All checklists

Security basics

Almost every incident we hear about comes down to the same few gaps. This list is deliberately short and deliberately ordered - work down it, and stop worrying about the exotic threats until the basics are done.

Security11 stepsUpdated 30 July 2026

Who this is for

Anyone responsible for security in an organisation without a full-time security person.

Time needed: Half a day for most of it

01

Identity first

Where most attacks actually start.

  • Multi-factor authentication on every account, no exceptionsThe exceptions are how people get in. Senior staff and shared mailboxes included.
  • Count your admin accounts and cut the numberDay-to-day work shouldn't happen from an account that can change everything.
  • Block legacy sign-in protocolsOlder protocols skip MFA entirely, which makes the rest of the work pointless.
  • Review who has access to shared mailboxes and finance systemsAccess tends to accumulate; nobody ever asks for less.

02

Email and devices

The two routes in that staff touch every day.

  • Turn on external sender warningsA small banner stops a surprising share of invoice fraud.
  • Check SPF, DKIM and DMARC are configuredStops other people sending email that looks like it came from you.
  • Confirm every laptop is encryptedA lost unencrypted laptop is a reportable data breach; an encrypted one usually isn't.
  • Enforce automatic updates on devices and browsersMost exploited flaws had a patch available months earlier.

03

Assume something gets through

What decides how bad a bad day gets.

  • Back up Microsoft 365, not just files on a serverRetention policies are not backup - deleted mail eventually goes for good.
  • Test one restore and write down how long it tookAn untested backup is a hope, not a control.
  • Agree who to call, in what order, if something looks wrongOne page, printed. It won't be online when you need it.

Worth watching out for

  • Don't buy a new security product until MFA is on everywhere - the tool won't cover the gap the settings left.
  • Contractors and long-term temps are usually exempted from the rules and are a common way in.
  • If you're doing this to satisfy a client questionnaire, Cyber Essentials covers much of the same ground formally.

Stuck on one of these steps?

Get an IT health check that reviews your support, security and Microsoft setup, then gives you a short, prioritised list of what's worth doing.