Free course · Module 1
What do I fix first?
Sooner or later someone hands you a list of security problems. Your IT provider sends a report. Your website host emails a warning. An insurer scans your business from the outside and sends you the results. The list is always longer than the time and money you have to fix it.
This module is about the order. By the end you'll have written down, in plain words, how your business decides what gets fixed first, how fast, who decides, and what happens when something can't be fixed.
Who it's for. Owners and managers of businesses with roughly 5 to 50 people and nobody whose job is security. You probably run on Microsoft 365 or Google Workspace, QuickBooks, a card reader or online store, and a website, with an outside IT provider or nobody at all.
What you should have done first. This is not a course on passwords or phishing. It assumes you've turned on two-step login, have backups running, and have talked to your staff about scams. If not, start with the free CISA Cyber Essentials or FlintScope's Free Six, then come back.
Warm up (optional, 5 minutes). Play What First, a short game where you run a small business for a year with more problems than you can fix. It shows why the order matters. This module gives you the rules to get the order right.
What you finish with
My Fix-First Rules
A Word file you build on your own computer, one part per lesson. It opens in Word, Google Docs or Pages. Prefer pen and paper? The printable version has the same parts.
Nothing you write is sent to this site. Once it's filled in, the file describes how your business is set up and where it's exposed, so keep it on your own drive and share it only with named people.
The lessons
- 01"Critical" isn't the same as urgent11 minWhy the severity label on a security alert is the wrong way to decide what to fix first, and what the label actually tells you. Fills in: Part 1, what we don't sort by.
- 02Exploited and exposed comes first13 minThe two-question test that finds the real emergencies on any list of security problems, and the four boxes everything else falls into. Fills in: Part 2, the gate.
- 03What would hurt most12 minHow to name the handful of systems your business can't run without, and use that list to put everything that isn't an emergency in order. Fills in: Part 3, our top systems.
- 04Deadlines, and saying no on purpose14 minSet fix deadlines you can hold your IT provider to, decide what counts as fixed, and handle the problems you can't fix by accepting them in writing, with a name and an end date. Fills in: Parts 4 and 5, deadlines and exceptions.