Back to the blog

The five security jobs that matter most

Security advice usually arrives as a list of forty things, all marked urgent, most of them products. That's not much use when you've got a limited budget and a day job. Here are the five jobs that reduce the most real risk, in the order we'd normally do them.

Cyber security2 July 20269 min read

Most organisations we speak to aren't unaware of security. They've read the guidance, they've had the insurance questionnaire, they've sat through the webinar. The problem isn't knowing that security matters. It's working out what to do first when the list is long, the budget isn't, and nobody can tell you which item on it actually moves the needle.

So this isn't a comprehensive framework. It's the short version: the handful of jobs that, in our experience, close off the routes attackers actually use. Progress matters more than perfection, and these five are where progress is cheapest.

1. Get multi-factor authentication on everything

Almost every incident we hear about starts with someone's password. Not a clever exploit, not a zero-day - a password that was reused, guessed or handed over on a convincing-looking sign-in page. Multi-factor authentication is the single change that turns most of those attempts into a dead end.

The catch is the word "everything". Plenty of organisations have MFA on email and assume they're covered, while the VPN, the remote desktop server and the finance system still take a password on its own. Those are the doors that get tried. Worth checking, in this order:

  • Microsoft 365 or Google Workspace, for every account including shared mailboxes and service accounts.
  • Anything reachable from the internet: VPN, remote desktop, web portals for line-of-business systems.
  • Administrator accounts, which should be separate from day-to-day accounts and always protected.
  • The exceptions somebody set up eighteen months ago "just temporarily" and never removed.

If you only do one thing this quarter, make it this. It costs very little and it removes the attack that's most likely to reach you.

2. Fix the leavers process

Starters get sorted, because someone can't work until they are. Leavers get forgotten, because nobody's chasing. The result is a slow accumulation of live accounts belonging to people who left months ago, still holding access to email, files and sometimes systems the current team has forgotten exist.

This is an administrative fix rather than a technical one, which is why it's usually cheap and usually neglected. What good looks like: one agreed checklist, one person accountable for running it, and a monthly comparison between the payroll list and the account list. Anything that appears on one and not the other gets dealt with that week.

3. Take away admin rights nobody needs

In a lot of organisations, everyone's laptop account is a local administrator, usually because it was easier to set up that way years ago. It means any software that runs on a machine - including software the user didn't intend to run - can install itself, change settings and spread more easily.

Removing admin rights is the change people worry about most, because it sounds like it'll generate complaints. In practice, done properly, most users never notice. The work is in finding the handful of applications that genuinely need elevation and handling those cases deliberately, rather than leaving the door open for everyone to avoid a conversation with three people.

4. Make email harder to fake

Invoice fraud doesn't need to break into anything. It just needs an email that looks like it came from a director or a supplier, arriving at the right moment, asking for bank details to be updated. The technical protections that make spoofing harder - SPF, DKIM and DMARC - are free, and a surprising number of organisations have them half-configured or not at all.

Pair that with two practical habits. First, external emails should be visibly marked as external, so a message pretending to be from the finance director doesn't blend in. Second, agree a rule that bank detail changes are always confirmed by phone, on a number you already hold, never one from the email. That rule has saved more money than any product we could sell you.

5. Prove the backups restore

Backups are the thing everyone believes they have and far fewer have tested. A backup job that reports success every night tells you a job ran. It doesn't tell you the data is complete, that you can get it back within a working day, or that anyone knows how.

  • Restore something real, this quarter. A folder, a mailbox, a database - not a test file created for the purpose.
  • Time it, and write down how long it took. That number is your actual recovery time, whatever the contract says.
  • Check Microsoft 365 is covered. Microsoft keeps the service running; keeping your data recoverable is your responsibility.
  • Make sure one copy can't be reached from the network an attacker would already be on.

The point of a backup isn't the backup. It's the restore, and the only way to know you have one is to do it while nothing is on fire.

What we've deliberately left off

You'll notice there's no new product on this list. Monitoring tools, advanced endpoint protection and security awareness training all earn their place, and we'd usually recommend them next. But they work considerably better on top of these five than instead of them. Buying detection before you've turned on MFA is paying to be told about the break-in you could have prevented.

There's also no talk of being fully secure, because nobody is. The realistic aim is that the easy routes in are closed, the damage from anything that does happen is limited, and you can answer an insurer or a client honestly without having to guess.

A sensible order of work

If you're starting from a blank sheet, most organisations can get through MFA and the leavers process inside a month, with no new spend. Admin rights and email protections tend to take a quarter, because they need a bit of care and a few conversations. Backup testing should then become a routine rather than a project.

None of this requires a big transformation programme, and it shouldn't come with a fear-driven sales pitch attached. If a provider can't tell you which of these five you've already got covered, that's the conversation to have before you look at anything else.

The short version

  • MFA everywhere, not just on email, closes off the attack you're most likely to face.
  • The leavers process is an admin fix, not a technical one, and it's usually the cheapest win on the list.
  • Removing unnecessary admin rights limits how far any single problem can spread.
  • Confirm bank detail changes by phone. That habit prevents more loss than most products.
  • A backup you haven't restored from is a plan, not a safety net.

Not sure which of this applies to you?

Get an IT health check that reviews your support, security and Microsoft setup, then gives you a short, prioritised list of what's worth doing.