First 14 Days Action Plan
Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.
Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.
Purpose
The first two weeks, taken from the practices in the first three stages of the recommended sequence. These are the moves that close the largest doors before anything else is attempted.
How to use it
Assign an owner and a target date to each line before you start. Two weeks in, run the validation checks in the final section — an action nobody validated is not finished.
First 24 hours
Nothing here requires procurement. All of it is confirmation, discovery, or switching something on that you already own.
- List accounts with admin or remote access
- Enable MFA for those accounts today
- Name an inventory owner
- Pull existing lists from MDM, identity provider, and procurement
- Find default and vendor-set passwords on reachable devices
- List every shared/generic login in use
- Name an inventory owner
- Collect existing vendor and project asset lists
- Identify your most sensitive systems and where CUI lives
- Confirm management interfaces are off the user network
- Map every connection between the business and OT networks
- Flag any direct, unfiltered IT-to-OT paths
- Inventory every remote and vendor access path into OT
- Disable any unknown or always-on tunnel
- List systems already past end-of-support
- Flag any that are internet-facing
- Confirm scanning covers internet-facing systems
- Check for any known-exploited vulnerabilities already public
- Cross-reference the OT inventory against known-exploited and vendor advisories
- Flag any internet-reachable OT device
Owner and date
| Action | Owner | Target date | Done |
|---|---|---|---|
By day 14
- Enroll every administrator on a phishing-resistant method and stop accepting SMS as an admin factor
- Write down and test the break-glass procedure before you tighten enforcement further
- Merge the endpoint, identity, and procurement exports into one record and mark the rows that appear in only one source
- Flag every device with no owner and every account with no matching employee
- Change the default and vendor-set passwords you can safely change in the next approved maintenance window
- Confirm break-glass access exists, is documented, and has been tested against an identity or network outage
- Walk down one production line and record make, model, firmware, connectivity, and criticality with the operators
- Reconcile that line against the vendor and project documentation and investigate anything that appears in only one
- Confirm management interfaces are unreachable from the standard user network and fix any that are
- Move high-risk devices — legacy systems, IoT, guest Wi-Fi — off the general user segment
- Map every connection between the business and OT networks, including forgotten links, cellular modems, and vendor tunnels
- Close or broker the riskiest direct path in an approved window, with a tested rollback
- Disable any remote pathway you cannot identify an owner and a business reason for
- Route the highest-risk remaining pathway through a brokered jump host with strong authentication
- Confirm no internet-facing system is running unsupported software; isolate anything that is
- Disable the legacy protocols you can turn off without a project — SMBv1, TLS 1.0/1.1, basic authentication
- Run an authenticated scan across endpoints and servers and confirm it covered the full inventory
- Check your estate against the known-exploited vulnerability catalogue and remediate those findings first
- Cross-reference the inventory against vendor advisories and the known-exploited catalogue, and rank by exposure and process impact
- Apply compensating controls — isolation, access restriction — to the worst findings you cannot safely patch yet
Owner and date
| Action | Owner | Target date | Done |
|---|---|---|---|
Validate before you call it done
The first validation check for each practice in scope. If the check has not been run, the practice is not deployed.
| Practice | First validation check | Result | Date |
|---|---|---|---|
| IT-01 | Attempt sign-in with password only on a test account — it must fail. | ||
| IT-02 | Pick ten devices from the network at random; all ten must appear in the inventory with an owner. | ||
| OT-01 | Pick a production device and confirm it no longer uses a default or vendor-set password. | ||
| OT-02 | Pick five random devices on the floor; all five must appear in the inventory. | ||
| IT-05 | From a standard user device, attempt to reach a server-zone or management interface — it must be blocked. | ||
| OT-03 | From a business-network host, attempt to reach an OT controller directly — it must be blocked. | ||
| OT-06 | Attempt to reach an OT device remotely without going through the jump host — it must fail. | ||
| IT-03 | Confirm no internet-facing system is running unsupported software. | ||
| IT-06 | Confirm the last authenticated scan actually covered the full asset inventory, not a subset. | ||
| OT-05 | Confirm every high-risk OT vulnerability has either an applied patch or a documented compensating control. |
Limitations
Nothing on this list should be actioned on a live operational-technology system without the process owner's agreement, an approved maintenance window, a tested rollback, and a safety review. Where a security action conflicts with safe operation, the safe operation wins and the control is compensated instead.
This is independent educational material. It supports planning and evidence collection; it does not establish compliance with NIST SP 800-171, DFARS 252.204-7012, CMMC, export-control obligations, or any contract requirement, and it is not an assessment. Tailor every item to your own technical, operational, contractual, regulatory, and safety requirements.
Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-first-14-days-action-plan to keep filenames consistent across your team.