---
title: The Most Important Small Business Checklist of the Year - Protelligent, Inc.
description: This handy cybersecurity checklist can help you prevent security compromise, and provide measures to contain an attack after infiltration.
image: https://protelligent.net/hubfs/Imported_Blog_Media/ITPriorities2019_BLG.jpg
---

# The Most Important Small Business Checklist of the Year

[Cybersecurity](https://protelligent.net/blog/tag/cybersecurity)

 January 10, 2019 4 min read  By: Christopher George

 Share this post 

<http://www.linkedin.com/shareArticle?mini=true&url=> <https://twitter.com/intent/tweet?original_referer=&url=&source=tweetbutton&text=> <http://www.facebook.com/share.php?u=>

![asset](https://protelligent.net/hubfs/Website%20assets%20-%202024/banner%20tier2.svg)

![The Most Important Small Business Checklist of the Year](https://protelligent.net/hs-fs/hubfs/Imported_Blog_Media/ITPriorities2019_BLG.jpg?width=1030&height=534&name=ITPriorities2019_BLG.jpg)

As you begin to establish goals and reevaluate critical business risks for the year ahead, cybersecurity must be at the very top of your list. According to the [Breach Level Index](https://www.breachlevelindex.com/request-report?utm_campaign=breach-level-index&utm_medium=press-release&utm_source=&utm_content=&utm_term), the number of lost, stolen or compromised records increased by a jaw-dropping 133% in the first half of 2018 compared to the same time the previous year. As attack methods continue to evolve, you not only need a strong security platform, but the knowledge and experience to put it all together. Without the right strategy and execution, you are taking a serious gamble with your livelihood.  
 Our Protelligent® engineers have compiled this handy cybersecurity checklist of tactics that can help you prevent initial compromise, along with measures to contain an attack after infiltration.  
**UP-FRONT TACTICS TO HELP PREVENT INITIAL COMPROMISE**

- □ **Patch vulnerable software** and restrict network access to what you cannot quickly patch

- □ **Restrict Access to Remote Desktop (RDP)** 
    - Place RDP listening ports behind a firewall
    - Use an RDP Gateway
    - Enable network-level authentication
    - Change the default listening port

- □ ****Use Server Message Block (SMB) Best Practices**** 
    - Disable SMBv1
    - Restrict SMB network activity by using firewalls

- □** Block Malicious File Attachments in Email** 
    - Executable and batch files (.EXE, .BAT)
    - Script files (.JS, .VBS)
    - Archive files (.ZIP, .SFX, .7z )

- □** Organizational Awareness**

- □** Utilize Ad Blockers in Web Browsers**

- □** Secure Microsoft Office** 
    - Enforce stringent macro controls to reduce potential infection from malware and malicious scripts
    - Ensure the “update automatic links at open” setting in Microsoft Word is disabled to prevent the Microsoft Dynamic Data Exchange (DDE) feature from launching malware
    - Disable Microsoft’s Object Linking and Embedding (OLE) feature when possible to reduce malicious file attacks

**PRECAUTIONS TO CONTAIN ATTACKS AFTER INFILTRATION**

- □** Secure Windows PowerShell to keep attackers from leveraging its range of functionality** 
    - Update to the latest version
    - Block unsigned PowerShell scripts to make potential attacks more visible
    - Use PowerShell “constrained language mode” to avoid many fileless-attack techniques
    - Enable extended PowerShell logging, carefully monitor events and utilize an auditing tool to help process them
    - Disable PowerShell if it is not necessary for your business

- □** Utilize and Secure Windows Management Instrumentation (WMI)** 
    - Use WMI to your advantage by setting up defensive permanent WMI event subscriptions to log and respond to malicious activity
    - Set up a fixed port and block if remote WMI is not necessary for your business

- □** Apply Application and Restricted Privileges Controls** 
    - Use AppLocker to limit executable files, DLLs and scripts
    - Create rules to strengthen AppLocker against bypass
    - Give users the least amount of access and privileges necessary to complete their job duties
    - If possible, set User Account Control (UAE) to “always notify” when a program makes an attempt to change the machine or any Windows settings
    - Enforce UAC by enabling admin approval mode to prevent privilege escalation attempts
    - Eliminate users from the local administrators’ group
    - Disable credential caching for network authentication
    - Refrain from using the same credentials across systems
    - Apply automatic log-out settings to your network after a period of inactivity
    - Disable anonymous access to Network File Shares (NFS) and File Transfer Protocol (FTP)
    - Require strong passwords
    - Require multi-factor authentication
    - Administer account lockout policies or successive delays for logins

- □** Create Continuous Monitoring Processes for any the following** 
    - Changes in the registry
    - Scheduled task creations
    - Questionable WMI activity
    - Sketchy API calls and processes
    - Processes or tasks produced with the CREATE_SUSPENDED flag

While all of these safeguards can help mitigate risk, the biggest challenge is sustaining the gain. Our all-inclusive [Premonition Security Suite](https://protelligent.net/premonition) is designed to align cybersecurity with your business goals and objectives, enabling you to confidently do more, innovate more and grow more today and into the future.

Level the playing field now. Contact us at [(855) PRO-TELL](tel:8557768355) and ensure your defenses are working ***for you,*** not against you.

 Share this post

[![Share on linkedin](https://protelligent.net/hs-fs/hubfs/linkedin-color.png?width=24&name=linkedin-color.png) ](http://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fprotelligent.net%2Fblog%2Fthe-most-important-small-business-checklist-of-the-year%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://protelligent.net/hs-fs/hubfs/x-twitter-color.png?width=24&name=x-twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fprotelligent.net%2Fblog%2Fthe-most-important-small-business-checklist-of-the-year%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fprotelligent.net%2Fblog%2Fthe-most-important-small-business-checklist-of-the-year%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on facebook](https://protelligent.net/hs-fs/hubfs/facebook-color.png?width=24&name=facebook-color.png) ](http://www.facebook.com/share.php?u=https%3A%2F%2Fprotelligent.net%2Fblog%2Fthe-most-important-small-business-checklist-of-the-year%3Futm_medium%3Dsocial%26utm_source%3Dfacebook)

## Similar Blog Post

 

Get the latest insights, inspiration,  and resources to level the playing field for your small and medium-sized businesses.

[ See All ](https://protelligent.net/blog)

[![](https://protelligent.net/hs-fs/hubfs/Imported_Blog_Media/cloud-24-seven-security-protelligent-blg.jpg?width=352&name=cloud-24-seven-security-protelligent-blg.jpg) ](https://protelligent.net/blog/15-reasons-not-to-let-your-guard-down)

[Cybersecurity](https://protelligent.net/blog/tag/cybersecurity)

#### 15 Reasons Not to Let Your Guard Down

 During the lazy days of summer, don’t let your guard down. We’ve learned from recent events that hackers and attackers are still...

[ Learn More ](https://protelligent.net/blog/15-reasons-not-to-let-your-guard-down)

[![hackers during tax season](https://protelligent.net/hs-fs/hubfs/Imported_Blog_Media/Tax_Season_Phishing_BLG.jpg?width=352&name=Tax_Season_Phishing_BLG.jpg) ](https://protelligent.net/blog/just-one-employee-to-take-the-bait)

[Cybersecurity](https://protelligent.net/blog/tag/cybersecurity)

#### It Takes Just One Employee to Take the Bait. Attacks are on the Rise.

 During this year’s tax season, hackers are taking full advantage of the large amounts of data being exchanged online by going on...

[ Learn More ](https://protelligent.net/blog/just-one-employee-to-take-the-bait)

[![](https://protelligent.net/hs-fs/hubfs/Imported_Blog_Media/Cyber_Security_Tips_Cloud_Computing.png?width=352&name=Cyber_Security_Tips_Cloud_Computing.png) ](https://protelligent.net/blog/top-4-cybersecurity-tips-for-successful-cloud-computing)

[Cloud](https://protelligent.net/blog/tag/cloud) [Cybersecurity](https://protelligent.net/blog/tag/cybersecurity)

#### Top 4 Cybersecurity Tips for Successful Cloud Computing

 The security hits keep coming from all directions, and misconfigurations in third-party Application Programming Interfaces (API)...

[ Learn More ](https://protelligent.net/blog/top-4-cybersecurity-tips-for-successful-cloud-computing)

![decor](https://protelligent.net/hubfs/Website%20assets%20-%202024/decor-footer.png)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Christopher George",
    "url" : "https://protelligent.net/blog/author/christopher-george"
  },
  "dateModified" : "2024-05-17T15:15:33.849Z",
  "datePublished" : "2019-01-10T15:40:52.000Z",
  "headline" : "The Most Important Small Business Checklist of the Year - Protelligent, Inc.",
  "image" : [ "https://protelligent.net/hubfs/Imported_Blog_Media/ITPriorities2019_BLG.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://protelligent.net/blog/the-most-important-small-business-checklist-of-the-year",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://protelligent.net/hubfs/Logo%20-%20Color%20-%20Digital%20-%20Hubspot.png"
    },
    "name" : "Protelligent, Inc."
  }
}
```