The Breach That Started With an Unpatched Laptop

In 2023, the MOVEit Transfer vulnerability (CVE-2023-34362) was exploited by the Cl0p ransomware group to compromise over 2,500 organizations worldwide. The root cause wasn't some exotic zero-day that no one could have predicted — it was a known vulnerability with an available patch that hadn't been applied. Basic cyber hygiene failed, and the consequences were catastrophic.

I've spent years watching organizations pour money into advanced threat detection platforms while ignoring the fundamentals. A solid cyber hygiene checklist isn't glamorous. It won't win you a vendor award. But it will stop the vast majority of attacks that actually hit real businesses every single day.

This post gives you the specific, actionable checklist I recommend to every organization I work with — from ten-person shops to enterprises. No theory. No fluff. Just the steps that reduce your attack surface right now.

What Is Cyber Hygiene, and Why Does Your Checklist Matter?

Cyber hygiene refers to the routine practices and precautions that keep your systems, data, and users secure. Think of it like washing your hands — simple, repetitive, and shockingly effective at preventing disaster.

According to the Verizon 2024 Data Breach Investigations Report, 68% of breaches involved a human element, including social engineering and credential theft. Most of those breaches didn't require a sophisticated threat actor. They required a missing checkbox on someone's cyber hygiene checklist.

A checklist works because it removes ambiguity. Your team stops debating what "good security" looks like and starts executing on a defined standard.

The 12-Step Cyber Hygiene Checklist

1. Enforce Multi-Factor Authentication Everywhere

If you only do one thing on this list, do this. Multi-factor authentication (MFA) blocks over 99% of automated credential-stuffing attacks, according to Microsoft's own research. Enable it on email, VPNs, cloud platforms, admin consoles — everything.

Don't rely on SMS-based MFA if you can avoid it. Use authenticator apps or hardware keys. SIM-swapping attacks make SMS the weakest MFA option.

2. Patch Operating Systems and Software Within 72 Hours

CISA maintains a Known Exploited Vulnerabilities Catalog that lists actively exploited flaws. If a vulnerability shows up there, you patch it immediately — not next quarter, not next sprint.

Set a policy: critical patches within 72 hours, high-severity within two weeks. Automate where you can. Manual patching at scale is a fantasy.

3. Run Phishing Simulations Monthly

Your employees are your largest attack surface. Social engineering is still the most reliable way threat actors get inside your network. Monthly phishing simulations train your people to recognize suspicious emails before they click.

I've seen organizations cut their phish-click rates by over 60% in six months with consistent simulations. Our phishing awareness training for organizations gives you a structured program to make that happen.

4. Require Unique, Strong Passwords With a Password Manager

Password reuse is an epidemic. When a credential dump from one breached service gets tested against your corporate email — and it works — you have a data breach on your hands.

Deploy an enterprise password manager. Require minimum 16-character passwords. Ban the most common passwords outright. This is non-negotiable in 2026.

5. Implement Endpoint Detection and Response (EDR)

Traditional antivirus is dead. EDR solutions monitor endpoint behavior in real time, catching ransomware and fileless malware that signature-based tools miss entirely.

Make sure your EDR covers every endpoint — including those personal devices your remote employees are using. Shadow IT kills organizations.

6. Maintain an Asset Inventory

You can't protect what you don't know about. Maintain a living inventory of every device, application, and cloud service in your environment. Update it at least quarterly.

The NIST Cybersecurity Framework starts with "Identify" for a reason. Asset management is the foundation of every other security control.

7. Segment Your Network

Flat networks are a gift to attackers. Once a threat actor compromises one system, lateral movement gives them the keys to everything. Network segmentation limits blast radius.

Start with the basics: separate guest Wi-Fi from corporate. Isolate sensitive databases. Move toward a zero trust architecture where every connection is verified regardless of location.

8. Back Up Data Using the 3-2-1 Rule

Three copies of your data. Two different media types. One offsite (or offline). Test your restores quarterly — backups you've never tested are backups that don't work.

Ransomware gangs increasingly target backup systems first. Keep at least one backup air-gapped or immutable so attackers can't encrypt it alongside everything else.

9. Conduct Security Awareness Training Regularly

Annual compliance training doesn't change behavior. Regular, engaging security awareness training does. Your employees need to understand social engineering tactics, credential theft techniques, and how to report suspicious activity.

Our cybersecurity awareness training program covers exactly these topics in a format that people actually remember. Make training a continuous process, not a once-a-year checkbox.

10. Review and Restrict Admin Privileges

Principle of least privilege isn't optional — it's survival. Every account with admin rights is a high-value target. Audit privileged access monthly. Remove standing admin rights wherever possible and implement just-in-time access instead.

In my experience, most organizations have two to three times more admin accounts than they actually need. Every unnecessary one is an open door.

11. Enable Logging and Monitor It

Logs without monitoring are just expensive storage. Enable logging on firewalls, endpoints, identity systems, and cloud platforms. Feed those logs into a SIEM or managed detection service that actually alerts on anomalies.

Mean time to detect a breach was 204 days according to IBM's 2023 Cost of a Data Breach report. Good logging and monitoring shrinks that window from months to hours.

12. Have an Incident Response Plan — and Test It

When ransomware hits at 2 a.m. on a Saturday, nobody is going to calmly draft a response plan from scratch. You need a documented, tested incident response plan that covers roles, communication chains, containment steps, and legal obligations.

Run a tabletop exercise at least twice a year. Walk through realistic scenarios. The organizations that recover fastest from a data breach are the ones that practiced before it happened.

How Often Should You Review Your Cyber Hygiene Checklist?

Review your full cyber hygiene checklist quarterly at minimum. Threats evolve. Your infrastructure changes. New employees join. SaaS tools get added without IT's knowledge. A checklist that isn't reviewed becomes a relic.

Assign a specific owner — a security lead, IT director, or virtual CISO — who is accountable for each quarterly review. Document what changed and why. That documentation becomes invaluable during audits and post-incident investigations.

The Zero Trust Connection

If you're hearing the term zero trust and wondering how it fits here, the answer is simple: a good cyber hygiene checklist is the prerequisite. You cannot implement zero trust without solid MFA, asset inventory, network segmentation, and least privilege already in place.

Zero trust isn't a product you buy. It's an architecture built on the fundamentals this checklist covers. Get these right first, then layer on continuous verification and micro-segmentation.

Where Most Organizations Fail

I've seen three patterns repeatedly sink otherwise well-intentioned security programs:

  • Inconsistency. They enforce MFA on email but not on their CRM. They patch servers but ignore workstations. Threat actors find the gaps you skip.
  • Treating training as compliance. A 20-minute video once a year doesn't build muscle memory. Phishing simulation programs and continuous security awareness training do.
  • No accountability. The checklist exists in a shared drive nobody opens. Nobody owns it. Nobody tracks it. It becomes decoration.

Don't let your cyber hygiene checklist collect dust. Make it a living operational document with clear owners, deadlines, and consequences for non-compliance.

Start With What You Can Control Today

You don't need a six-figure budget to start. Enable MFA today. Run a phishing simulation this week. Audit your admin accounts this month. Each step on this cyber hygiene checklist reduces your risk in measurable ways.

The organizations that avoid headlines aren't lucky — they're disciplined. They do the boring work consistently. That's the entire secret.

Build your security culture from the ground up with our cybersecurity awareness training, and start testing your human defenses with our phishing awareness training program. The checklist only works when your people do.