Fictional example · Not your results

A sample security action plan

This invented small team uses Microsoft 365, Exchange Online, and Windows. It has a security owner, an incomplete inventory, no MFA, partially managed updates, and questions it still needs to investigate.

The example uses the same rules as the free checkup. It is not a customer case study, evidence of effectiveness, or a recommendation for your organization.

Start my own checkup →

A practical plan based on fictional answers, not a security score. Start with a few actions, give each one an owner, and check your progress.

Downloads include the environment choices, answers, exclusions, and guidance shown below. Nothing is automatically shared.

What this checkup covers

14 / 14

Selected checks answered

0

Outside the selected technology scope

0

Independently verified

Microsoft 365:
Yes
Exchange Online:
Yes
Windows:
Yes
Business email:
Yes
Online file sharing:
Yes

1 item

Act first

Start with these missing foundational protections. Confirm the scope and test changes before rolling them out.

Protect sign-ins with MFA

Not in place

Stolen passwords can expose business systems.

Your next action

Pilot strong MFA, protect emergency access, then expand enforcement.

How to know it worked

Confirm a representative account cannot sign in using only a password.

Estimated effort: medium · NIST CSF 2.0: PR.AA

Related implementation guide ↗
Sources and implementation limits

Use available capabilities; document cost or licensing constraints rather than assuming a paid product.

Selected NIST category alignment, not complete category coverage. Linked SCuBA baselines are version-pinned supporting references, not an automated assessment or a universal SMB mandate.

2 items

Plan next

Plan time to close these gaps and finish what you have started.

Know what you need to protect

Partly in place

Unknown assets and accounts can remain unprotected.

Your next action

Start a shared inventory and assign a monthly review owner.

How to know it worked

Compare an inventory sample with deployed devices and active accounts.

Estimated effort: medium · NIST CSF 2.0: ID.AM

Related implementation guide ↗
Sources and implementation limits

Use available capabilities; document cost or licensing constraints rather than assuming a paid product.

Selected NIST category alignment, not complete category coverage. Linked SCuBA baselines are version-pinned supporting references, not an automated assessment or a universal SMB mandate.

Keep Windows up to date

Partly in place

Unsupported or unpatched software leaves known weaknesses.

Your next action

Inventory unsupported software and establish a tested update schedule.

How to know it worked

Check representative devices for successful updates and remaining overdue items.

Estimated effort: medium · NIST CSF 2.0: PR.PS

Related implementation guide ↗
Sources and implementation limits

Use available capabilities; document cost or licensing constraints rather than assuming a paid product.

Selected NIST category alignment, not complete category coverage. Linked SCuBA baselines are version-pinned supporting references, not an automated assessment or a universal SMB mandate.

10 items

Needs verification

Find out what is in place before drawing conclusions. Uncertainty is not a pass or a failure.

Block older sign-in methods

Not sure

Older authentication can bypass modern protections.

How to verify

Review sign-in logs and confirm the block applies to intended accounts.

What to look for

ScubaGear control result plus exceptions and application dependencies.

Estimated effort: medium · NIST CSF 2.0: PR.AA

Related implementation guide ↗
Sources and implementation limits

Microsoft licensing and permissions affect available settings and evidence; missing capability is not a pass.

Selected NIST category alignment, not complete category coverage. Linked SCuBA baselines are version-pinned supporting references, not an automated assessment or a universal SMB mandate.

Limit administrator access

Not sure

Excess privilege increases the impact of account compromise.

How to verify

Review a sample of administrator assignments against approved responsibilities.

What to look for

Privileged account list, separate admin identities, review date, and application consent process.

Estimated effort: medium · NIST CSF 2.0: PR.AA

Related implementation guide ↗
Sources and implementation limits

Use available capabilities; document cost or licensing constraints rather than assuming a paid product.

Selected NIST category alignment, not complete category coverage. Linked SCuBA baselines are version-pinned supporting references, not an automated assessment or a universal SMB mandate.

Control external email forwarding

Not sure

Forwarding can leak messages after an account compromise.

How to verify

Verify authorized exceptions and test that unapproved forwarding is blocked.

What to look for

ScubaGear forwarding result and business-approved exceptions.

Estimated effort: low · NIST CSF 2.0: PR.DS

Related implementation guide ↗
Sources and implementation limits

Microsoft licensing and permissions affect available settings and evidence; missing capability is not a pass.

Selected NIST category alignment, not complete category coverage. Linked SCuBA baselines are version-pinned supporting references, not an automated assessment or a universal SMB mandate.

Protect your email domain

Not sure

Spoofed business email can enable fraud.

How to verify

Confirm legitimate mail passes authentication and inspect DMARC reports.

What to look for

Domain inventory, DNS records, legitimate senders, and ScubaGear results when available.

Estimated effort: medium · NIST CSF 2.0: PR.PS

Related implementation guide ↗
Sources and implementation limits

Microsoft licensing and permissions affect available settings and evidence; missing capability is not a pass.

Selected NIST category alignment, not complete category coverage. Linked SCuBA baselines are version-pinned supporting references, not an automated assessment or a universal SMB mandate.

Filter malicious email

Not sure

Malicious messages can steal credentials or introduce malware.

How to verify

Check policy coverage and use an approved benign test procedure.

What to look for

Protection policies, assigned recipients, exclusions, and relevant license entitlements.

Estimated effort: medium · NIST CSF 2.0: PR.PS

Related implementation guide ↗
Sources and implementation limits

Use available capabilities; document cost or licensing constraints rather than assuming a paid product.

Selected NIST category alignment, not complete category coverage. Linked SCuBA baselines are version-pinned supporting references, not an automated assessment or a universal SMB mandate.

Share files intentionally

Not sure

Overbroad links can expose business data.

How to verify

Check representative sensitive files using an unauthorized test account.

What to look for

Sharing defaults, anonymous links, guest access reviews, and sample permissions.

Estimated effort: medium · NIST CSF 2.0: PR.AA

Related implementation guide ↗
Sources and implementation limits

Use available capabilities; document cost or licensing constraints rather than assuming a paid product.

Selected NIST category alignment, not complete category coverage. Linked SCuBA baselines are version-pinned supporting references, not an automated assessment or a universal SMB mandate.

Protect your Windows devices

Not sure

Device compromise or theft can expose business information.

How to verify

Confirm protection health, firewall profiles, encryption state, and authorized key recovery.

What to look for

Guided checks on representative devices, including recovery-key handling.

Estimated effort: medium · NIST CSF 2.0: PR.PS

Related implementation guide ↗
Sources and implementation limits

Use available capabilities; document cost or licensing constraints rather than assuming a paid product.

Selected NIST category alignment, not complete category coverage. Linked SCuBA baselines are version-pinned supporting references, not an automated assessment or a universal SMB mandate.

Notice suspicious activity

Not sure

An enabled log without review may not help detect compromise.

How to verify

Generate a benign event and confirm it is visible to the assigned reviewer.

What to look for

Audit settings, retention, alert recipients, and evidence of review.

Estimated effort: medium · NIST CSF 2.0: DE.CM

Related implementation guide ↗
Sources and implementation limits

Microsoft licensing and permissions affect available settings and evidence; missing capability is not a pass.

Selected NIST category alignment, not complete category coverage. Linked SCuBA baselines are version-pinned supporting references, not an automated assessment or a universal SMB mandate.

Prepare for an incident

Not sure

Confusion can increase incident duration and business disruption.

How to verify

Run a short tabletop exercise and record improvements.

What to look for

Accessible response checklist, contacts, and exercise record.

Estimated effort: low · NIST CSF 2.0: RS.MA

Related implementation guide ↗
Sources and implementation limits

Use available capabilities; document cost or licensing constraints rather than assuming a paid product.

Selected NIST category alignment, not complete category coverage. Linked SCuBA baselines are version-pinned supporting references, not an automated assessment or a universal SMB mandate.

Make sure you can recover

Not sure

A successful backup job does not prove recovery is possible.

How to verify

Restore representative data safely and compare recovery time with business needs.

What to look for

Backup coverage, separation of access, and dated restoration-test evidence.

Estimated effort: medium · NIST CSF 2.0: RC.RP

Related implementation guide ↗
Sources and implementation limits

Use available capabilities; document cost or licensing constraints rather than assuming a paid product.

Selected NIST category alignment, not complete category coverage. Linked SCuBA baselines are version-pinned supporting references, not an automated assessment or a universal SMB mandate.

1 item

Practices you reported

You said these practices are in place. They have not been independently verified.

Someone owns security

In place

Unowned decisions and unknown dependencies delay recovery.

How to verify

Have the owner review the list and rehearse one outage scenario.

What to look for

Named owner, critical services, and acceptable downtime.

Estimated effort: low · NIST CSF 2.0: GV.RR

Related implementation guide ↗
Sources and implementation limits

Use available capabilities; document cost or licensing constraints rather than assuming a paid product.

Selected NIST category alignment, not complete category coverage. Linked SCuBA baselines are version-pinned supporting references, not an automated assessment or a universal SMB mandate.

How to read this plan

Missing foundational protections are Act first; partial or other gaps are Plan next. Unknown answers or uncertain applicability need verification. Priorities are guidance, not calculated risk or business-impact estimates.

Self-reported answers; no independent evidence has been collected or verified. A starting point for improvement, not certification or a complete risk assessment. NIST category mappings are authored alignment, not an official crosswalk. Check licensing and test changes safely before applying them.

Catalog 0.2.1 · Content review: 2026-09-22 · Created