All guides

A sensible first-year security plan

Most security plans fail because they try to do everything at once. This one is deliberately sequenced: the jobs that remove the most risk for the least disruption come first, and the slower cultural work comes later, once the basics are holding. You can run it with an internal team, with a provider, or as a checklist to hold someone else to.

Security13 min readUpdated 30 July 2026

Who this is for

Owners, operations leaders and IT managers who know security needs attention but don't want a twelve-page risk register to get started.

01

Months one to three: lock the front door

Almost every incident we help organisations unpick starts with a set of credentials, not a clever piece of malware. Someone's password is guessed, reused or typed into a convincing login page, and the rest follows. So the first quarter is about accounts.

  • Turn on multi-factor authentication for every account, including the ones nobody uses. Exceptions are where breaches live.
  • Find and remove the shared accounts. If three people use info@ to log in, nobody is accountable and nothing is traceable.
  • Reduce administrator rights to the smallest possible number of named people, with separate admin accounts from their day-to-day ones.
  • List every account that exists and match it against your current staff list. Expect surprises.
  • Write down who can approve a new account and who can approve access to finance systems.

If you only do one thing this year, make it MFA everywhere with no exceptions. It removes more risk than every other item on this list combined.

Expect some grumbling in week one and near silence by week three. The disruption of MFA is real but short. The disruption of a compromised mailbox is neither.

02

Months four to six: email and devices

With identity tightened, the next targets are the inbox and the laptop. Both are fixable with configuration rather than new spend, which is why they belong early.

Email

  • Publish SPF, DKIM and DMARC records so other organisations can tell a real message from someone pretending to be you.
  • Add an external-sender banner so a spoofed internal name is obvious at a glance.
  • Review mailbox forwarding rules - quietly forwarded mail is a classic sign of an old compromise nobody noticed.
  • Check who has delegate access to senior mailboxes and whether they still need it.

Devices

  • Confirm disk encryption is on for every laptop, and that you can prove it.
  • Get patching on a schedule with someone reporting on what failed, not just what ran.
  • Make sure every device can be wiped remotely if it's lost.
  • Retire anything still running an operating system that no longer gets security updates, or isolate it deliberately.

03

Months seven to nine: backup you've actually tested

This quarter is short on tasks and long on proof. The work isn't buying backup - most organisations already have some - it's establishing that it does what you think it does.

  • Write down what's backed up, and just as importantly what isn't. Microsoft 365 data is the usual gap: Microsoft keeps the service running, not your history.
  • Agree how much data you could stand to lose and how long you could stand to be down. Two numbers, written on a page, signed off by someone senior.
  • Do a real restore. Not a report that says the job completed - an actual file, mailbox and, if you can, a whole system.
  • Time the restore and compare it to the number you agreed. If it doesn't match, you have a finding worth escalating.
  • Make sure at least one copy is somewhere ransomware can't reach from your network.

Put a restore test in the calendar twice a year with a named owner. Untested backups quietly rot; scheduled ones get noticed when they break.

04

Months ten to twelve: people and process

Training first and configuration later is the wrong order - you end up asking people to compensate for gaps you could have closed yourself. By month ten the technical ground is firmer, so awareness work has something to stand on.

  • Run short, specific awareness sessions. Ten focused minutes on invoice fraud beats an hour of general theory.
  • Give people an obvious, blame-free way to report something odd, and thank them when they use it.
  • Write a one-page incident plan: who to call, in what order, and what to do in the first hour.
  • Formalise the starters and leavers process so access is granted and removed the same way every time.
  • Decide whether Cyber Essentials is worth pursuing. If clients or funders ask about security, it usually is.

None of this needs to be perfect. A plan people remember beats a policy nobody reads.

05

Keeping it going after year one

Year one is catch-up. Year two onwards should be maintenance, and it's a much lighter load: quarterly access reviews, twice-yearly restore tests, an annual look at who's an administrator and why, and a check that leavers really did lose access.

The organisations that stay in good shape aren't the ones who spent the most. They're the ones who kept doing five small things on a schedule.

The short checklist

  • MFA on every account, with no standing exceptions.
  • Shared logins removed, admin rights cut to a named few.
  • SPF, DKIM and DMARC published, forwarding rules reviewed.
  • Encryption confirmed and patching reported on, not assumed.
  • Microsoft 365 data backed up separately from Microsoft.
  • A real restore performed and timed against an agreed target.
  • A one-page incident plan with names and phone numbers.
  • Starters and leavers written down as a repeatable process.

Want a second opinion on where you've got to?

Get an IT health check that reviews your support, security and Microsoft setup, then gives you a short, prioritised list of what's worth doing.