Many incidents exploit ordinary gaps: a platform nobody updated, a vendor nobody inventoried, an account nobody closed. This workbook is the boring, unglamorous list of the things that actually matter, laid out so a real team can sit at a real table and fill them in.
List every system that is reachable from the internet or holds data you would hate to lose: website, intranet, CRM, file storage, email, payment tooling, anything with a login page. If a row makes you uncomfortable to fill in, that row is the finding.
| System / platform | What it runs on | Who built it | Who maintains it now | Last updated | Holds sensitive data? |
|---|---|---|---|---|---|
| Public website | |||||
| Email & calendar | |||||
| File storage / drive | |||||
“Who maintains it now” must be a person’s name, not a company and not “the agency.” If the honest answer is nobody, write nobody. That is the most valuable word on this page.
1. If this system were compromised tonight, what would we lose?
2. Who would notice, and how?
3. Who is contractually responsible for keeping it patched?
an inventory you cannot recall is one you cannot review.
Several recent incidents illustrate indirect vendor risk: a partner, a support platform, or a contractor’s privileged credentials. Every vendor holding your data, or holding access into your systems, is a door with your name on it. List them all, including the ones you inherited.
| Vendor / service | What they hold or can reach | Access level | Contract owner | Breach notice in contract? | Reviewed on |
|---|---|---|---|---|---|
a vendor who bristles at these questions has answered them.
Without a lifecycle process, access tends to accumulate and can survive role changes and departures. Go system by system and write down every account with administrative rights, including shared accounts, service accounts, and the ones belonging to people who no longer work here. Then decide, out loud, which ones stay.
| System | Person or account | Access level | Still needed? Why | 2FA on? | Action |
|---|---|---|---|---|---|
Shared accounts (“info@”, “admin”, the social media login everyone uses) deserve their own row. They are the accounts nobody owns and everybody uses, which is the worst possible combination.
Give every person the least access that lets them do their job, review it on a schedule, and remove it the same day it stops being necessary. Convenience is the reason access sprawls, and excessive privileges plus reuse are what can turn one stolen password into an organization-wide incident.
Order matters. Password migrations often create avoidable confusion when people start by changing forty passwords with nowhere to put them. Set up the manager first, protect the email account second, then work outward by blast radius.
Nothing else works until this exists.
Your email is the master key. Treat it that way.
Banking, hosting, CMS, payroll, social, then everything else.
Book ninety minutes with the whole team, screens open, manager installed in advance. Do steps 1 and 2 together in the room. Assign step 3 as homework with a deadline and a named owner who checks it.
Patch on your schedule or on the attacker’s. Put a name and a recurring calendar entry against each month, initial the box when it is done, and keep this page where the team can see it. Set a documented cadence that fits your exposure; critical security patches do not wait for the calendar.
A vendor announcing an actively exploited vulnerability is not a monthly item. Define now who can authorize an emergency patch window, and how fast.
Take a backup you have actually verified, patch a staging copy first where one exists, and keep a written rollback step. Fear of breaking things is the most common reason systems go unpatched.
Internet-facing vulnerabilities can be scanned and exploited rapidly, sometimes within hours of disclosure, so critical patches need an out-of-cycle path. “Next quarter” is not one.
Both platforms leave important protections switched off, or behind a tier you may not have bought. Work down the column for the platform you run. Console paths verified 16 August 2026; admin consoles move things, so search the setting name if a path has drifted.
| # | The setting | Microsoft 365 | Google Workspace | Owner · date |
|---|---|---|---|---|
| 1 | MFA baseline | Entra ID > Overview > Properties > Manage security defaults | Security > Authentication > 2-step verification. Enforcement On; methods “Any except… text, phone call” | |
| 2 | Admin credentials & break-glass | Two or more cloud-only emergency accounts on passkey (FIDO2). Validate every 90 days | More than one super admin, separate daily accounts. Security > Authentication > Account recovery | |
| 3 | Anti-phishing preset Off by default | Threat policies > Preset Security Policies > Standard protection. Impersonation protection is OFF until you do this | Not applicable. Nearest equivalent: Gmail > Safety, and Security sandbox (Business Standard and above) | |
| 4 | Third-party app consent Open by default on Google | Enterprise apps > Consent and permissions. Confirm “Let Microsoft manage…” and enable the admin consent workflow | Security > Access and data control > API controls > Manage App Access. “Unconfigured third-party apps” defaults to allow everything | |
| 5 | Email authentication DKIM off by default on MS | Defender > Threat policies > Email authentication settings > DKIM. SPF -all. Custom domains do not sign until enabled | Apps > Gmail > Authenticate email. SPF ~all. Then DMARC p=none → quarantine → reject | |
| 6 | External sharing default | SharePoint admin > Policies > Sharing. Set File and folder links to “Only people in your organization” | Apps > Drive and Docs > Sharing settings. Confirm general access = Restricted; Access Checker = Recipients only | |
| 7 | External calendar sharing | Restrict to free/busy. Out of box, all users can invite anyone to view their calendar | Apps > Calendar > Sharing settings. Set external to “Only free/busy information” | |
| 8 | Prune administrators | Fewer than five Global Administrators; fewer than ten privileged assignments | More than one super admin, none used for daily work, none left signed in | |
| 9 | Log horizon | Audit (Standard) = 180 days. Entra logs 7 days free, 30 on P1/P2 | Most logs 6 months. Business tiers get no investigation tool; Email Log Search holds 30 days | |
| 10 | Backup decision | M365 Backup ($0.15/GB/mo, OneDrive/SharePoint/Exchange only), a third party, or accepted risk | No first-party backup exists. Third party, or accepted risk. Vault is not an archive |
Microsoft: Conditional Access, Intune and Defender for Office 365 P1 all arrive at Business Premium. Below it, several rows above are unavailable rather than unset.
Google: Context-Aware Access, the investigation tool, DLP and the security center all require Enterprise. No Business tier, including Business Plus, reaches them.
Education, not legal advice. Vendor console paths and defaults change without notice; verify in your own tenant. Paths and defaults as of 16 August 2026.
Fill this in now and keep a copy reachable when your systems are not: a wall, a wallet, a phone photo. The first hour sets the tone, and it is the worst time to start improvising.
Name, role, mobile number. Include an alternate for every person. Incidents do not check calendars.
One named person with authority to take systems offline, spend money, and engage outside help. A committee is not a decision-maker.
Disconnect immediately; if you cannot, CISA says power down to stop the spread. Rotate credentials, revoke sessions and tokens. Preserve logs and snapshots; do not wipe or rebuild before evidence is captured.
One voice for customers, one for staff, one for regulators or press. Silence is a choice with consequences; so is speaking early with the wrong facts.
Location, access method, who can restore, and when it was last successfully tested.
Technical partner, legal counsel, insurer, and the relevant authority. Establish these relationships before the incident, not during it.
Every action, with a timestamp and a name. It is the difference between a defensible response and one reconstructed from memory, and it is what regulators, insurers and your board will ask for.
This page is not about your organization. It is the one worth doing at a kitchen table, because the exposure it covers cannot be undone later: material absorbed into a trained model has no deletion request. The goal is not guilt. It is reducing what gets added from here, and closing the identity-fraud surface, which genuinely is reducible.
| Account / platform | Who runs it | Audience setting | Shows children? | Identifiers in captions | Action & date |
|---|---|---|---|---|---|
| Parent 1 social | |||||
| Parent 2 social | |||||
| Shared photo album | |||||
| Teen’s own accounts | |||||
| Grandparents / relatives | |||||
| School / team / club pages | |||||
Under “identifiers”, look for the combination that powers child identity fraud: full legal name, birthdate, school or hospital name, street, and a clear face. Captions add identity, school, date and location context. The photo itself can also carry biometric, impersonation or exploitation risk on its own.
A stranger gets friendly fast, moves things to images, then turns and demands money within hours. Three things have to land: you will not be in trouble, paying does not guarantee it stops and often leads to further demands, and the right move is to tell an adult and keep the messages.
Under the TAKE IT DOWN Act, signed 19 May 2025, covered platforms must remove reported non-consensual intimate imagery (including AI “digital forgeries”) and known identical copies within 48 hours of a valid request. The FTC enforces it and the compliance deadline has passed. This right is live.
Work down the column and take anything unresolved to counsel. Naming the statute turns a vague worry into a decision someone can make.
| Statute | Applies when, and what it requires | Exposure | Owner & date |
|---|---|---|---|
| Ley 39-2012 | Covered commercial operator collecting personal info from PR residents. Publish a clear, conspicuous policy; describe who data may be shared with. | Mismatch: up to $50,000. Otherwise DACO enforcement | |
| Ley 163-2026 | Unauthorized commercial or advertising use of an identifiable AI-generated or cloned likeness. Consent and exceptions apply. | $750–$20,000; $100k intentional; 1-yr clock | |
| Ley 111-2005 | Breach of covered data. Notice analysis turns on whether it was unencrypted or insufficiently protected. 10 days to DACO only. | $500–$5,000 per violation | |
| Ley 185-2024 | Defined social-network site or app allowing PR residents aged 18 or younger to register. Legal review required. | Reported up to $25,000 | |
| Ley 40-2024 | Contracted IT or communications service provider to the Government. Notify PRITS and the contracting entity within 48 hours. | Statutory duty | |
| Ley 5-1973 | DACO consumer-protection authority that can reach deceptive advertising. | Up to $10,000, each day separate | |
| Ley 207-2006 | Employee SSNs on identification cards and routinely circulated documents. | $500–$5,000 | |
| TAKE IT DOWN | Covered platforms. Remove reported NCII and known copies within 48 hours. | FTC enforcement | |
| EU AI Act Art. 50 | Output used in the EU. Transitional treatment for some existing systems to 2 Dec 2026. | Applying since 2 Aug 2026 | |
| CA SB 942, as amended by AB 853 | GenAI provider with over 1M monthly California users. AB 853 sets the 2 Aug 2026 operative date. | $5,000 per violation per day | |
| CA AB 2013 | Develop or substantially modify a GenAI system offered in California. | Disclosure duty |
As of 15 Aug 2026 we found no general cross-sector PR statute imposing AI-specific disclosure, risk-assessment, bias-audit or deployer duties on a private company merely for using AI. The AI-specific enactments cover four principal areas: elections, government, criminal deepfakes, likeness. Other law still applies. If someone sells you an AI compliance package for a local private-sector duty, ask them to name the statute.
Government clients differ: PRITS Carta Circular 2023-002 requires prior PRITS authorization before an agency integrates, acquires or contracts for AI development.
Education, not legal advice. Coverage under each statute turns on facts this table cannot establish. Several of these are weeks old. Confirm with counsel before acting.
Officers need not tell you that you may decline. Refusing alone is not suspicion (Bostick, 1991).
Anywhere. It will not stop a border search, but it preserves the objection.
Police stops only. Never at a port of entry.
Out loud. In Salinas (2013) a plurality allowed use of non-custodial silence where the privilege was not invoked.
| If you decline to unlock | In CBP’s own terms | Notes for me |
|---|---|---|
| US citizen | Not denied entry over an incomplete inspection; device may be detained. | |
| Green-card holder | Generally not “seeking admission” on return, but no authority settles refusal. Unsettled. | |
| Visa / ESTA | Refusal may be weighed in admissibility; inspection alone does not decide it. |
Ask for a CBP Form 6051D receipt. Detention ordinarily under 5 days; copies not kept past 21 days without probable cause.
Torres (1979): an ordinary nonstop island-to-mainland trip is domestic and does not itself trigger a border search. The bag check is agricultural (7 CFR Part 318).
Know-your-rights education, not legal advice. Much of this is unsettled and none accounts for your status or jurisdiction. Talk to a lawyer.
In a 2025 observational survey of 48,340 people across 47 countries, policy-contravening AI use was highest where generative AI was banned outright (67%) and lowest where no policy existed at all (33%). The design does not establish why the groups differed. A rule people route around may remove your visibility rather than the behaviour. Anchors are NIST AI RMF subcategories, which are voluntary and not law.
Which tools are allowed, for what, and who can add one.
The short list for your actual footprint.
Client identifiers, credentials, unreleased financials, health data, anything under NDA.
One accountable person plus an executive sponsor. Not a committee.
Who delivers it, to whom, how often.
Nothing reaches a client, regulator or the public without a named person checking it.
A no-blame route for “I pasted something I should not have.”
What AI vendors may do with your data; what your client contracts already say.
Accounts closed, data exported or deleted, integrations revoked.
Education, not legal advice. Two PR items are worth counsel time: unauthorized commercial or advertising use of an AI-generated or cloned likeness may fall under Ley 139-2011 as amended by Ley 163-2026, subject to consent and exceptions; and Ley 111-2005 breach notification can be triggered by credentials or employment evaluations pasted into an outside tool. As of 15 Aug 2026 we found no general cross-sector PR statute imposing AI-specific duties merely for using AI.
Not a full defence, and not a one-time fix. These are the changes with evidence behind them, ordered by effort. Removal in particular is maintenance: Consumer Reports found profiles reappearing weeks or months later.
Doing it yourself: 70% of profiles gone at four months, at no cost. The seven paid services averaged 35%, ranging from 4% to 68%; the $19.99 service beat several costing six times more. Consumer Reports, August 2024. Small non-random sample, explicitly not nationally representative.
Note: some removal services advertise on or partner with the people-search sites they claim to fight.
The Coalition Against Stalkerware warns that removing monitoring software, or making significant changes, may be detected by the abuser and could increase the abuse and harassment. It also deletes evidence you may need. Their guidance is to build a safety plan with a trusted survivor assistance program first, and to attempt removal only if you believe it is safe to do so.
National Domestic Violence Hotline: 1-800-799-7233, 24/7 and confidential · stopstalkerware.org · techsafety.org
Education, not legal advice. Menu paths and vendor practices change between software versions; verify on your own device. Figures as of 15 August 2026.
Everything in this workbook decays. Accounts accumulate, vendors change, software goes end-of-life, and the person who owned the calendar leaves. A short standing review is what turns a good week into a practice. Put it in the calendar before you close this page.
| Standing agenda | Q1 | Q2 | Q3 | Q4 |
|---|---|---|---|---|
| Admin access reviewed, removals executed | ||||
| Offboarding completed for every departure | ||||
| Vendor register updated, new vendors added | ||||
| Patch calendar signed off for the quarter | ||||
| Backup restored and verified | ||||
| End-of-life software flagged with a plan | ||||
| Staff emails checked against a breach index | ||||
| Payment & credential requests: second-channel rule rehearsed | ||||
| Incident plan still accurate, contacts current |
Mutiny Labs builds custom, security-first platforms and supervises them after launch: minimized attack surface, access designed around real roles, updates on our watch, one accountable partner. If you filled this workbook in and did not like the answers, that is a good reason to talk.
info@mutiny-labs.com · +1 888 449 4466 · mutiny-labs.com · privacy: mutiny-labs.com/privacy-policy.html