Originally adapted from The Technology Press. Substantially reviewed and updated 15 September 2026.
Start with the business you need to keep running
A list of products cannot tell you whether the business is ready for an incident. Start with the information and processes you need to protect, then check the controls around them.
These thirteen checks are a discussion guide, not a certification checklist or a promise to make a business “disaster-proof”. Priorities depend on your environment and obligations.

Identify critical work and technology.
Set prioritiesReduce avoidable access and exposure.
Verify controls operatePractise response and restoration.
Assign responsibilityPractical checkpoints, not a guarantee of security or compliance.
What to check
1–3. Assets, owners and supported software
Know what exists, who owns it and whether it receives updates.
What to check
Include cloud applications and supplier-managed services, not just laptops.
4–6. Authentication, privilege and devices
Use suitable stronger authentication, least privilege and managed device settings.
What to check
Separate administrator accounts and review access as roles change.
7–9. Email, payments and suppliers
Layer technical protection with verification processes.
What to check
Confirm changed payment details independently and agree supplier access and incident responsibilities.
10–11. Backups and monitoring
Test recoverability and make alerts someone’s responsibility.
What to check
Record restore results, gaps and monitoring coverage rather than assuming licences prove readiness.
12–13. People and incident planning
Make reporting easy and rehearse decisions.
What to check
Explain how staff should report a concern and who leads technical, business and communications actions.
Sources & further reading
Make the next step practical
Talk to ITFR about your business, priorities and the controls that fit.









