ORIGINAL PUBLIC RESOURCE · 2026

Lebanon Cybersecurity Executive Readiness Checklist 2026

This checklist is a practical self-assessment for Lebanese companies that want to understand where security work should start. It is not a certification, compliance opinion, or industry benchmark. Its purpose is to help leadership and technical teams turn cybersecurity into a visible list of controls, evidence, owners, and next actions.

How to use this checklist

Review every item with the person who owns the system. For each item, record the evidence, owner, last verification date, and next action. The optional score below is only a Think Unlimited self-assessment aid; it is not a certification or external benchmark.

0 — Not establishedNo reliable evidence that the control exists.
1 — PartialThe control exists but is incomplete, informal, or not recently verified.
2 — VerifiedThe control is implemented and supported by current evidence.

1. Identity and privileged access

  • List every administrator, owner, super-admin, domain administrator, cloud administrator, billing administrator, advertising-account administrator, and emergency account.
  • Require multi-factor authentication for high-risk accounts and document the recovery method.
  • Remove or disable former-employee, dormant, test, and vendor accounts that no longer need access.
  • Separate normal daily accounts from privileged administrator accounts where practical.
  • Review active sessions, recovery emails, recovery phone numbers, forwarding rules, delegated access, API tokens, and connected applications.
  • Record who can change DNS, website hosting, cloud infrastructure, payment settings, customer databases, and advertising accounts.

2. Internet-facing assets and attack surface

  • Maintain an inventory of public domains, subdomains, websites, APIs, VPNs, remote-access services, admin panels, cloud endpoints, and exposed storage.
  • Confirm that every public service has a business owner and a technical owner.
  • Remove abandoned test systems, old staging sites, expired campaigns, unused subdomains, and legacy services.
  • Track certificate expiry, DNS changes, exposed ports, and internet-facing administrative interfaces.
  • Identify which public systems would create the largest business impact if compromised or unavailable.

3. Web applications and APIs

  • Document authentication, authorization, session handling, password reset, file upload, payment, and administrative workflows.
  • Test whether users can access data or actions outside their intended permissions.
  • Review API authentication, object-level authorization, rate limits, error handling, secrets, and sensitive data exposure.
  • Confirm that dependencies, plugins, frameworks, and server components are patched according to risk.
  • Use authorized penetration testing when exploitability or business logic needs to be validated beyond automated scanning.

4. Cloud and SaaS configuration

  • Identify every production cloud account, tenant, project, subscription, and business-critical SaaS platform.
  • Review privileged roles, service accounts, API keys, OAuth apps, public storage, network exposure, and logging.
  • Ensure billing, identity, storage, backups, and production administration are not dependent on one uncontrolled personal account.
  • Document which third parties or contractors have cloud access and how that access is removed.
  • Verify that critical logs are retained long enough to investigate an incident.

5. Email, endpoints, and staff access

  • Protect business email with multi-factor authentication and strong recovery controls.
  • Review endpoint protection, operating-system patching, disk encryption, screen-lock policy, and local administrator rights.
  • Train staff to verify unusual payment, credential, document-sharing, and password-reset requests.
  • Create a simple process for reporting suspicious email, lost devices, account compromise, and unexpected login prompts.
  • Ensure sensitive business data is not routinely stored on unmanaged personal devices without approved protection.

6. Vendors and third-party access

  • List vendors that can access production systems, customer data, email, cloud infrastructure, websites, advertising accounts, finance systems, or support tools.
  • Record the access method, owner, business purpose, and expected end date for each privileged vendor relationship.
  • Use named accounts rather than shared credentials where possible.
  • Require prompt notification of security incidents that could affect your organization.
  • Review and revoke access when a project, contract, or employment relationship ends.

7. Monitoring and detection

  • Identify the minimum signals needed to investigate account takeover, unauthorized admin changes, malware, cloud misuse, web attacks, and unusual data movement.
  • Centralize or preserve logs for high-value systems so that one compromised device cannot erase the only evidence.
  • Define which alerts require immediate escalation and who receives them.
  • Review false positives and missed incidents so detection rules improve over time.
  • Use AI for correlation or summarization only where the underlying evidence remains accessible to human reviewers.

8. Incident response

  • Name the people who can isolate systems, revoke credentials, contact providers, preserve evidence, approve customer communications, and make business-continuity decisions.
  • Maintain an incident contact list outside the systems that might be compromised.
  • Create first-hour procedures for account takeover, ransomware, exposed data, website compromise, and cloud-admin compromise.
  • Preserve logs and evidence before destructive cleanup when it is safe to do so.
  • Run at least one tabletop exercise so the response plan is tested before a real incident.

9. Backup, recovery, and resilience

  • Identify which systems and data must be restored first after a serious incident.
  • Maintain backups that are protected from the same credentials used for normal production administration.
  • Test restoration instead of assuming a successful backup job guarantees recoverability.
  • Document acceptable downtime and data-loss tolerance for critical services.
  • Include DNS, cloud configuration, code repositories, authentication systems, and business SaaS exports in recovery planning where appropriate.

10. AI, LLM, and agent governance

  • List AI tools and agents that can access company data, files, email, CRM records, cloud resources, or external actions.
  • Define what information employees may and may not send to public or third-party AI services.
  • Review OAuth scopes, connectors, plugins, service accounts, and API keys used by AI systems.
  • Require human approval for high-impact actions such as sending external messages, changing production systems, moving money, deleting records, or modifying security controls.
  • Test AI workflows for prompt injection, excessive permissions, unintended data exposure, and unsafe tool execution.

What to do after the review

Prioritize gaps that combine high business impact with easy attack paths or weak recovery. Assign a named owner and due date, then verify remediation rather than marking work complete from a ticket alone. Where exploitability is uncertain, use authorized technical validation. Where monitoring or response is weak, run a tabletop exercise and confirm the logs, contacts, and recovery paths actually work.