Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
TEMPLATE · IT / OTv1.0 · REVIEWED 2026-07-28

First 14 Days Action Plan

Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.

Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.

Purpose

The first two weeks, taken from the practices in the first three stages of the recommended sequence. These are the moves that close the largest doors before anything else is attempted.

How to use it

Assign an owner and a target date to each line before you start. Two weeks in, run the validation checks in the final section — an action nobody validated is not finished.

First 24 hours

Nothing here requires procurement. All of it is confirmation, discovery, or switching something on that you already own.

  • List accounts with admin or remote accessIT-01
  • Enable MFA for those accounts todayIT-01
  • Name an inventory ownerIT-02
  • Pull existing lists from MDM, identity provider, and procurementIT-02
  • Find default and vendor-set passwords on reachable devicesOT-01
  • List every shared/generic login in useOT-01
  • Name an inventory ownerOT-02
  • Collect existing vendor and project asset listsOT-02
  • Identify your most sensitive systems and where CUI livesIT-05
  • Confirm management interfaces are off the user networkIT-05
  • Map every connection between the business and OT networksOT-03
  • Flag any direct, unfiltered IT-to-OT pathsOT-03
  • Inventory every remote and vendor access path into OTOT-06
  • Disable any unknown or always-on tunnelOT-06
  • List systems already past end-of-supportIT-03
  • Flag any that are internet-facingIT-03
  • Confirm scanning covers internet-facing systemsIT-06
  • Check for any known-exploited vulnerabilities already publicIT-06
  • Cross-reference the OT inventory against known-exploited and vendor advisoriesOT-05
  • Flag any internet-reachable OT deviceOT-05

Owner and date

ActionOwnerTarget dateDone
    
    
    
    
    
    

By day 14

  • Enroll every administrator on a phishing-resistant method and stop accepting SMS as an admin factorIT-01
  • Write down and test the break-glass procedure before you tighten enforcement furtherIT-01
  • Merge the endpoint, identity, and procurement exports into one record and mark the rows that appear in only one sourceIT-02
  • Flag every device with no owner and every account with no matching employeeIT-02
  • Change the default and vendor-set passwords you can safely change in the next approved maintenance windowOT-01
  • Confirm break-glass access exists, is documented, and has been tested against an identity or network outageOT-01
  • Walk down one production line and record make, model, firmware, connectivity, and criticality with the operatorsOT-02
  • Reconcile that line against the vendor and project documentation and investigate anything that appears in only oneOT-02
  • Confirm management interfaces are unreachable from the standard user network and fix any that areIT-05
  • Move high-risk devices — legacy systems, IoT, guest Wi-Fi — off the general user segmentIT-05
  • Map every connection between the business and OT networks, including forgotten links, cellular modems, and vendor tunnelsOT-03
  • Close or broker the riskiest direct path in an approved window, with a tested rollbackOT-03
  • Disable any remote pathway you cannot identify an owner and a business reason forOT-06
  • Route the highest-risk remaining pathway through a brokered jump host with strong authenticationOT-06
  • Confirm no internet-facing system is running unsupported software; isolate anything that isIT-03
  • Disable the legacy protocols you can turn off without a project — SMBv1, TLS 1.0/1.1, basic authenticationIT-03
  • Run an authenticated scan across endpoints and servers and confirm it covered the full inventoryIT-06
  • Check your estate against the known-exploited vulnerability catalogue and remediate those findings firstIT-06
  • Cross-reference the inventory against vendor advisories and the known-exploited catalogue, and rank by exposure and process impactOT-05
  • Apply compensating controls — isolation, access restriction — to the worst findings you cannot safely patch yetOT-05

Owner and date

ActionOwnerTarget dateDone
    
    
    
    
    
    

Validate before you call it done

The first validation check for each practice in scope. If the check has not been run, the practice is not deployed.

PracticeFirst validation checkResultDate
IT-01Attempt sign-in with password only on a test account — it must fail.  
IT-02Pick ten devices from the network at random; all ten must appear in the inventory with an owner.  
OT-01Pick a production device and confirm it no longer uses a default or vendor-set password.  
OT-02Pick five random devices on the floor; all five must appear in the inventory.  
IT-05From a standard user device, attempt to reach a server-zone or management interface — it must be blocked.  
OT-03From a business-network host, attempt to reach an OT controller directly — it must be blocked.  
OT-06Attempt to reach an OT device remotely without going through the jump host — it must fail.  
IT-03Confirm no internet-facing system is running unsupported software.  
IT-06Confirm the last authenticated scan actually covered the full asset inventory, not a subset.  
OT-05Confirm every high-risk OT vulnerability has either an applied patch or a documented compensating control.  

Limitations

Production and safety come first

Nothing on this list should be actioned on a live operational-technology system without the process owner's agreement, an approved maintenance window, a tested rollback, and a safety review. Where a security action conflicts with safe operation, the safe operation wins and the control is compensated instead.

First 14 Days Action Plan · version 1.0 · reviewed 2026-07-28 · file name batb-first-14-days-action-plan

Generated from Your first 14 days at brilliantatthebasics.us. The live pages carry the current version of this guidance.

Independent educational material published by inDirectIT, Inc. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Cybersecurity practices must be tailored to each organization’s technical, operational, contractual, regulatory, and safety requirements.

All downloads

Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-first-14-days-action-plan to keep filenames consistent across your team.