1.
Do you use a vulnerability scanner to check if your applications are up to date and apply patches to the applications if necessary?
2.
Are Microsoft Office Macro's disabled for users who don't need to have them enabled?
3.
Do you have regular backups configured and are they monitored?
4.
Do you use a vulnerability scanner to check if Operating Systems are up to date and apply patches if necessary?
5.
Do you restrict administrative access to your systems?
6.
Do you control which applications can be run by your users on their workstations?
7.
Do all users need to use Multi Factor Authentication (MFA) to login if they are not in the office?
8.
Has the web browser on your systems been hardened or are you using the default browser settings?