Controls library
Every missing control, in one place
Every case on this site ends with the one control that would have stopped it or cut it short. Here they all are, grouped by type. Start with the group that sounds most like your business.
Close the same gap
Check which of these you have
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
Identity and access
Logins, two-step verification, and who can reset them. Read the guide: Employee offboarding checklist: how to cut off a former employee's access the same day Read the guide: How to verify callers before password resets, and protect your phone number from SIM swaps Read the guide: Which two-step login actually stops phishing, and how a small office rolls it out
Multifactor authentication on all remote access Strict limits on internal admin tools Mandatory default password change Independent custody of signing keys Phishing-resistant MFA, not push approvals Verify callers before help desk resets Keep critical keys off personal devices MFA on every remote portal Mandatory two-step login for all accounts Enforced MFA and credential rotation Block personal browser profiles at work Phishing-resistant MFA like hardware keys Verify new hires' identity and location Revoke cloud access at offboarding Phishing-resistant hardware security keys Two-factor login on remote access Access control on sensitive databases Verify identity before issuing MFA tokens Phishing-resistant multi-factor authentication Device-bound sessions for vendor staff Enforced two-factor for remote access Force new unique passwords plus MFA Rotate and validate login signing keys MFA on every account, even test Two-factor login on social accounts Verify caller identity before sharing No plaintext password files on shares Verify identity before credential resets Non-SMS MFA and carrier port locks Consistent identity checks across support Isolate authentication secrets from corporate network Unique credentials for remote access MFA on the cloud admin console Change default passwords before deployment MFA on all third-party remote access Separate power to change withdrawal signers No SMS codes guarding exchange funds MFA for admins and disciplined patching Vendors and third parties
Contractors, IT providers and suppliers with a key to your systems. Read the guide: How to manage vendor, IT provider and contractor access to your systems
Vendor access segmented from payment systems Integrity checks on the build pipeline Security due diligence before acquisition Independently verify what signers approve Monitor vendor privileged credential use Help desk identity verification Vendor controls on prepaid card limits Verify employers and vendors independently Vendor remote access risk assessment Vet who owns and services ATMs Third-party help desk caller verification Written scope approved by all owners Patching and monitoring
Known holes left open and alarms nobody answered. Read the guide: How a small business keeps software and devices patched, and why default passwords must go
Timely patching and verified monitoring Continuous review of cloud configurations Verified, controlled code deployment Patch critical flaws within days Encrypt card data in transit internally Act on security alerts promptly Complete inventory of connected devices Strong wireless encryption and segmentation Lock down forgotten development servers Escalate and disclose breaches promptly Purge data from file-transfer servers Authenticate commands sent to field devices Isolate infotainment from vehicle controls Remediate prior security audit findings Audit and monitor account usage logs Segment IoT devices from core network Test upgrade defaults before deployment Retire deprecated verification code before launch Reconcile wallets against the ledger daily Patch internet-facing VPNs within days Payments and fraud
Fake invoices, fake bosses and money that moved without a second check. Read the guide: How to stop fake invoices, changed bank details and fake-boss payment requests
Independent verification of outgoing payment orders Verify payment changes with known supplier Verify payment requests out of band Callback verification before urgent payments Independent second approval on withdrawals Call back on a known number Reconcile SWIFT messages with core banking Balance checks on every withdrawal Verify payee identity before sending funds Out-of-band verification of large transfers Dual approval for large wires MFA on executive email accounts Callback verification for wire requests Verify the asset actually exists Insider risk
Trusted people with too much access and nobody watching.
Monitor privileged insider access Least-privilege limits on support data Separate trading from trade settlement Role-based access to user data Insider bribe reporting channel Identity proofing during remote hiring Independent confirmation of every trade Disable access at termination time No single-person admin control Need-to-know access with monitoring Monitor privileged support staff actions Cut ex-contractor access; authenticate commands Rotate shared credentials at offboarding Independent audits of client asset custody Monitor downloads by departing staff Revoke every external account at offboarding