01
Months one to three: lock the front door
Almost every incident we help organisations unpick starts with a set of credentials, not a clever piece of malware. Someone's password is guessed, reused or typed into a convincing login page, and the rest follows. So the first quarter is about accounts.
- Turn on multi-factor authentication for every account, including the ones nobody uses. Exceptions are where breaches live.
- Find and remove the shared accounts. If three people use info@ to log in, nobody is accountable and nothing is traceable.
- Reduce administrator rights to the smallest possible number of named people, with separate admin accounts from their day-to-day ones.
- List every account that exists and match it against your current staff list. Expect surprises.
- Write down who can approve a new account and who can approve access to finance systems.
If you only do one thing this year, make it MFA everywhere with no exceptions. It removes more risk than every other item on this list combined.
Expect some grumbling in week one and near silence by week three. The disruption of MFA is real but short. The disruption of a compromised mailbox is neither.
02
Months four to six: email and devices
With identity tightened, the next targets are the inbox and the laptop. Both are fixable with configuration rather than new spend, which is why they belong early.
- Publish SPF, DKIM and DMARC records so other organisations can tell a real message from someone pretending to be you.
- Add an external-sender banner so a spoofed internal name is obvious at a glance.
- Review mailbox forwarding rules - quietly forwarded mail is a classic sign of an old compromise nobody noticed.
- Check who has delegate access to senior mailboxes and whether they still need it.
Devices
- Confirm disk encryption is on for every laptop, and that you can prove it.
- Get patching on a schedule with someone reporting on what failed, not just what ran.
- Make sure every device can be wiped remotely if it's lost.
- Retire anything still running an operating system that no longer gets security updates, or isolate it deliberately.
03
Months seven to nine: backup you've actually tested
This quarter is short on tasks and long on proof. The work isn't buying backup - most organisations already have some - it's establishing that it does what you think it does.
- Write down what's backed up, and just as importantly what isn't. Microsoft 365 data is the usual gap: Microsoft keeps the service running, not your history.
- Agree how much data you could stand to lose and how long you could stand to be down. Two numbers, written on a page, signed off by someone senior.
- Do a real restore. Not a report that says the job completed - an actual file, mailbox and, if you can, a whole system.
- Time the restore and compare it to the number you agreed. If it doesn't match, you have a finding worth escalating.
- Make sure at least one copy is somewhere ransomware can't reach from your network.
Put a restore test in the calendar twice a year with a named owner. Untested backups quietly rot; scheduled ones get noticed when they break.
04
Months ten to twelve: people and process
Training first and configuration later is the wrong order - you end up asking people to compensate for gaps you could have closed yourself. By month ten the technical ground is firmer, so awareness work has something to stand on.
- Run short, specific awareness sessions. Ten focused minutes on invoice fraud beats an hour of general theory.
- Give people an obvious, blame-free way to report something odd, and thank them when they use it.
- Write a one-page incident plan: who to call, in what order, and what to do in the first hour.
- Formalise the starters and leavers process so access is granted and removed the same way every time.
- Decide whether Cyber Essentials is worth pursuing. If clients or funders ask about security, it usually is.
None of this needs to be perfect. A plan people remember beats a policy nobody reads.
05
Keeping it going after year one
Year one is catch-up. Year two onwards should be maintenance, and it's a much lighter load: quarterly access reviews, twice-yearly restore tests, an annual look at who's an administrator and why, and a check that leavers really did lose access.
The organisations that stay in good shape aren't the ones who spent the most. They're the ones who kept doing five small things on a schedule.