Ransomware Recovery Plan: Test Backups Before an Attack
Direct answer: A backup is not a ransomware recovery capability until you can restore the right data and systems within business objectives without reintroducing the attacker. Keep protected and appropriately…
Google Workspace Security Baseline for Small Organizations
Direct answer: A small-organization Google Workspace baseline begins with resilient administration and enforced 2-Step Verification, then controls Gmail threats, Drive sharing, third-party apps, devices, alerts, and recovery. Maintain more than…
Microsoft 365 Security Baseline for Small Organizations
Direct answer: A small-organization Microsoft 365 baseline should protect identities first, then reduce risky email, application, sharing, device, and administrative paths. Use Security Defaults when it fits a simple tenant;…
Smishing, Vishing, and Mobile Phishing Response Guide
Direct answer: Treat an unexpected text, call, QR code, or authentication prompt as untrusted until independently verified. Do not use the contact details, link, or instructions in the message. Pause…
Shadow AI Policy Template: Control AI Without Blocking Work
Direct answer: A shadow AI policy should make safe work easier than secret work. Publish a short list of approved services and use cases, define data that must never be…
Software Supply Chain Security and SBOM Buyer Guide
Direct answer: An SBOM is an inventory artifact, not proof that software is secure. A buyer should use it to identify components, versions, suppliers, and dependency relationships, then connect that…
Third-Party Cyber Risk Checklist for Small Businesses
Direct answer: A useful third-party cyber risk review is proportional to what the vendor can access, change, store, or interrupt. Inventory vendors, map each one to business services and data,…
CISA KEV Patch Playbook: Alert to Verified Remediation
Direct answer: A CISA KEV alert should trigger a controlled response, not an automatic production change. Confirm that the affected product and version are present, identify exposure and business importance,…
Vulnerability Prioritization: CVSS vs EPSS vs CISA KEV
Direct answer: CVSS, EPSS, and CISA KEV answer different questions. CVSS describes technical severity. EPSS estimates the probability of observed exploitation activity for a published CVE in the next 30…
NIST CSF 2.0 for Small Businesses: A 90-Day Roadmap
Direct answer: A small business can adopt NIST CSF 2.0 without building an enterprise compliance program. Use the framework as a decision system: define what matters, assign accountable owners, choose…
