
THE 24UNET SECURITY BASELINE
The 2am Saturday Test: Is Your IT Provider Actually Protecting You?
Would your current setup catch an account takeover at 2am on a Saturday?
Someone steals a session token and signs in as your controller, past the multi-factor authentication (MFA) prompt. They add an inbox rule that hides replies, and before Monday a payment instruction has changed.
This page is the list we include for every 24uNet client, in writing. Take it to whoever protects you today and ask which lines they deliver. Then you will know exactly where the gaps are.
THE 2AM TEST
The 2am Saturday test, in plain English
An account takeover has no ransom note. Someone simply signs in as one of your people.
What an account takeover actually looks like
Here is the pattern, step by step:
• A staff member signs in on a fake page. The attacker captures the session token, the pass your browser keeps after login, and is past MFA.
• They create inbox rules that hide replies and forward mail to an outside address.
• Before Monday, a payment instruction changes.
We can add identity threat detection and response, built to catch "token theft, rogue apps, hidden inbox rules."
Who is allowed to act?
Can someone disable the account and revoke its sessions without waiting for permission?
How would you know Monday morning what happened?
We can keep security logs with enough history to scope a real incident.
NOT A TIER. NOT AN UPSELL.
The Security Baseline: 24 lines, 6 groups
Under a master service agreement, every line below is yours from day one. Prefer to pick and choose? A service authorization covers just the lines you want.
Identity
• Multi-factor authentication enforced on every account, no exceptions.
• Conditional access: legacy sign-in blocked outright.
• Identity threat detection & response: watches for token theft, rogue apps, hidden inbox rules.
• Password manager and same-day offboarding.
Endpoint
• Managed EDR with a 24/7 SOC: analysts who act, not alerts you triage.
• Full-disk encryption on every device, keys recoverable.
• OS and third-party patching, reported against an agreed service level.
Network
• Managed firewall, with rules reviewed, documented and patched.
• No exposed remote desktop: VPN or zero-trust access, with MFA.
• Web filtering on the device, on or off your network.
• Guest Wi-Fi and connected devices kept separate from your business.
• Advanced filtering beyond the Microsoft 365 default.
• SPF, DKIM and DMARC at enforcement.
• Impersonation protection and external sender warnings.
• Inbox rule monitoring.
• Ongoing awareness training with phishing simulation.
Data & recovery
• Immutable, ransomware-resistant backup.
• Microsoft 365 backed up separately.
• Restores tested annually, results in writing.
• Recovery objectives agreed in advance.
Evidence & governance
• Written incident response plan with named roles, tested once a year.
• 90 days of retained security logs, enough history to scope a real incident.
• Annual external penetration test.
• Annual risk assessment, plus help with insurer questionnaires.
If a line on this list isn't true for you today, that's the conversation.
THREE LINES, IN DETAIL
Password managers, phishing training and patching
Password manager for small business
We can give every employee a password vault that the business owns, recovers and shuts off the day someone leaves. CISA's advice: "Create long, random, unique passwords with a password manager for safer accounts."
What done looks like:
• Everyone has one, not just IT.
• Shared logins live in shared vaults, not a spreadsheet.
• MFA protects the vault itself.
• Same-day offboarding removes vault access.
Ask your provider: "Who has a vault today, and what happened to the last person who left?"
Phishing training for employees
We can run simulated phishing emails through the year, with short lessons when someone clicks. Prefer a live session? We also offer in-person training built around your team. CISA notes that in the AI era "some emails will now have perfect grammar and spelling."
What done looks like:
• Simulations run year-round, not once.
• Results go to the owners.
• Every inbox has a "report phish" button.
• Wire and payment requests get callback verification.
Ask your provider: "When was our last simulation, and who clicked?"
Third-party patch management
We can patch the software Windows Update doesn't touch: browsers, PDF readers, Zoom, Java, accounting and design apps. Patching runs on a schedule we agree with you, with a report of what's patched and what's still outstanding. CISA says: "It's important to install ALL updates, especially for our web browsers and antivirus software."
Ask your provider: "Show me your latest patch report, including third-party apps."
You don't need to switch providers. You need answers.
Send this checklist ahead of your next review meeting. Ask for a yes, no or partial on every line, and evidence for every yes.

The technology we work with
WHERE THE GAPS HIDE
Where most gaps hide
Does Microsoft 365 back up your data?
Not the way most firms assume. Microsoft keeps the service running. Backing up and restoring your content is your responsibility. Ask your provider where your Microsoft 365 backup lives, and when it was last restored
Is your email authenticated, or just "set up"?
A DMARC policy of "none" is monitoring only. Nothing is blocked. At enforcement, the policy is "quarantine" or "reject," and forged mail in your name goes to junk or is refused. Ask your provider for your current policy.
When was your last restore test?
A backup you have never restored is a hope. The restore test is the proof. Ask for the date of the last restore test and the written result. If neither exists, you have found a gap.
Callback verification for every payment change
Any request to change banking details, and any wire instruction, is verified by phone to a number you already had on file, never a number in the email. It costs nothing. Almost no business has it written down.
WHAT HAPPENS NEXT
Want a second set of eyes? The independent security review
1. The walkthrough
About an hour. We go line by line through the checklist against your actual environment. No tooling to install, no access required.
2. Written findings
What you already have right, what is missing, and what it would take to close each gap. Yours to keep whether or not you hire us.
3. A plan, not a quote
What we would fix first, what can wait a quarter, and what it takes, in order of your risk.
FAQ
Frequently asked questions
What questions should I ask my IT provider about cybersecurity?
Ask them to show evidence, line by line. Start with five: MFA on every account, who responds at 2am, separate Microsoft 365 backup, DMARC at enforcement, and the date of the last restore test.
How do I know if my MSP is doing a good job on security?
Ask for artifacts, not assurances. A managed service provider (MSP) doing good security work can show reports, dated tests and a written incident response plan. "We have that covered" with nothing to show is unconfirmed.
Does Microsoft 365 back up my data?
Not in the way most firms assume. Microsoft protects the service, and your content is your responsibility. Version history helps with single files, not a mass restore after ransomware. Back Microsoft 365 up separately, and test the restore.
What security controls do cyber insurers require?
Commonly MFA, endpoint detection and response (EDR), tested and isolated backups, and a written incident response plan. Requirements vary by carrier, so check your own application.
What is CIS Controls IG1?
Implementation Group 1 (IG1) is the set of CIS Controls safeguards that the Center for Internet Security defines as essential cyber hygiene. It is the starting point for organizations with limited IT and security staff.
What should I do if a Microsoft 365 account is hacked?
Block sign-in, reset the password and revoke active sessions right away. Then find and remove any inbox rules and forwarding the attacker added, noting where mail was going. Call your IT provider and your cyber insurer early.
How do I stop wire fraud from fake payment-change emails?
Verify every payment change by calling a number you already had on file, never a number in the email. Write the rule down, apply it to every wire instruction, and let nobody skip it.
Is an MSP the same as an MSSP?
No. An MSP runs day-to-day IT: support, devices and updates. An MSSP (managed security service provider) focuses on security monitoring and response. This checklist shows which security lines your provider delivers.
What should a small business look for in a password manager?
Business-owned vaults, shared vaults for team logins, MFA on the vault and the ability to remove a departing employee's access the same day.
How often should employees get phishing training?
Continuously: simulations through the year rather than one annual video.
What is third-party patch management?
Keeping non-Microsoft software, like browsers, PDF readers and line-of-business apps, updated, with a report showing it was done.
What is a patch management SLA?
An agreed target for applying updates, measured and reported so you can check it.

ABOUT THE AUTHOR
Dane Gray, Cofounder, 24uNet
Certified Ethical Hacker (CEH), CompTIA Security+, CMMC-AB Registered Practitioner, Texas A&M University. 30+ years in IT and cybersecurity. Dane leads 24uNet's CMMC Level 1 readiness work and independent security reviews.
Last reviewed: October 2, 2026
TALK TO US
Not sure how your provider would answer? Let's find out.
Or call Denver (303) 468-5515 | College Station (979) 256-5100
About an hour. No tooling to install, no access required. Written findings are yours to keep.
