Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
GETTING STARTEDHIGH-LEVEL STARTER

Your first 14 days with the Top 10

A high-level starting sequence for resource-constrained DIB teams — the handful of highest-leverage moves, in order. Each links into the full practice and cloud setup guides when you’re ready to go deeper.

How to use this

Do these in order; don’t try to do everything at once. Two weeks in, you’ll have closed the biggest doors and be ready to build a full 30/60/90-day roadmap. For a plan tailored to your answers, use the 30-day plan builder.

1
Days 1–2

See what you have and lock the front door

Turn on phishing-resistant MFA for admins

A stolen admin password is the fastest path to a full takeover. Start here.

IT-01 guide

Start one asset & account inventory

You can't protect what you can't see. One living list is the foundation for everything after.

IT-02 guide
2
Days 3–5

Close the doors attackers use first

Review every remote-access pathway

Vendor and remote access is a favorite way in — broker it, log it, time-box it.

Remote access

Enable logging on identity and email

You can't investigate what you never recorded. Turn on audit logs now, not after an incident.

Cloud setup guides
3
Days 6–10

Prove you can recover

Restore-test your most critical system

An untested backup is only a hope. One real restore tells you where you actually stand.

IT-09 guide

Turn on vulnerability scanning

Most breaches use known, unpatched holes. Start scanning and read the top ten findings.

IT-06 guide
4
Days 11–14

Set the pattern and sequence the rest

Sketch first-pass network segmentation

Containment keeps one breached device from becoming ten. Draw the zones you need.

IT-05 guide

Build your 30-day plan

Turn these first moves into an owned, sequenced roadmap with owners and dates.

Plan builder