The Security Checklist for Consultants (Your Own Practice)
Search for “security checklist for consultants” and you’ll find checklists for hiring security consultants. This is the other one — the checklist for consultants securing their own practice, whether you’re solo or running a five-person firm.
Consultants have a specific risk profile: you hold other companies’ confidential information — strategy docs, financials, credentials clients probably shouldn’t have emailed you — and a breach doesn’t just cost you data, it costs the client relationships that are the business. Increasingly, enterprise clients also send security questionnaires before signing; the cyber-insurance readiness guide covers those in depth, and this checklist keeps you honest on the answers.
Tier 1 — Do this week (solo or firm)
- MFA on your email, then banking, then everything else. Your email resets every password you own — it’s the keys to the practice.
- A password manager, even solo. Unique passwords per client portal, per tool. When you hire, it becomes shared vaults instead of “the spreadsheet.”
- Turn on full-disk encryption — FileVault (Mac) or BitLocker/Device Encryption (Windows). A consultant’s lost laptop should be a hardware loss, not a client-notification event.
- Auto-updates on, OS and browser.
- A real backup with version history, separate from your sync folder — sync is not backup.
Tier 2 — Do this month
- Separate the roles: stop working day-to-day in the account that owns your domain, billing, and admin consoles. One break-glass admin login per platform, stored in the password manager.
- Client-data hygiene: one folder (or shared drive) per client; access granted per engagement; an end-of-engagement step that returns or deletes what you no longer need. Data you don’t hold can’t leak — and “we delete client files 90 days after engagement close” is a sentence clients love reading.
- Email authentication (SPF, DKIM, DMARC) on your domain — consultants get impersonated because invoice fraud pays. Your email provider has a copy-paste guide; it’s DNS records, not a project.
- Stop receiving credentials by email. When a client needs to hand you a login, use your password manager’s secure-send feature or their SSO guest access. Credentials in your inbox become your breach and theirs.
- A one-page incident sheet: who you’d call, which clients you’d have to notify, where the backups are.
Tier 3 — When you hire (or subcontract)
- Company-owned accounts from day one — work email and tools under your domain, never personal Gmail “just for now.”
- The access inventory: one page per person listing everything they can reach. It turns departures into a one-hour teardown instead of a month of surprises.
- Contractor access is scoped and expiring: per-engagement folder access, guest accounts where the platform supports them, a calendar reminder to revoke on the end date.
- Offboarding is written down before you need it.
What consultants can skip (usually)
- A VPN service — if your work lives in reputable cloud tools over HTTPS, a consumer VPN adds little for the client-confidentiality risks that matter here. (Public-Wi-Fi habits matter less than your MFA and disk encryption.)
- A hardware firewall for a laptop-based practice.
- Enterprise DLP/SIEM — at this size, the folder-per-client discipline above outperforms them per dollar.
The client-questionnaire dividend
Everything above maps one-to-one onto the security addendums enterprise clients send. Do the checklist once, screenshot the evidence as you go, and the next questionnaire is an afternoon instead of a scramble — and “yes, and here’s the evidence” wins deals against consultants who answer “we take security seriously.”
Run the 10-Minute Security Check to turn this into a prioritized list for your specific setup.