Guided checklist

Find the next practical security fixes without guessing.

Walk through plain-language readiness questions, mark what is done or uncertain, and download a filled PDF your team can use as a short action plan.

Start guided checklist Get help prioritizing gaps
Guided checklist

Check your readiness without needing security jargon.

For each area, choose the closest status. If you are not sure, choose Not sure. That answer is useful because it shows what to verify next.

Identity and access

These questions ask whether people log in safely and whether old or unnecessary access is removed.

Is MFA enabled for important staff accounts?

MFA means a second step after a password, such as an authenticator app or security key. Start with email, file storage, finance, donor, HR, cloud, and admin accounts.

Example: Done: all staff use MFA for email and file storage, but finance still needs confirmation.

Are admin accounts named, limited, and reviewed?

Admin accounts can change settings, read sensitive data, or remove other users. Funders want to know they are not shared or forgotten.

Example: Needs work: two old admin accounts still need to be removed.

Does offboarding remove access from key systems?

When staff, contractors, or volunteers leave, someone should remove access from email, files, vendors, shared inboxes, and devices.

Example: Not sure: HR has a checklist, but vendor accounts are not always included.

Do staff use a password manager for sensitive systems?

A password manager helps people use unique passwords instead of reusing one password across many accounts.

Example: Needs work: leadership uses one, but program staff do not.

Data, backups, and recovery

These questions help you explain what sensitive data exists and whether it can be recovered.

Do you know where sensitive data lives?

Sensitive data can include donor, beneficiary, legal, staff, finance, program, source, or operational records.

Example: Not sure: donor and finance systems are known, but old shared folders have not been reviewed.

Do you know how long important records should be kept?

Retention means how long you keep records before archiving or deleting them. Different data may have different expectations.

Example: Needs work: donor records are understood, but program files are kept indefinitely.

Are critical files and systems backed up?

Backups should cover the information your team needs to keep operating after deletion, ransomware, account compromise, or vendor failure.

Example: Done: files and CRM are backed up, but restore permissions need review.

Has anyone tested a restore recently?

A restore test proves you can recover data, not just that a backup setting is turned on.

Example: Needs work: backups exist, but no one has documented a restore in the last year.

Incident readiness

These questions ask whether your team knows who does what when something goes wrong.

Is a primary responder and decision maker named?

The responder coordinates first actions. The decision maker can approve disruptive steps like disabling accounts or notifying stakeholders.

Example: Done: operations director responds first; executive director makes notification decisions.

Are outside support contacts recorded?

Include IT, security, legal, insurance, hosting, and platform support. After-hours paths matter.

Example: Not sure: IT contact is known, but legal and insurance contacts are not in the incident plan.

Do you have communication templates for common incidents?

Templates reduce panic when you need to notify staff, funders, customers, beneficiaries, or affected people.

Example: Needs work: no drafts exist yet.

Has the team walked through one likely incident?

A tabletop is a short practice conversation. It exposes gaps before the incident is real.

Example: Needs work: we have talked informally, but never practiced a scenario.

Remediation plan

Use this section to turn the checklist into a short action plan.

What is the most important gap you found?

Pick the issue that creates the most risk or would be hardest to explain to a funder.

Example: No recent access review, so former staff may still have access to shared folders.

What fix should happen first?

Write a practical next step. It does not need to solve everything.

Example: Export current users, remove stale accounts, and save the access review record.

Who owns it, and what evidence will show it is complete?

A name and a proof point make this easier to act on.

Example: Operations director by Aug 15; evidence is an access review spreadsheet and screenshots.

More resources

Keep going with related resources.

Readiness support

Need a second set of eyes?

Secure Origin helps nonprofits and NGOs turn this checklist into a Protect The Organization roadmap, remediation plan, validation scope, or funder-ready evidence package.

PGP for sensitive email
hello@secureorigin.io fingerprint:
0BA7 6A2D 2761 340E 394F 7F13 129B A65D 2CA7 34C5
Request review Book call