The operating rhythm
- Every week: Review failed backups, overdue critical updates, security alerts and urgent access changes.
- Every month: Review MFA exceptions, third-party accounts, mail sender changes and one recovery question.
- Every quarter: Practice an incident decision, test a restore and review business priorities.
- Every check: Record an owner, evidence, exception and next date.
Last updated: September 24, 2026
Advice such as “use MFA” helps only when someone knows who is enrolled, who is excepted and what happens when enrollment fails. NIST's CSF 2.0 small-business guide gives a risk-management structure; the cadence below is a practical Valydex interpretation for lean teams. Adjust it to your actual systems, contract terms and support hours.
The weekly review
The operations or IT owner checks four queues: failed or missing backups, critical update exceptions, high-priority security alerts and user/contractor access changes. Record the affected system, owner and next step. Escalate an alert no one can interpret to your IT support or incident responder; leaving a dashboard unattended is not monitoring. Give finance a separate channel to report suspicious payment or invoice changes, and confirm with a known number before any transfer.
| Signal | Question to ask | Action if the answer is unclear |
|---|---|---|
| Backup failure | Is the critical workload covered and restorable? | Assign a restore test or correct scope |
| Update exception | Is a supported device exposed or just awaiting restart? | Name the device owner and deadline |
| Security alert | Who investigated and decided it was safe? | Escalate to the incident contact |
| Access change | Does a leaver or vendor still have a route in? | Revoke and verify across connected apps |
The monthly review
Sample privileged and finance accounts for MFA and recovery settings. Compare active accounts with staff and contractor records. Check whether a new marketing, billing or support service sends mail from your domain; each sender belongs in the SPF/DKIM/DMARC inventory. Review recurring payment verification exceptions and the status of one restore. A supplier invoice or product subscription is not evidence that the control is configured. Use the security checklist as the control register.
The quarterly review
The business owner and technical owner walk through one scenario: a stolen administrator account, fraudulent bank change or unavailable file server. Confirm who can isolate systems, contact the bank, preserve records and authorize communications. Run a restore test that resembles real work. Update the incident runbook and 90-day roadmap when responsibilities or systems change.
When the team is too small for a formal meeting
Make a short shared log with date, control, result, owner and next date. The same person may hold several roles, but record a backup decision-maker. If outsourced IT performs the check, agree on the evidence and escalation path. Fund or accept an exception explicitly; do not let it disappear because the next review was busy.
Where to start
If there is no register, start with the free assessment, then verify its findings against your live systems. Assign the top three actions rather than opening a shopping list.
Sources checked September 24, 2026: NIST SP 1300, FTC small-business cybersecurity guidance, and CISA SMB resources. Review frequencies are editorial suggestions, not guaranteed outcomes.