension":1252,"featured":1250,"guideInputs":4193,"guideOutputs":4197,"lastReviewed":1261,"meta":4201,"navigation":279,"path":4202,"relatedResources":4203,"reviewStatus":1277,"scopeNote":4214,"seo":4215,"seoTitle":3597,"sources":4216,"stem":4231,"__hash__":4232},"guides\u002Fguides\u002Fsmall-business-vendor-it-provider-security.md","Small Business Vendor and IT Provider Security Guide","Small-business owners, operators, finance leaders, and internal technology leads",{"type":10,"value":3600,"toc":4170},[3601,3605,3608,3611,3614,3617,3621,3624,3657,3660,3664,3667,3705,3708,3728,3731,3735,3738,3742,3745,3748,3752,3755,3758,3762,3765,3768,3772,3775,3782,3786,3789,3794,3798,3801,3804,3808,3811,3815,3818,3821,3824,3951,3954,3958,3961,4024,4027,4031,4034,4066,4104,4107,4134,4138,4141,4144,4147,4164,4167],[13,3602,3604],{"id":3603},"start-with-the-decision","Start with the decision",[18,3606,3607],{},"Most small businesses depend on outside providers. That is not a failure. The question is whether the business understands the dependency well enough to make a reasonable decision.",[18,3609,3610],{},"This guide is intentionally limited. It covers the few provider questions that most often change a purchase or renewal decision. It does not try to turn a business owner into a procurement department, auditor, privacy attorney, or security architect.",[18,3612,3613],{},"Use it when a provider can administer systems, hold important information, move money, reset accounts, or interrupt work. If the provider cannot do any of those things, record who owns the relationship and move on.",[18,3615,3616],{},"Do not put passwords, recovery codes, bank details, customer records, or confidential provider evidence into this guide. Record where protected material is stored instead.",[42,3618,3620],{"id":3619},"five-minute-triage","Five-minute triage",[18,3622,3623],{},"Continue with the full guide when any answer is yes:",[98,3625,3627,3633,3639,3645,3651],{"className":3626},[271],[50,3628,3630,3632],{"className":3629},[275],[277,3631],{"disabled":279,"type":280}," The provider can administer business accounts, computers, networks, cloud services, websites, or production systems.",[50,3634,3636,3638],{"className":3635},[275],[277,3637],{"disabled":279,"type":280}," The provider stores or can view sensitive employee, customer, financial, legal, regulated, or business information.",[50,3640,3642,3644],{"className":3641},[275],[277,3643],{"disabled":279,"type":280}," The provider can create users, reset accounts, change payment details, or influence account recovery.",[50,3646,3648,3650],{"className":3647},[275],[277,3649],{"disabled":279,"type":280}," A prolonged outage could stop billing, payroll, customer delivery, production, or another important activity.",[50,3652,3654,3656],{"className":3653},[275],[277,3655],{"disabled":279,"type":280}," Replacing the provider would require data export, system transition, credential changes, or urgent outside help.",[18,3658,3659],{},"If every answer is no, keep a simple record of the service, business owner, renewal date, and reason it is considered routine. Revisit that decision if the provider's access, information, integration, or business importance changes.",[13,3661,3663],{"id":3662},"step-1-write-down-the-relationship","Step 1: Write down the relationship",[18,3665,3666],{},"A recognizable brand and polished security page do not explain the relationship. Start with what the provider does in your environment.",[135,3668,3669,3689],{},[138,3670,3671],{},[141,3672,3673,3676,3678,3681,3684,3687],{},[144,3674,3675],{},"Provider and service",[144,3677,2966],{},[144,3679,3680],{},"Access, information, or money involved",[144,3682,3683],{},"What stops if unavailable",[144,3685,3686],{},"Renewal or notice date",[144,3688,1120],{},[163,3690,3691],{},[141,3692,3693,3695,3697,3699,3701,3703],{},[168,3694],{},[168,3696],{},[168,3698],{},[168,3700],{},[168,3702],{},[168,3704],{},[18,3706,3707],{},"Use three practical priorities:",[98,3709,3710,3716,3722],{},[50,3711,3712,3715],{},[265,3713,3714],{},"Routine:"," Limited access, limited information, and limited interruption. Keep the basic record.",[50,3717,3718,3721],{},[265,3719,3720],{},"Important:"," Meaningful access or business dependency exists, but a workable alternative or manual process is available. Complete the eight questions.",[50,3723,3724,3727],{},[265,3725,3726],{},"Critical:"," The provider has broad administration, important information, financial authority, account-recovery power, or control over a process the business cannot readily replace. Complete the questions and consider a deeper review before signing or renewing.",[18,3729,3730],{},"Do not lower the priority because the provider is large or familiar. Consequence comes from what the provider can reach and what the business depends on.",[13,3732,3734],{"id":3733},"step-2-get-eight-useful-answers","Step 2: Get eight useful answers",[18,3736,3737],{},"You do not need a 200-question survey. You need answers that expose blind dependence.",[42,3739,3741],{"id":3740},"_1-what-can-the-provider-actually-access","1. What can the provider actually access?",[18,3743,3744],{},"Ask which accounts, systems, devices, folders, networks, integrations, and support tools the provider can reach. Confirm whether technicians use named accounts and strong multifactor authentication for administrative or remote access.",[18,3746,3747],{},"A vague answer such as \"our team handles everything\" is not enough. The business should know where powerful access exists and how it is removed when a provider employee leaves.",[42,3749,3751],{"id":3750},"_2-what-does-the-business-still-own-and-control","2. What does the business still own and control?",[18,3753,3754],{},"The business should retain appropriate control of foundational assets such as its domain, email or identity tenant, billing relationship, critical licenses, and recovery path. An outside provider may administer them, but that is different from owning them.",[18,3756,3757],{},"Ask whether the business can regain control if the usual provider contact is unavailable.",[42,3759,3761],{"id":3760},"_3-what-information-crosses-the-provider-boundary","3. What information crosses the provider boundary?",[18,3763,3764],{},"Name the important categories. Ask where the information is stored, whether provider staff can view it, whether subprocessors or integrations receive it, and what happens to it after cancellation.",[18,3766,3767],{},"Do not attempt a full privacy audit here. If regulated, privileged, or unusually sensitive information is involved, mark that as a reason for qualified review.",[42,3769,3771],{"id":3770},"_4-what-is-backed-up-and-has-recovery-been-tested","4. What is backed up, and has recovery been tested?",[18,3773,3774],{},"Ask what is actually backed up, how long copies are kept, who can delete them, and when a useful restoration was last tested. Synchronization, version history, service availability, and backup are not automatically the same thing.",[18,3776,3777,3778,3781],{},"The broader recovery program belongs in the ",[28,3779,3780],{"href":2868},"Small Business Security Foundations guide",". For this decision, confirm the provider's part of the handoff.",[42,3783,3785],{"id":3784},"_5-what-happens-when-something-goes-wrong","5. What happens when something goes wrong?",[18,3787,3788],{},"Get an incident contact that is better than a general sales inbox. Ask what events trigger customer notice, how the provider will reach the business if email is unavailable, what initial facts it can provide, and what the customer must do.",[18,3790,3791,3792,2319],{},"The provider does not need to promise that incidents cannot happen. It needs a usable communication and responsibility path. Build the business-wide response plan in ",[28,3793,1862],{"href":1861},[42,3795,3797],{"id":3796},"_6-who-owns-the-daily-security-work","6. Who owns the daily security work?",[18,3799,3800],{},"Clarify the few handoffs that matter for this service: approving users, removing access, applying important updates, reviewing alerts, checking backup failures, and escalating suspicious activity.",[18,3802,3803],{},"If the provider says a task is the customer's responsibility, assign it to a real person. \"The customer owns it\" is not a control until somebody knows they are expected to act.",[42,3805,3807],{"id":3806},"_7-can-the-business-leave-without-losing-control","7. Can the business leave without losing control?",[18,3809,3810],{},"Ask how the business exports its data and important configurations, removes provider access, transfers licenses, and confirms retention or deletion. A workable exit does not need to be painless, but it should exist before the relationship is under pressure.",[42,3812,3814],{"id":3813},"_8-what-supports-the-important-answers","8. What supports the important answers?",[18,3816,3817],{},"Ask for evidence that matches the consequence. That may be a relevant independent report, current security summary, configuration screen, backup or restore result, written procedure, insurance evidence, demonstration, or customer reference.",[18,3819,3820],{},"A certification logo can be useful context. It does not prove that the purchased service, product tier, configuration, or customer responsibilities were covered. A small local provider may not have a formal audit and may still give direct, credible answers with practical evidence.",[18,3822,3823],{},"Use one page to record the result:",[135,3825,3826,3845],{},[138,3827,3828],{},[141,3829,3830,3833,3836,3839,3842],{},[144,3831,3832],{},"Question",[144,3834,3835],{},"Answer or unknown",[144,3837,3838],{},"Evidence or explanation",[144,3840,3841],{},"Follow-up owner",[144,3843,3844],{},"Needed before signing?",[163,3846,3847,3860,3873,3886,3899,3912,3925,3938],{},[141,3848,3849,3852,3854,3856,3858],{},[168,3850,3851],{},"Access and authentication",[168,3853],{},[168,3855],{},[168,3857],{},[168,3859],{},[141,3861,3862,3865,3867,3869,3871],{},[168,3863,3864],{},"Business ownership and recovery",[168,3866],{},[168,3868],{},[168,3870],{},[168,3872],{},[141,3874,3875,3878,3880,3882,3884],{},[168,3876,3877],{},"Information and subprocessors",[168,3879],{},[168,3881],{},[168,3883],{},[168,3885],{},[141,3887,3888,3891,3893,3895,3897],{},[168,3889,3890],{},"Backup and restoration",[168,3892],{},[168,3894],{},[168,3896],{},[168,3898],{},[141,3900,3901,3904,3906,3908,3910],{},[168,3902,3903],{},"Incident communication",[168,3905],{},[168,3907],{},[168,3909],{},[168,3911],{},[141,3913,3914,3917,3919,3921,3923],{},[168,3915,3916],{},"Daily security responsibilities",[168,3918],{},[168,3920],{},[168,3922],{},[168,3924],{},[141,3926,3927,3930,3932,3934,3936],{},[168,3928,3929],{},"Exit and data return",[168,3931],{},[168,3933],{},[168,3935],{},[168,3937],{},[141,3939,3940,3943,3945,3947,3949],{},[168,3941,3942],{},"Evidence for important claims",[168,3944],{},[168,3946],{},[168,3948],{},[168,3950],{},[18,3952,3953],{},"Unknown is an acceptable answer while the review is open. It is not the same as yes.",[13,3955,3957],{"id":3956},"step-3-look-for-the-red-flags","Step 3: Look for the red flags",[18,3959,3960],{},"Pause before signing or renewing when one or more of these conditions cannot be resolved:",[98,3962,3964,3970,3976,3982,3988,3994,4000,4006,4012,4018],{"className":3963},[271],[50,3965,3967,3969],{"className":3966},[275],[277,3968],{"disabled":279,"type":280}," Nobody at the business owns the relationship.",[50,3971,3973,3975],{"className":3972},[275],[277,3974],{"disabled":279,"type":280}," The provider cannot explain its administrative or remote-access paths.",[50,3977,3979,3981],{"className":3978},[275],[277,3980],{"disabled":279,"type":280}," Powerful access depends on shared credentials or lacks strong multifactor authentication.",[50,3983,3985,3987],{"className":3984},[275],[277,3986],{"disabled":279,"type":280}," The provider alone controls the domain, tenant, billing account, or recovery path.",[50,3989,3991,3993],{"className":3990},[275],[277,3992],{"disabled":279,"type":280}," Important information, retention, staff access, or deletion cannot be explained.",[50,3995,3997,3999],{"className":3996},[275],[277,3998],{"disabled":279,"type":280}," Backup is assumed, but nobody can name what is covered or when restoration was last tested.",[50,4001,4003,4005],{"className":4002},[275],[277,4004],{"disabled":279,"type":280}," Incident notification depends only on ordinary support or the same email that may be affected.",[50,4007,4009,4011],{"className":4008},[275],[277,4010],{"disabled":279,"type":280}," Important provider and customer responsibilities are both described as belonging to the other party.",[50,4013,4015,4017],{"className":4014},[275],[277,4016],{"disabled":279,"type":280}," The business cannot export essential data or remove provider access through a planned transition.",[50,4019,4021,4023],{"className":4020},[275],[277,4022],{"disabled":279,"type":280}," Marketing claims replace answers about the actual service being purchased.",[18,4025,4026],{},"One red flag does not always mean reject the provider. It means the business should resolve, condition, compensate for, or consciously accept the issue rather than letting it disappear into the contract.",[13,4028,4030],{"id":4029},"step-4-record-the-decision","Step 4: Record the decision",[18,4032,4033],{},"Choose the smallest decision that accurately describes the result:",[98,4035,4036,4042,4048,4054,4060],{},[50,4037,4038,4041],{},[265,4039,4040],{},"Proceed:"," The important answers are clear enough for the consequence.",[50,4043,4044,4047],{},[265,4045,4046],{},"Proceed with conditions:"," The provider is usable, but specific changes, answers, or contract terms must be completed.",[50,4049,4050,4053],{},[265,4051,4052],{},"Pause:"," A material unknown needs an answer before the business commits.",[50,4055,4056,4059],{},[265,4057,4058],{},"Get a deeper review:"," Broad administration, sensitive information, complex integrations, financial authority, difficult recovery, or unclear legal obligations exceed a short self-guided review.",[50,4061,4062,4065],{},[265,4063,4064],{},"Replace or redesign:"," The business cannot reduce a material access, ownership, recovery, or trust problem to an acceptable level.",[135,4067,4068,4088],{},[138,4069,4070],{},[141,4071,4072,4075,4077,4080,4082,4085],{},[144,4073,4074],{},"Provider",[144,4076,868],{},[144,4078,4079],{},"Conditions or open questions",[144,4081,161],{},[144,4083,4084],{},"Due date",[144,4086,4087],{},"Next review or trigger",[163,4089,4090],{},[141,4091,4092,4094,4096,4098,4100,4102],{},[168,4093],{},[168,4095],{},[168,4097],{},[168,4099],{},[168,4101],{},[168,4103],{},[18,4105,4106],{},"Complete the review when:",[98,4108,4110,4116,4122,4128],{"className":4109},[271],[50,4111,4113,4115],{"className":4112},[275],[277,4114],{"disabled":279,"type":280}," The business owner understands what the provider can reach and what depends on it.",[50,4117,4119,4121],{"className":4118},[275],[277,4120],{"disabled":279,"type":280}," Material unknowns are resolved, assigned, or included as conditions.",[50,4123,4125,4127],{"className":4124},[275],[277,4126],{"disabled":279,"type":280}," The provider and customer handoffs are clear enough to operate.",[50,4129,4131,4133],{"className":4130},[275],[277,4132],{"disabled":279,"type":280}," The decision and next review trigger are recorded.",[13,4135,4137],{"id":4136},"keep-the-review-proportional","Keep the review proportional",[18,4139,4140],{},"Do not recreate the whole security program inside every provider review.",[18,4142,4143],{},"Use the foundations guide for business-wide account, device, backup, alert, and ownership work. Use the incident guide for the overall response plan. Use a focused architecture or legal review when the technical or contractual boundary truly warrants it.",[18,4145,4146],{},"For an existing provider, the core conversation can fit into 20 minutes:",[47,4148,4149,4152,4155,4158,4161],{},[50,4150,4151],{},"Confirm the service owner, access, information, and operational importance.",[50,4153,4154],{},"Walk through the eight questions and mark unknowns.",[50,4156,4157],{},"Identify the largest realistic consequence.",[50,4159,4160],{},"Decide what must change before renewal and who owns it.",[50,4162,4163],{},"Record the next trigger: renewal, access change, major integration, incident, outage, ownership change, or material service change.",[18,4165,4166],{},"A short review cannot prove that a provider will never fail. It can keep the business from signing a contract while nobody understands the access, dependency, recovery path, or way out.",[18,4168,4169],{},"If the answers remain technical, disputed, or difficult to validate, use the email and booking options on this page. Bring the proposal and the unanswered questions, not passwords or sensitive records.",{"title":1214,"searchDepth":1215,"depth":1215,"links":4171},[4172,4175,4176,4186,4187,4188],{"id":3603,"depth":1215,"text":3604,"children":4173},[4174],{"id":3619,"depth":1220,"text":3620},{"id":3662,"depth":1215,"text":3663},{"id":3733,"depth":1215,"text":3734,"children":4177},[4178,4179,4180,4181,4182,4183,4184,4185],{"id":3740,"depth":1220,"text":3741},{"id":3750,"depth":1220,"text":3751},{"id":3760,"depth":1220,"text":3761},{"id":3770,"depth":1220,"text":3771},{"id":3784,"depth":1220,"text":3785},{"id":3796,"depth":1220,"text":3797},{"id":3806,"depth":1220,"text":3807},{"id":3813,"depth":1220,"text":3814},{"id":3956,"depth":1215,"text":3957},{"id":4029,"depth":1215,"text":4030},{"id":4136,"depth":1215,"text":4137},"If a provider has broad access, holds critical data, or sits inside a process the business cannot afford to lose, test the assumptions before the contract becomes difficult to change.","Discuss a provider decision","A short, printable guide for checking the access, data, recovery, incident, and exit questions that matter before signing or renewing a provider.","Allow 15 to 25 minutes for the core review. Pause for a deeper technical or contract review when a provider has broad administration, sensitive data, payment authority, or critical operational responsibility.",[4194,4195,4196],"The proposal or contract, the service owner, and the provider contact who can answer operational questions.","A plain-language understanding of what the provider can access, what information it holds, and what stops if the service fails.","Any available security summary, backup report, incident terms, or exit instructions that relate to the service being purchased.",[4198,4199,4200],"A short provider snapshot and eight important answers.","A proceed, proceed with conditions, pause, or deeper-review decision.","Named follow-up actions and a review trigger.",{},"\u002Fguides\u002Fsmall-business-vendor-it-provider-security",[4204,4206,4208,4210],{"label":2867,"url":2868,"description":4205},"Handle the business-wide ownership, account, device, backup, and response basics outside this provider decision.",{"label":1862,"url":1861,"description":4207},"Prepare the broader response process instead of rebuilding it inside every provider review.",{"label":1663,"url":1662,"description":4209},"Use a focused review when a provider, integration, cloud design, or remote-access path needs technical validation.",{"label":4211,"url":4212,"description":4213},"vCISO Advisory","\u002Fservices\u002Fvciso-advisory","Build a repeatable vendor-review process when these decisions have become recurring work.","This is a non-exhaustive guide to the issues most likely to matter in an ordinary small-business provider decision. It is not a complete vendor-risk assessment, legal or contract review, procurement approval, managed IT service, or guarantee that a provider will prevent an incident. Providers with broad administration, regulated or highly sensitive information, payment authority, or critical operational dependencies may warrant qualified legal and technical review.",{"title":3597,"description":4191},[4217,4220,4223,4226,4228],{"label":4218,"url":4219},"NIST SP 1305: Cybersecurity Framework 2.0 Quick-Start Guide for Cybersecurity Supply Chain Risk Management","https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Fsp\u002F1305\u002Ffinal",{"label":4221,"url":4222},"NIST Cybersecurity Framework 2.0","https:\u002F\u002Fwww.nist.gov\u002Fcyberframework",{"label":4224,"url":4225},"CISA: Protecting Against Cyber Threats to Managed Service Providers and Their Customers","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fnews\u002Fcisa-nsa-fbi-and-international-cyber-authorities-issue-cybersecurity-advisory-protect-managed",{"label":4227,"url":3592},"FTC Cybersecurity for Small Business: Vendor Security",{"label":4229,"url":4230},"FTC Start with Security: A Guide for Business","https:\u002F\u002Fwww.ftc.gov\u002Fbusiness-guidance\u002Fresources\u002Fstart-security-guide-business","guides\u002Fsmall-business-vendor-it-provider-security","EkOVqpZ6OjDlsljNFBizsomI1kIOr3bqCSOMDhCv9Sk",1785969847016]