The 5-Point Business Exposure Checklist

Five plain-language questions that reveal whether your business is an easy target — no technical knowledge required, and nothing here costs money to fix.

FREE NO SIGN-UP 10 MINUTES

Most businesses that get hit were not chosen. They were found — by software scanning thousands of organisations at once, looking for the easiest way in.

The doors attackers use most are the same five every time, and you can check all of them yourself. This checklist is written for business owners, managers and finance teams — not for IT specialists. Each point tells you what is at stake in plain terms, and gives you the exact question to put to whoever handles your technology.

Go through each point and answer honestly. An “I don’t know” is the most valuable answer on the page — it is exactly where your risk is hiding.

Five Questions Worth Asking

Each point below reflects an exposure we see repeatedly across Ghanaian businesses — and each one can be closed without a security budget.

POINT — 01

Can a stranger send email pretending to be you?

If your domain is not locked down, anyone on the internet can send an email that looks like it came from your company — to your clients, your bank, or your own staff. No hacking required. This is the single most common route to fraudulent invoices and lost payments, and it costs nothing to fix.

Ask your IT person or provider

“Do we have SPF, DKIM and DMARC set up on our domain — and is DMARC set to reject, not just monitor?”

POINT — 02

Is every account protected by more than a password?

Passwords leak constantly — usually from somewhere else entirely, then reused on your systems. Two-step verification stops the overwhelming majority of account takeovers. Email is the priority: whoever controls your email can reset everything else.

Check today

Is two-step verification switched on for every company email account — especially finance, management, and anyone who can move money?

POINT — 03

Are your staff’s passwords already for sale?

When an employee’s password is stolen — often from a personal device infected with malware — it ends up bundled and sold in criminal markets. Your business can be fully exposed without a single system of yours being touched. Most companies only find out after the money is gone.

Ask yourself

Has anyone ever checked whether your company’s email addresses appear in known data leaks? If nobody has looked, the answer is unknown — not “no”.

POINT — 04

Would you know if someone got in?

Attackers rarely announce themselves. They sit quietly in an email account for weeks, learning how you write and who pays you — then send one convincing message at the right moment. Antivirus does not catch this. Someone has to be watching for the signs.

Ask your IT person or provider

“If someone logged into our email from another country tonight, what would tell us — and who would see it?”

POINT — 05

Can you verify a payment request without email?

The most expensive attacks in West Africa right now are not clever code — they are a believable email asking finance to update bank details. If your only check is replying to that email, you are asking the attacker for permission. One phone-call rule prevents nearly all of it, and costs nothing.

Make it a written rule

Any change to bank or payment details must be confirmed by phone call to a known number — never a number supplied in the email itself.

Reading Your Result

Count how many points you could answer with a confident “yes”.

4–5 Confident Yeses

  • You are ahead of most businesses your size.
  • Keep it reviewed — exposure changes as staff and systems change.
  • Consider periodic external exposure assessment to track drift.

2–3 Confident Yeses

  • You have real gaps, but they are closeable.
  • Start with points 1 and 2 — both are free.
  • Together they stop the most common attacks against businesses like yours.

0–1 Confident Yeses

  • Your business is currently an easy target.
  • Nothing here requires a large budget.
  • It requires someone to actually do it this week.

This checklist is general guidance for business owners and managers. It is not a substitute for a full security assessment, nor for legal or regulatory advice. Every organisation’s risk is different — if any point above concerns you, speak to a qualified professional about your specific situation.

See What Attackers Can Already See

We run a free Exposure Snapshot — a passive check of what is publicly exposed about your organisation: leaked credentials, email security gaps, and weaknesses visible from the outside. No systems are touched and nothing is attacked. You receive a plain-language summary of what we find and what to do about it.