Fourteen pages, Letter size. Print it double-sided, or save it as a PDF from the print dialog. ← back to the security page
mutiny.
Support & Education · 2026
Bring a pen No login, no email, no follow-up Designed to be filled in
A working session for your team

Own
your stack.

Many incidents exploit ordinary gaps: a platform nobody updated, a vendor nobody inventoried, an account nobody closed. This workbook is the boring, unglamorous list of the things that actually matter, laid out so a real team can sit at a real table and fill them in.

If you finish only page 2 and page 6, you will have completed two high-value foundational exercises.
01Cover & how to use thisread first
02Infrastructure inventorywhat you run
03Vendor & third-party registerwho holds your data
04Access audit & offboardingwho holds the keys
05Password & 2FA migrationin order, with dates
06Patch & maintenance calendartwelve months
07Workspace settings, Microsoft & Googleten, in order
08Incident response, one pagethe first hour
09Family exposure audittake this one home
10Puerto Rico compliance quick-checkname the statute
11Rights at a checkpointfold and carry
12AI policy starternine answers
13Privacy resettake this one home
14Quarterly review cadenceso it survives
Mutiny Labs · Support & Education
Fractional innovation leadership · San Juan, Puerto Rico
info@mutiny-labs.com · +1 888 449 4466
this document is yours. copy it, adapt it, use it.
mutiny.
02 · Infrastructure inventory
Worksheet one

What you actually run.

List every system that is reachable from the internet or holds data you would hate to lose: website, intranet, CRM, file storage, email, payment tooling, anything with a login page. If a row makes you uncomfortable to fill in, that row is the finding.

System / platform What it runs on Who built it Who maintains it now Last updated Holds sensitive data?
Public website
Email & calendar
File storage / drive

“Who maintains it now” must be a person’s name, not a company and not “the agency.” If the honest answer is nobody, write nobody. That is the most valuable word on this page.

Red flags to circle as you go

  • Software versions no longer receiving security updates
  • Plugins, themes or add-ons whose author has gone quiet
  • Anything last updated more than twelve months ago
  • Systems nobody in the room can log into today

The three questions behind this page

1. If this system were compromised tonight, what would we lose?
2. Who would notice, and how?
3. Who is contractually responsible for keeping it patched?

an inventory you cannot recall is one you cannot review.

Own your stack · Mutiny Labs security workbook · rev. 2026-08-16Page 2 of 14
mutiny.
03 · Vendor & third-party register
Worksheet two

You inherit every vendor’s security.

Several recent incidents illustrate indirect vendor risk: a partner, a support platform, or a contractor’s privileged credentials. Every vendor holding your data, or holding access into your systems, is a door with your name on it. List them all, including the ones you inherited.

Vendor / service What they hold or can reach Access level Contract owner Breach notice in contract? Reviewed on

Don’t forget these vendors

  • Hosting & domain registrar
  • Payment processor
  • Email marketing platform
  • Accounting & payroll
  • Analytics & tag managers
  • Former agencies
  • Freelancers with logins
  • Backup provider
  • IT support contractor
  • Anything with an API key

Ask every vendor these four things

  • What data of ours do you store, and where?
  • Who on your side can access it, and is that access reviewed?
  • How quickly will you notify us of an incident, in writing?
  • If you disappeared tomorrow, could we get our data out?

a vendor who bristles at these questions has answered them.

Own your stack · Mutiny Labs security workbook · rev. 2026-08-16Page 3 of 14
mutiny.
04 · Access audit & offboarding
Worksheet three

Who holds the keys?

Without a lifecycle process, access tends to accumulate and can survive role changes and departures. Go system by system and write down every account with administrative rights, including shared accounts, service accounts, and the ones belonging to people who no longer work here. Then decide, out loud, which ones stay.

System Person or account Access level Still needed? Why 2FA on? Action

Shared accounts (“info@”, “admin”, the social media login everyone uses) deserve their own row. They are the accounts nobody owns and everybody uses, which is the worst possible combination.

Offboarding checklist: run it the day someone leaves

  • Disable email and force sign-out of active sessions
  • Remove from file storage, shared drives and chat
  • Revoke CMS, hosting and deployment access
  • Remove from social, payment and analytics tools
  • Rotate any shared password they knew
  • Revoke API keys and personal access tokens they created
  • Transfer ownership of files, domains and repositories
  • Record the date and who executed each step

The principle, in one line

Give every person the least access that lets them do their job, review it on a schedule, and remove it the same day it stops being necessary. Convenience is the reason access sprawls, and excessive privileges plus reuse are what can turn one stolen password into an organization-wide incident.

Access review owner
Next review date
Own your stack · Mutiny Labs security workbook · rev. 2026-08-16Page 4 of 14
mutiny.
05 · Password & 2FA migration
Checklist one

Do these in order.

Order matters. Password migrations often create avoidable confusion when people start by changing forty passwords with nowhere to put them. Set up the manager first, protect the email account second, then work outward by blast radius.

Step 1 · Give the passwords somewhere to live

Nothing else works until this exists.

Step 2 · Protect the account that resets all the others

Your email is the master key. Treat it that way.

Step 3 · Work outward by blast radius

Banking, hosting, CMS, payroll, social, then everything else.

Migration session plan

Book ninety minutes with the whole team, screens open, manager installed in advance. Do steps 1 and 2 together in the room. Assign step 3 as homework with a deadline and a named owner who checks it.

Track it

Password manager chosen
Migration session date
Owner who verifies completion
Own your stack · Mutiny Labs security workbook · rev. 2026-08-16Page 5 of 14
mutiny.
06 · Patch & maintenance calendar
Worksheet four

Twelve months, one page.

Patch on your schedule or on the attacker’s. Put a name and a recurring calendar entry against each month, initial the box when it is done, and keep this page where the team can see it. Set a documented cadence that fits your exposure; critical security patches do not wait for the calendar.

January owner
Core platform & plugin updates
Dependency / version check
Review new admin accounts
Done by · date
February owner
Core platform & plugin updates
Backup restore test
Review new admin accounts
Done by · date
March owner
Core platform & plugin updates
Q1 access review
Vendor register refresh
Done by · date
April owner
Core platform & plugin updates
Dependency / version check
Review new admin accounts
Done by · date
May owner
Core platform & plugin updates
Breach-index sweep of staff emails
Review new admin accounts
Done by · date
June owner
Core platform & plugin updates
Q2 access review
Incident plan walkthrough
Done by · date
July owner
Core platform & plugin updates
Dependency / version check
Review new admin accounts
Done by · date
August owner
Core platform & plugin updates
Backup restore test
Review new admin accounts
Done by · date
September owner
Core platform & plugin updates
Q3 access review
Vendor register refresh
Done by · date
October owner
Core platform & plugin updates
Dependency / version check
Review new admin accounts
Done by · date
November owner
Core platform & plugin updates
End-of-life software review
Review new admin accounts
Done by · date
December owner
Core platform & plugin updates
Q4 access review
Plan next year’s cadence
Done by · date

Out-of-cycle rule

A vendor announcing an actively exploited vulnerability is not a monthly item. Define now who can authorize an emergency patch window, and how fast.

Emergency patch authority

Before you patch

Take a backup you have actually verified, patch a staging copy first where one exists, and keep a written rollback step. Fear of breaking things is the most common reason systems go unpatched.

The uncomfortable truth

Internet-facing vulnerabilities can be scanned and exploited rapidly, sometimes within hours of disclosure, so critical patches need an out-of-cycle path. “Next quarter” is not one.

Own your stack · Mutiny Labs security workbook · rev. 2026-08-16Page 6 of 14
mutiny.
07 · Workspace settings
Worksheet five: the tenant you already pay for

The settings that ship off.

Both platforms leave important protections switched off, or behind a tier you may not have bought. Work down the column for the platform you run. Console paths verified 16 August 2026; admin consoles move things, so search the setting name if a path has drifted.

# The setting Microsoft 365 Google Workspace Owner · date
1MFA baselineEntra ID > Overview > Properties > Manage security defaultsSecurity > Authentication > 2-step verification. Enforcement On; methods “Any except… text, phone call”
2Admin credentials & break-glassTwo or more cloud-only emergency accounts on passkey (FIDO2). Validate every 90 daysMore than one super admin, separate daily accounts. Security > Authentication > Account recovery
3Anti-phishing preset
Off by default
Threat policies > Preset Security Policies > Standard protection. Impersonation protection is OFF until you do thisNot applicable. Nearest equivalent: Gmail > Safety, and Security sandbox (Business Standard and above)
4Third-party app consent
Open by default on Google
Enterprise apps > Consent and permissions. Confirm “Let Microsoft manage…” and enable the admin consent workflowSecurity > Access and data control > API controls > Manage App Access. “Unconfigured third-party apps” defaults to allow everything
5Email authentication
DKIM off by default on MS
Defender > Threat policies > Email authentication settings > DKIM. SPF -all. Custom domains do not sign until enabledApps > Gmail > Authenticate email. SPF ~all. Then DMARC p=none → quarantine → reject
6External sharing defaultSharePoint admin > Policies > Sharing. Set File and folder links to “Only people in your organization”Apps > Drive and Docs > Sharing settings. Confirm general access = Restricted; Access Checker = Recipients only
7External calendar sharingRestrict to free/busy. Out of box, all users can invite anyone to view their calendarApps > Calendar > Sharing settings. Set external to “Only free/busy information”
8Prune administratorsFewer than five Global Administrators; fewer than ten privileged assignmentsMore than one super admin, none used for daily work, none left signed in
9Log horizonAudit (Standard) = 180 days. Entra logs 7 days free, 30 on P1/P2Most logs 6 months. Business tiers get no investigation tool; Email Log Search holds 30 days
10Backup decisionM365 Backup ($0.15/GB/mo, OneDrive/SharePoint/Exchange only), a third party, or accepted riskNo first-party backup exists. Third party, or accepted risk. Vault is not an archive

The tier check, before you tick anything

Microsoft: Conditional Access, Intune and Defender for Office 365 P1 all arrive at Business Premium. Below it, several rows above are unavailable rather than unset.

Google: Context-Aware Access, the investigation tool, DLP and the security center all require Enterprise. No Business tier, including Business Plus, reaches them.

Sign-off

Platform we run · edition · seat count
Who owns the admin console · next review date
Own your stack · Mutiny Labs security workbook · rev. 2026-08-16Page 7 of 14
mutiny.
08 · Incident response, one page
The first hour

Write this before you need it.

Fill this in now and keep a copy reachable when your systems are not: a wall, a wallet, a phone photo. The first hour sets the tone, and it is the worst time to start improvising.

1

Who gets called, immediately

Name, role, mobile number. Include an alternate for every person. Incidents do not check calendars.

2

Who decides

One named person with authority to take systems offline, spend money, and engage outside help. A committee is not a decision-maker.

3

Contain, then preserve

Disconnect immediately; if you cannot, CISA says power down to stop the spread. Rotate credentials, revoke sessions and tokens. Preserve logs and snapshots; do not wipe or rebuild before evidence is captured.

4

Who speaks, and to whom

One voice for customers, one for staff, one for regulators or press. Silence is a choice with consequences; so is speaking early with the wrong facts.

5

Where the backups live

Location, access method, who can restore, and when it was last successfully tested.

6

Outside help on speed dial

Technical partner, legal counsel, insurer, and the relevant authority. Establish these relationships before the incident, not during it.

Keep a timeline from minute one

Every action, with a timestamp and a name. It is the difference between a defensible response and one reconstructed from memory, and it is what regulators, insurers and your board will ask for.

Do not, under pressure

  • Delete evidence while “cleaning up”
  • Tell customers “no data was affected” before you know
  • Pay or negotiate without legal counsel
  • Act on an urgent payment or access request (however senior the voice or face) without confirming it on a second channel you chose
  • Let one exhausted person work it alone past hour four
Own your stack · Mutiny Labs security workbook · rev. 2026-08-16Page 8 of 14
mutiny.
09 · Family exposure audit
Worksheet five: take this one home

What is already public about your kids.

This page is not about your organization. It is the one worth doing at a kitchen table, because the exposure it covers cannot be undone later: material absorbed into a trained model has no deletion request. The goal is not guilt. It is reducing what gets added from here, and closing the identity-fraud surface, which genuinely is reducible.

Account / platform Who runs it Audience setting Shows children? Identifiers in captions Action & date
Parent 1 social
Parent 2 social
Shared photo album
Teen’s own accounts
Grandparents / relatives
School / team / club pages

Under “identifiers”, look for the combination that powers child identity fraud: full legal name, birthdate, school or hospital name, street, and a clear face. Captions add identity, school, date and location context. The photo itself can also carry biometric, impersonation or exploitation risk on its own.

Six moves, in order

  • Audit the old public albums: birthdays, first days of school, hospital photos, sports rosters
  • Reset audiences to private, knowing settings reduce exposure rather than eliminate it
  • Turn off location for the camera; strip metadata before posting
  • Keep names, schools, birthdates and streets out of captions, and treat the image itself as sensitive too
  • Talk through the sextortion script before it arrives
  • Freeze your children’s credit where your jurisdiction allows it

The conversation, in three sentences

A stranger gets friendly fast, moves things to images, then turns and demands money within hours. Three things have to land: you will not be in trouble, paying does not guarantee it stops and often leads to further demands, and the right move is to tell an adult and keep the messages.

Under the TAKE IT DOWN Act, signed 19 May 2025, covered platforms must remove reported non-consensual intimate imagery (including AI “digital forgeries”) and known identical copies within 48 hours of a valid request. The FTC enforces it and the compliance deadline has passed. This right is live.

We had this conversation on
Own your stack · Mutiny Labs security workbook · rev. 2026-08-16Page 9 of 14
mutiny.
10 · Puerto Rico compliance quick-check
Worksheet six

What actually binds you here.

Work down the column and take anything unresolved to counsel. Naming the statute turns a vague worry into a decision someone can make.

Statute Applies when, and what it requires Exposure Owner & date
Ley 39-2012Covered commercial operator collecting personal info from PR residents. Publish a clear, conspicuous policy; describe who data may be shared with.Mismatch: up to $50,000. Otherwise DACO enforcement
Ley 163-2026Unauthorized commercial or advertising use of an identifiable AI-generated or cloned likeness. Consent and exceptions apply.$750–$20,000; $100k intentional; 1-yr clock
Ley 111-2005Breach of covered data. Notice analysis turns on whether it was unencrypted or insufficiently protected. 10 days to DACO only.$500–$5,000 per violation
Ley 185-2024Defined social-network site or app allowing PR residents aged 18 or younger to register. Legal review required.Reported up to $25,000
Ley 40-2024Contracted IT or communications service provider to the Government. Notify PRITS and the contracting entity within 48 hours.Statutory duty
Ley 5-1973DACO consumer-protection authority that can reach deceptive advertising.Up to $10,000, each day separate
Ley 207-2006Employee SSNs on identification cards and routinely circulated documents.$500–$5,000
TAKE IT DOWNCovered platforms. Remove reported NCII and known copies within 48 hours.FTC enforcement
EU AI Act Art. 50Output used in the EU. Transitional treatment for some existing systems to 2 Dec 2026.Applying since 2 Aug 2026
CA SB 942, as amended by AB 853GenAI provider with over 1M monthly California users. AB 853 sets the 2 Aug 2026 operative date.$5,000 per violation per day
CA AB 2013Develop or substantially modify a GenAI system offered in California.Disclosure duty

What is not required, so you can stop worrying about it

As of 15 Aug 2026 we found no general cross-sector PR statute imposing AI-specific disclosure, risk-assessment, bias-audit or deployer duties on a private company merely for using AI. The AI-specific enactments cover four principal areas: elections, government, criminal deepfakes, likeness. Other law still applies. If someone sells you an AI compliance package for a local private-sector duty, ask them to name the statute.

Government clients differ: PRITS Carta Circular 2023-002 requires prior PRITS authorization before an agency integrates, acquires or contracts for AI development.

Take these to counsel

Counsel · reviewed on
Own your stack · Mutiny Labs security workbook · rev. 2026-08-16Page 10 of 14
mutiny.
11 · Rights at a checkpoint
One-pager: print it, fold it, carry it

Three sentences, and what’s actually settled.

Officers need not tell you that you may decline. Refusing alone is not suspicion (Bostick, 1991).

“I do not consent to a search.”

Anywhere. It will not stop a border search, but it preserves the objection.

“Am I free to go?”

Police stops only. Never at a port of entry.

“I am invoking my right to remain silent.”

Out loud. In Salinas (2013) a plurality allowed use of non-custodial silence where the privilege was not invoked.

Settled

  • Warrant needed after arrest (Riley, 2014)
  • Consent searches need no warrant
  • Refusal is not suspicion (Bostick)
  • Citizens keep entry (CBP); device may be detained
  • Basic border searches: no suspicion (Alasaad)

Unsettled: no Supreme Court ruling

  • Whether you can be compelled to unlock
  • Speaking a passcode vs typing it, among others
  • Biometrics: submitting vs being ordered
  • Green-card holders who decline
  • Refusal has costs (extreme court-order case)

Before you fly

If you decline to unlock In CBP’s own terms Notes for me
US citizenNot denied entry over an incomplete inspection; device may be detained.
Green-card holderGenerally not “seeking admission” on return, but no authority settles refusal. Unsettled.
Visa / ESTARefusal may be weighed in admissibility; inspection alone does not decide it.

If a device is taken (CBP policy, not a constitutional guarantee)

Ask for a CBP Form 6051D receipt. Detention ordinarily under 5 days; copies not kept past 21 days without probable cause.

Officer / badge / agency / time

San Juan to the mainland is domestic

Torres (1979): an ordinary nonstop island-to-mainland trip is domestic and does not itself trigger a border search. The bag check is agricultural (7 CFR Part 318).

Own your stack · Mutiny Labs security workbook · rev. 2026-08-16Page 11 of 14
mutiny.
12 · AI policy starter
Worksheet seven

Nine answers, and you have a policy.

In a 2025 observational survey of 48,340 people across 47 countries, policy-contravening AI use was highest where generative AI was banned outright (67%) and lowest where no policy existed at all (33%). The design does not establish why the groups differed. A rule people route around may remove your visibility rather than the behaviour. Anchors are NIST AI RMF subcategories, which are voluntary and not law.

1 · Approved tools (GOVERN 1.6)

Which tools are allowed, for what, and who can add one.

2 · Which laws reach us (GOVERN 1.1)

The short list for your actual footprint.

3 · What may never be pasted (GOVERN 1.2, 1.4)

Client identifiers, credentials, unreleased financials, health data, anything under NDA.

4 · Named owner (GOVERN 2.1, 2.3)

One accountable person plus an executive sponsor. Not a committee.

5 · Training (GOVERN 2.2)

Who delivers it, to whom, how often.

6 · Human review before it ships (GOVERN 3.2)

Nothing reaches a client, regulator or the public without a named person checking it.

7 · How to report a problem (GOVERN 1.5, 4.3)

A no-blame route for “I pasted something I should not have.”

8 · Vendor and contract clauses (GOVERN 6.1, 6.2)

What AI vendors may do with your data; what your client contracts already say.

9 · How a tool gets retired (GOVERN 1.7)

Accounts closed, data exported or deleted, integrations revoked.

Sign-off

Policy owner · date
Next review
Own your stack · Mutiny Labs security workbook · rev. 2026-08-16Page 12 of 14
mutiny.
13 · Privacy reset
Worksheet eight: take this one home

The settings that measurably work.

Not a full defence, and not a one-time fix. These are the changes with evidence behind them, ordered by effort. Removal in particular is maintenance: Consumer Reports found profiles reappearing weeks or months later.

Do these first

What the removal test found

Doing it yourself: 70% of profiles gone at four months, at no cost. The seven paid services averaged 35%, ranging from 4% to 68%; the $19.99 service beat several costing six times more. Consumer Reports, August 2024. Small non-random sample, explicitly not nationally representative.

Note: some removal services advertise on or partner with the people-search sites they claim to fight.

What you cannot opt out of

  • Data breaches
  • Government and court records
  • Brokers who never registered anywhere
  • DROP if you are not a California resident

If you think someone you know is monitoring your phone, read this before changing anything

The Coalition Against Stalkerware warns that removing monitoring software, or making significant changes, may be detected by the abuser and could increase the abuse and harassment. It also deletes evidence you may need. Their guidance is to build a safety plan with a trusted survivor assistance program first, and to attempt removal only if you believe it is safe to do so.

National Domestic Violence Hotline: 1-800-799-7233, 24/7 and confidential · stopstalkerware.org · techsafety.org

Household notes

Done on

Date · who did it
Own your stack · Mutiny Labs security workbook · rev. 2026-08-16Page 13 of 14
mutiny.
14 · Quarterly review cadence
Make it survive the enthusiasm

Ninety minutes, four times a year.

Everything in this workbook decays. Accounts accumulate, vendors change, software goes end-of-life, and the person who owned the calendar leaves. A short standing review is what turns a good week into a practice. Put it in the calendar before you close this page.

Standing agenda Q1 Q2 Q3 Q4
Admin access reviewed, removals executed
Offboarding completed for every departure
Vendor register updated, new vendors added
Patch calendar signed off for the quarter
Backup restored and verified
End-of-life software flagged with a plan
Staff emails checked against a breach index
Payment & credential requests: second-channel rule rehearsed
Incident plan still accurate, contacts current

Assign it now, while the pen is in your hand

Review owner
Standing meeting day & time
Who this gets reported to

Three notes for next quarter

If any of this turns out to be someone else’s job

Mutiny Labs builds custom, security-first platforms and supervises them after launch: minimized attack surface, access designed around real roles, updates on our watch, one accountable partner. If you filled this workbook in and did not like the answers, that is a good reason to talk.

info@mutiny-labs.com · +1 888 449 4466 · mutiny-labs.com · privacy: mutiny-labs.com/privacy-policy.html

mutiny.
nobody gets breached
during a strategy offsite.
Own your stack · Mutiny Labs security workbook · rev. 2026-08-16Page 14 of 14