Start here
- Each item is a five-minute start or check, not a promise that a business-wide control can be finished in five minutes.
- Begin with email and finance access, backups and payment verification.
- Write down what is missing and assign the fuller rollout to an owner.
Last updated: September 24, 2026
You can make a useful security decision in five minutes. You usually cannot enroll every employee in MFA, patch every device or prove every backup works in that time. This list separates the first action from the completion test, so a quick win does not become false assurance. It follows the practical direction in CISA's Secure Our World material and NIST's SMB quick start.
| Five-minute start | What proves completion later |
|---|---|
| Open the email admin console and check whether your own administrator account has MFA | Export enrollment and exception status for every privileged account |
| Look up the last successful backup of your most important data | Restore a file or service to a safe location and verify usability |
| Ask finance how a bank-detail change is approved | Put a known-number callback and second approver into the actual workflow |
| List the people with admin rights to a key app | Remove stale rights and test one leaver's access |
| Check whether a company laptop has updates and disk encryption enabled | Compare policy and compliance across the full device inventory |
| Review one suspicious email reporting path | Staff know where to report; the mailbox or ticket reaches a named responder |
| Find the emergency IT and bank contact numbers | Keep an offline copy and test the contacts in an exercise |
For a suspected active attack, follow the incident-response plan or the ransomware first-response page. Do not spend five minutes changing settings on an affected machine without coordinating containment and evidence preservation.
Three actions to do this week
Protect the accounts that can move money or change access. Assign an identity owner to check MFA for email, administrators, finance and remote access. Choose phishing-resistant methods where practical, and keep recovery under business control. A single enrolled administrator does not prove coverage.
Prove a restore. The backup owner selects one important file or workload, restores it outside production and records whether the business can use it. A green backup dashboard is a useful signal, but it is not a recovery test. See the backup guide.
Close the email-only payment path. Finance uses a number already held in supplier records to confirm any new bank account. The request email cannot supply the callback number. Keep a second approval for material transfers; the BEC guide gives an example workflow.
Turn quick starts into a plan
Make a three-column list: missing control, owner, verification date. Handle an unknown result as an investigation. Use the security checklist to track evidence and the 90-day roadmap to sequence larger changes. If you are unsure where to begin, the assessment creates a local planning report without requiring an account.
No purchase required for these starts
Check capabilities in your current email, device and backup subscriptions first. A new tool is useful only if it fills a specific gap and someone can operate it.
Sources checked September 24, 2026: CISA Secure Our World resources, NIST SP 1300, and FTC small-business cybersecurity guidance. Timing and task selection are editorial advice, not measured risk reduction.