Las Vegas is a target-rich environment. The headlines go to the Strip — the 2023 casino breaches proved even billion-dollar security programs can fall to a single phone call — but attackers spend most of their time on smaller targets: dental practices with patient records, law firms with client files, property managers with resident data and payment flows. Smaller defenses, same valuable data.
Here is the checklist we use when we assess a new client's environment. Score yourself honestly.
Identity and access
1. Multi-factor authentication (MFA) everywhere. Email, Microsoft 365, VPN, banking, line-of-business apps. MFA blocks the vast majority of account-takeover attacks. If you check only one box on this list, check this one.
2. No shared logins. Every employee gets their own account. Shared credentials make it impossible to know who did what — and impossible to cleanly cut access when someone leaves.
3. Offboarding within hours, not weeks. When an employee departs, their accounts should be disabled the same day. Orphaned accounts are a favorite way in.
4. Least-privilege access. The front desk does not need admin rights. Neither does the office manager. Neither, honestly, do you.
Endpoints and email
5. EDR on every device — not legacy antivirus. Modern attacks are fileless and signature-less; traditional antivirus does not see them. Endpoint detection and response watches behavior and isolates compromised machines automatically.
6. Patching on a schedule. Most exploited vulnerabilities had patches available for months. Someone must own patching — operating systems, browsers, and the forgotten ones like firewall firmware.
7. Email filtering and DNS protection. Stop phishing links and malicious attachments before they reach the inbox.
8. Ongoing phishing training. Your team is your largest attack surface. Security awareness training with simulated phishing turns them into a detection layer instead.
Data and recovery
9. Backups that follow 3-2-1. Three copies, two media, one offsite/immutable. Ransomware crews hunt and encrypt backups first — immutability is what defeats them.
10. Tested restores. A backup you have never restored is a hope, not a plan. Test quarterly, and time it: that number is how long your business will be down.
11. A written business continuity plan. Who declares an incident? Who calls the insurer? What runs first? Deciding this during the fire is how an outage becomes a catastrophe.
Monitoring and awareness
12. Dark web monitoring. Employee credentials leak from third-party breaches constantly and are sold months before they are used. Early warning lets you reset passwords before attackers log in.
13. Someone watching the alerts. Security tools that nobody monitors are decoration. 24/7 eyes — in-house or through a partner — turn alerts into responses.
14. Cyber insurance that will actually pay. Insurers now require MFA, EDR, and tested backups. Misrepresenting your controls on the application is the fastest route to a denied claim.
15. An annual risk assessment. Environments drift. New SaaS apps appear, staff change, an old server quietly keeps running. Review yearly — regulated industries like healthcare should go deeper.
Scoring honestly
Most Las Vegas small businesses we assess check five or six of these boxes and assume they are covered because "we have antivirus and backups." The gap between that and fifteen is exactly where incidents happen — and closing it costs far less than one week of downtime.
Want a professional read on where you stand? Request an assessment — we will walk your environment against this list and show you precisely what is exposed, no obligation attached.

