This page is a resource directory. It is not the mistakes list, and it is not the first-hour incident checklist.
It's written for a Houston business of about 5 to 50 people. CISA (the Cybersecurity and Infrastructure Security Agency) is the U.S. government team that publishes free cybersecurity guidance. Most of what a typical private firm can use this week is a page you can read and hand to your IT host. A few of the free scanning services are not open for just anyone to sign up.
What can a Houston small business get from CISA this week? Free guides, a public list of flaws attackers are already using, and official places to report. Not a city cyber help desk, and not automatic enrollment in vulnerability scanning.
What you can use, and what you should not sign up for
Start with the pages written for any business. The Small and Medium Businesses page is the front door. The guides below are free, and you don't need an account.
Cyber Hygiene scanning is different. On Cyber Hygiene Services, CISA describes two no-cost scans:
- Vulnerability scanning checks internet-reachable addresses for known weak spots and sends reports.
- Web application scanning checks public websites for weak settings.
The same page says who may enroll: U.S. federal, state, local, tribal, and territorial governments, and public and private sector critical infrastructure organizations. Critical infrastructure is CISA's term for organizations that run essential services. It does not mean every private company in Houston.
If you run a typical shop, firm, contractor, or clinic and you're not in that group, don't treat the signup email as an open door. If you are in that group, the page says to email vulnerability@cisa.dhs.gov with the subject line "Requesting Cyber Hygiene Services." If you're not sure, use the guides. Don't wait on a scan that may not be offered to you.
CISA's No-Cost Cybersecurity Services and Tools catalog is aimed at critical infrastructure partners and state, local, tribal, and territorial governments. Its "start here" list includes Cyber Hygiene enrollment. Read who each item is for. Don't enroll from the title alone.
While you're on the Cyber Hygiene page, use the publications it points to if you're not enrolling. One of them is the CISA CPG Checklist. CPGs (Cybersecurity Performance Goals) are a short list of baseline practices. The checklist is a worksheet, not a scan of your network.
Five CISA pages, and what to do on each
Work through these in order. One sitting is enough. If you don't know an answer, leave it as unknown.
1. Secure Our World
Open Secure Our World. It's a public campaign with four actions: recognize and report phishing, use strong passwords, turn on MFA, and update software.
Phishing is a message that tries to get someone to open a bad attachment, click a fake link, or hand over a password. MFA (multi-factor authentication) means a password plus a second step, such as an authenticator app or a security key.
Sit down with the people who pay bills and open email, and read the four actions out loud. Ask each person which of the four is already true on their work accounts. Write yes, no, or unknown. You're not installing anything on this pass.
2. Secure Your Business
Open Secure Your Business. It turns those four actions into a business list, and the short version is also on Four Cybersecurity Essentials for Businesses: train people to avoid phishing, require strong passwords, require MFA, and update business software.
The page then adds logging (a record of activity so someone can see odd sign-ins), backups, and encryption (scrambling data so a stolen copy is not readable). It also says to keep a written incident response plan and to report incidents.
On this pass, mark the four essentials only. Send the "not yet" items to your IT host along with the eight renewal questions. For proof that MFA is actually on, use the 20-minute MFA coverage drill. For backups, use the 15-minute backup test. Don't try to finish logging, encryption, and a full response plan the same afternoon.
3. Cyber Guidance for Small Businesses
Open Cyber Guidance for Small Businesses. This one is for the owner, not the firewall.
It asks you to treat security as a regular business topic, to name a security program manager, and to review a written incident response plan. That person doesn't have to be an IT expert. The job is to keep the list moving and to tell you what's stuck.
Write one name next to "security program manager." If that person is you, say so. Ask them to bring you a one-page plan later: who to call, what to unplug, and where the report links below are printed. The first hour of an actual incident is covered in First 60 minutes after a cyber incident. Don't rewrite that checklist on this page.
4. Known Exploited Vulnerabilities catalog
Open the Known Exploited Vulnerabilities catalog. CISA keeps it as the public list of vulnerabilities that have been used in real attacks. A vulnerability is a flaw in software or a device. The catalog is a way to decide what to patch first. It is not a scan of your office.
Ask your IT host one question: "Which of our internet-facing products are on this catalog, and what is the patch date?" Internet-facing means a person on the public internet can reach it, such as email, a VPN, a firewall, or a remote login page. You don't need to read every row. A dated answer is the result, including "none that we could match."
5. StopRansomware.gov
Open StopRansomware.gov and the #StopRansomware Guide. Ransomware is software that locks files and asks for payment. The site is the U.S. government's main ransomware shelf. The guide has a prevention side and a response side.
On a calm week, use the prevention side only. Confirm that you have a backup that isn't sitting on the same office network, that someone has opened a restored file, and that remote desktop isn't open to the public internet. The ransomware protect checklist is the local worksheet for that pass.
If something is already wrong, don't start a new project on this site. Use the first-hour checklist, then the reporting doors in the next section.
What is actually local, and what is federal
None of the City of Houston or Harris County pages checked for this article is a cyber help desk for a private firm. The pages below are the official ones that came back as a live page. Use each one for what it actually is.
Federal, and usable from Houston. The CISA guides above. NIST (the National Institute of Standards and Technology) publishes the Cybersecurity Framework 2.0: Small Business Quick-Start Guide (SP 1300, PDF). NIST describes it as a supplement for small and medium businesses that have a modest plan or none. It is not a replacement for the full framework. Download it and answer one question this month. Don't try to score the whole document this week.
The FTC (Federal Trade Commission) Cybersecurity for Small Business page is the plain-language companion. Two jobs it spells out that the CISA short list does not:
- On the office router, change the default password, turn on WPA2 or WPA3 (the current Wi-Fi protection settings), and keep guest Wi-Fi off the business network.
- If you send email from your own domain, ask the email provider whether SPF, DKIM, and DMARC are on. Those are settings that make it harder for someone else to send mail that looks like it came from your business. Ask the provider to show you the settings. Don't guess.
Texas, not a Houston office. The Texas Department of Information Resources publishes Cybersecurity Best Practices for Non-Profits and Small Businesses (PDF). It is a tip sheet: know what data you keep, write a short policy, use MFA, train staff, update software, and give each person their own account. It is not a state incident-response desk for your firm. Download it. Don't expect a technician to come to the shop because you opened the PDF.
City of Houston. Administrative Policy 8-2 is the City's own cybersecurity program for city information systems. It is an internal policy, dated on the page as October 17, 2014. It is not a service you enroll in.
Harris County. Harris County Universal Services — Information Technology says the county provides information security and technical support to county employees. That is county IT, not a public help line for private businesses.
FBI Houston. The FBI Houston field office is the local federal office for southeastern Texas. The page says you can report suspicious activity and crime 24/7 at (713) 693-5000 or at tips.fbi.gov. That number is for the field office, not a substitute for the written complaint form below. Use the field office page if you need to confirm the current number.
Start here, in this order
- Read Secure Our World and mark the four actions.
- Mark the four essentials on Secure Your Business.
- Name a security program manager from Cyber Guidance for Small Businesses.
- Send the KEV catalog question to your IT host.
- Save the Texas DIR PDF and NIST SP 1300. Skim. Pick one item, not the whole stack.
- Print the report links. If something is wrong today, stop and use the first-hour checklist.
Done means the table is filled in. It does not mean every gap is closed. A dated "unknown" is a real answer.
Where to report
This section only points at the forms. It is not the first-hour procedure. Steps for the first hour, including what not to wipe, are in First 60 minutes after a cyber incident.
- CISA. Start at cisa.gov/report, which opens CISA's incident reporting form.
- Ransomware. Report Ransomware says a victim can report to the FBI, CISA, or the U.S. Secret Service, and that one report is shared with the other agencies. Use that page for the current options. This article is not a filing instruction.
- FBI internet-crime complaint. File at the Internet Crime Complaint Center using the complaint form. The Houston field office page is the local contact, not a second copy of the same walkthrough.
- Scams and impostor email. The FTC page says to report phishing and business-email impostors at ReportFraud.ftc.gov.
Write the confirmation number next to the table. If email is down, the printed links still work from a phone that isn't on the office network.
One-page resource card
Copy or print this table. Leave blanks as unknown. Don't guess.
| # | Step | Where | Done? | Date | Note |
|---|---|---|---|---|---|
| 1 | Four Secure Our World actions marked | Secure Our World | Y / N | ||
| 2 | Four business essentials marked | Secure Your Business | Y / N | ||
| 3 | Security program manager named | Small-business guidance | Y / N | Name: | |
| 4 | KEV question sent to IT host | KEV catalog | Y / N | ||
| 5 | Texas tip sheet saved | DIR PDF | Y / N | ||
| 6 | NIST quick-start saved | SP 1300 | Y / N | ||
| 7 | Report links printed | CISA report · IC3 | Y / N |
Card date: YYYY-MM-DD · Filled by: · Security program manager:
Save it as cisa-resource-card-YYYY-MM-DD next to your IT-host renewal card.
Related guides
- First 60 minutes after a cyber incident — the hour this page does not rewrite
- Ransomware protect checklist — the calm-week prevention pass
- Ask your IT host these 8 questions — proof to request before you renew
- Run a 20-minute MFA coverage drill — show that the second step is real
- Test your backup in 15 minutes — open a restored file
- Resources — CISA and NIST references
Educational content only — not legal, insurance, or compliance advice.