BLACKBOOK Self-Assessment · 104 controls · about an hour

How exposed are you? Score it.

The BLACKBOOK is a workbook: thirteen chapters of procedures, each ending in a score. This is the scores without the procedures. Mark each control 0, 1, or 2. The grade calculates as you go. Nothing is sent anywhere; the page keeps your answers in your browser only.

Household or small business. Score every adult and every device, or every employee and every account that touches money or customer data.

Household · small businessThe BLACKBOOK Self-Assessment104 controls, 0/1/2 scoring, an hour. You are here. Defense contractor · any businessNIST 800-171 / SPRS Self-Assessment110 requirements, DoD point values, the score you would post to SPRS. Validated and signed by a CISO on request.

Two rules

Score what is true today, not what is planned or purchased. A tool you own but have not configured scores 0.

If anyone in scope is uncovered, the maximum is 1. One adult without a password manager, one laptop without a backup — attackers find the uncovered one.

0 = not done · 1 = partial, or not for everyone · 2 = done everywhere it applies
0 / 208 0%
Not scored

3Passwords and Password Managers

Chapter score 0 / 16

Some of your passwords are already in criminal hands; what matters is whether a stolen one gets an attacker anything. Unique passwords in a manager plus a hardware key or passkey on email and money accounts make the answer no. The steps are Bitwarden's; any manager meeting the Chapter 2 criteria works the same way.

3.1
Password manager installed on every device, for every adult
3.2
Passwords imported; browser saving off and cleared
3.3
Vault protected by hardware key + authenticator; recovery code printed
3.4
Reused and weak passwords replaced; security questions randomized
3.5
Hardware key or passkey on email and money accounts, two keys each
3.6
Recovery envelope stored and its location recorded; emergency access set
3.7
Breach monitoring active for every household address
3.8
Sessions and connected apps audited within the last year

4AI Social Engineering, Email Threats, and Social Engineering

Chapter score 0 / 16

Social engineering was always the cheapest attack; AI made it the best one. The tells you were taught — bad grammar, a voice that sounds off — are gone. Language models write flawless, personalized email; a few seconds of audio clones a voice that passes a phone call; real-time video replacement runs on consumer hardware. What remains is structure: urgency, secrecy, authority, and a change in where money, codes, or access go. Any two together is an attack until verified. The defense is a habit, and the procedures below install it.

4.1
Callback rule written and posted; known-good number list built
4.2
Family codeword set and known by every member
4.3
MFA prompts denied unless self-initiated; codes never read out
4.4
Links, attachments, QR codes, and search results handled by the rules above
4.5
Household knows how to report phishing and texts
4.6
Voicemail and public audio/video minimized
4.7
Annual briefing done, with no-blame rule stated
4.8
Business: written payment-change and callback procedure (Chapter 6)

5Keeping Your Family Cyber-Safe While Working, Learning, and Socializing from Home

Chapter score 0 / 16

The home is an office, a school, and a social venue on one network, and the attacker needs only the weakest of the three. Separate the network, separate the devices, and give every person a rule they can follow without you. Router menus differ by brand; the settings below exist on every current router — use the search box in the router's app or admin page if a name differs.

5.1
Router admin password changed; auto-update on; WPS, UPnP, remote management off; WPA3
5.2
Guest and smart-device networks in place; smart devices moved onto them
5.3
Work and family devices and accounts separated; screen locks set
5.4
Children's accounts under parental controls; no identifying usernames; location limited
5.5
Blame-free rule stated to every child this year
5.6
Parents' devices set up; recovery contacts exchanged; codeword agreed
5.7
Shared logins in the manager; rotated on every departure
5.8
Backups exist in two places and were test-restored this year

6Tips for Fraud Prevention

Chapter score 0 / 16

Fraud is a conversation, not a hack. Wire and closing fraud, investment and 'pig-butchering' schemes, romance, grandparent, government-impersonation, tech-support, invoice, and payroll-diversion fraud all end the same way: you send money to a destination you did not verify. Fix the last step and the story does not matter. The procedures below put the controls in place; Chapter 4 covers recognizing the approach.

6.1
Money-movement rule adopted (written and signed for a business)
6.2
Transaction, login, and change alerts on every account, to the alert address
6.3
Credit frozen at Equifax, Experian, TransUnion, and ChexSystems for every adult
6.4
IRS IP PIN in place for every filer
6.5
Carrier port-out/SIM lock on; verbal passwords at bank and carrier
6.6
Checks minimized; check alerts or Positive Pay on
6.7
Elderly relatives and the household briefed; second-person rule in use
6.8
Recovery steps known; the Emergency Contacts page filled in

7Tips for Cyber Protection While Traveling

Chapter score 0 / 16

Travel removes every protection that depends on being home and adds hostile networks, physical loss, border inspection, and a public announcement that the house is empty. Carry less, encrypt everything, connect through your own hotspot or VPN, and post about the trip after you are back. Run the three procedures in order: before, during, after.

7.1
Devices updated, backed up, and remotely locatable before departure
7.2
Laptops encrypted; VPN installed and tested; Wi-Fi auto-join off
7.3
Travel notices, alerts, carrier lock, and paper contacts in place
7.4
Hotspot or VPN for every connection; own charger only
7.5
Devices never unattended and unencrypted; powered off when stored
7.6
Border plan made; passcode used at checkpoints
7.7
Post-trip session and statement review done within a week
7.8
High-risk trips use clean loaner devices, wiped on return

8Securing Your Email Accounts

Chapter score 0 / 16

Email is the master key: every other account resets through it. Harden every account you own in the same order — strongest sign-in, recovery you control, sessions and apps you recognize, no forwarding you did not create. Paths are as each provider's help pages stated them in September 2026; menus move, so search the settings page for the term if a step has changed. Do 8.1 once, then the section for each provider you use.

8.1
Every account: unique password, printed recovery codes, protected recovery email and phone
8.2
Gmail hardened (8.2)
8.3
Outlook.com / Hotmail hardened (8.3)
8.4
iCloud Mail hardened (8.4)
8.5
Yahoo / AOL hardened (8.5)
8.6
Proton hardened (8.6)
8.7
Forwarding, filters, rules, and delegates checked on every account
8.8
Sessions and connected apps reviewed on every account

9Securing Your Mobile Devices

Chapter score 0 / 16

Your phone is your second factor, your wallet, and your password vault. Settings track the operating-system version, not the model, so this chapter is organized by platform. First rule: run the current OS with automatic updates. Second: retire any device that no longer receives security updates from anything touching money or email; no setting below can save an unpatched phone.

9.1
Current OS; automatic updates on; security patch within 90 days
9.2
6+ digit or alphanumeric lock; short auto-lock; sensitive lock-screen access off
9.3
Theft protections and remote locate/lock on and tested
9.4
Advanced Protection / Auto Blocker / Stolen Device Protection on
9.5
Encrypted backup on; recovery code stored
9.6
App permissions reviewed; privacy report read
9.7
SIM PIN set; sideloading off; Play Protect on
9.8
Unsupported devices retired from money and email

10Securing Your Social Media Accounts

Chapter score 0 / 16

Social media is where attackers do their research and where they impersonate you afterward. Your posts supply security-question answers, voice and video for cloning, travel dates, and the names of your children and your assistant; the account itself, once taken, is used to defraud everyone who trusts you. Lock it like a bank account and post like an intelligence officer: assume the adversary is reading.

10.1
Unique password and app/key two-factor on every social account; dormant accounts closed
10.2
Sessions and connected apps reviewed on every platform this year
10.3
Personal accounts private; phone/email discoverability off; location off
10.4
Tagging, messaging, and friends-list visibility restricted
10.5
Business pages: two or more admins with 2FA; ownership held by the business
10.6
Household follows the posting rules above
10.7
Followers and friends pruned
10.8
Household knows how to report impersonation and verify DM requests

11The Home Firewall

Chapter score 0 / 16

Your router is not a firewall. A consumer-grade edge device — Firewalla at home, a Ubiquiti UniFi gateway in the office — catches the basics: known-bad destinations, DNS filtering, segmentation, tracker blocking. What turns it into a defense is the rest of the stack behind it and someone watching.

11.1
Firewall appliance in place at the edge; provider box in bridge mode
11.2
Admin password changed; remote admin off; auto-update on; inbound deny-all; threat block and IPS on
11.3
DNS filtering for every network; bypass blocked
11.4
Four networks segmented with rules; devices moved
11.5
VPN server in use; no port forwards remain
11.6
Alarms and notifications on; MSP console (and GOLEM feed) if multi-site; monthly review in place
11.7
Subscription and end-of-support dates on the calendar
11.8
External scan run this year; all closed

12Securing Your Computers

Chapter score 0 / 16

Most household compromises still start on a laptop: a download, a browser extension, a saved password, an administrator account used for email. The controls are the same on Windows and Mac — automatic updates, a standard account for daily use, full-disk encryption, real endpoint protection, a hardened browser, and a screen that locks. I put every computer I am responsible for under NinjaOne with SentinelOne, because those two things together make this chapter automatic: patches, protection, and backups happen without anyone remembering, and as a virtual CISO I can look at any machine remotely and know it is handled — the automation is the point, not a person watching. If you are doing it yourself, the steps below get you most of the way.

12.1
Automatic updates on for OS and applications; unused software removed
12.2
Daily use on a standard account; admin reserved for installs
12.3
Full-disk encryption on; recovery key in the envelope
12.4
EDR (managed) or the hardened built-in floor on every computer; tamper protection on
12.5
Browser extensions pruned; blocker and enhanced protection on; banking profile separate
12.6
Screen lock within 5 minutes; remote access services off
12.7
Backups running and verified (Chapter 13)
12.8
Retired machines erased, not donated with data

13Backups and Ransomware Recovery

Chapter score 0 / 16

Ransomware works because backups fail: they are connected when the encryption runs, they were never tested, or they do not exist. The rule is 3-2-1 — three copies, on two kinds of media, one of them off-site and either offline or immutable (cannot be altered or deleted for a set period even by you). A phone backup and a laptop's cloud sync are not that. In the reference stack, NinjaOne runs the backups so that the copy exists, is versioned, and is restore-tested without anyone remembering; the steps below do the same by hand.

13.1
Every phone backing up to an encrypted cloud backup
13.2
Local backup drive in use and kept offline between backups
13.3
Cloud backup service with versioning (or NinjaOne backup) on every computer
13.4
Vault, email, firewall config, and recovery material backed up
13.5
Restore tested this year from each copy
13.6
Business: full-machine restore tested and timed
13.7
Recovery order known; no one will pay before calling
13.8
Backups cover every computer in the house, not just one

14Reducing Your Digital Footprint

Chapter score 0 / 16

The preface described how an attacker starts: not at your firewall but at Spokeo. People-search sites, data brokers, public records, and your own social media supply the address, the phone number, the relatives, the neighbors, the car, the mortgage, and the security-question answers — assembled in minutes, now by an agent. You cannot erase yourself. You can make the dossier thin, stale, and expensive to build, which is what sends an automated attacker to the next name. This is the work Gingerbread does continuously for Monadnock Cyber clients; the steps below are the manual version, and they are worth doing once even if you then hand it off.

14.1
Search done for every family member; findings recorded
14.2
Opt-outs filed with the major people-search sites and syndicators
14.3
Google 'Results about you' alerts and removals set
14.4
Source records reduced where possible; WHOIS privacy on
14.5
Unused accounts closed; alert-only email and secondary number in use for new sign-ups
14.6
Social media locked down (Chapter 10)
14.7
Quarterly re-check scheduled, or removal service / Gingerbread engaged
14.8
Public and private identities separated for anyone with a public profile

15Protect Your Office

Chapter score 0 / 16

A small business is attacked the same way a household is — through a person, a password, a payment, or a patch — with two differences: the attacker's payoff is larger, and the business has obligations a family does not (customers, regulators, an insurer, employees who can be fooled). The eight procedures below are the defensible minimum for a firm with no security staff. They are also, not by coincidence, most of what a cyber insurer now asks you to attest to. This is the checklist I run for my own office, and the one a Monadnock Cyber virtual CISO runs with a client.

15.1
MFA enforced for all; admins separate with hardware keys; break-glass account in the safe
15.2
SPF, DKIM, and DMARC at p=reject
15.3
Every endpoint under RMM + EDR; mobile managed
15.4
Written onboarding and same-day offboarding; quarterly access review signed
15.5
Dual control and callback on payments, in writing; bank dual approval on
15.6
Computers, servers, and the M365/Workspace tenant backed up immutably and restore-tested
15.7
Insurance attestations true and evidenced; audit logs retained; notification duties written
15.8
One-page incident plan printed; tabletop and phishing simulation done this year

Your result

Grade:

Answer the controls above. The grade and the chapters to work first appear here.

The printable Self-Assessment Edition and the full BLACKBOOK are free to registered readers. Registering means we may email you about your assessment and BLACKBOOK updates; reply "stop" at any time. We do not sell or share your details.