IT First Responder home
IT First Responder home

Thirteen Cyber Security Checks for a Stronger Business Baseline

A practical starting point for business security: assets, identities, updates, email, suppliers, recovery and response, with clear ownership.

Isometric Analyst Connecting Identity, Cloud Documents And Unusual Sign-In Signals To Investigate An Account Compromise.

Originally adapted from The Technology Press. Substantially reviewed and updated 15 September 2026.

PRACTICAL IT

Start with the business you need to keep running

A list of products cannot tell you whether the business is ready for an incident. Start with the information and processes you need to protect, then check the controls around them.

These thirteen checks are a discussion guide, not a certification checklist or a promise to make a business “disaster-proof”. Priorities depend on your environment and obligations.

Start With The Business You Need To Keep Running
AT A GLANCE
Know

Identify critical work and technology.

Set priorities
Protect

Reduce avoidable access and exposure.

Verify controls operate
Recover

Practise response and restoration.

Assign responsibility

Practical checkpoints, not a guarantee of security or compliance.

What to check

1–3. Assets, owners and supported software

Know what exists, who owns it and whether it receives updates.

What to check

Include cloud applications and supplier-managed services, not just laptops.

4–6. Authentication, privilege and devices

Use suitable stronger authentication, least privilege and managed device settings.

What to check

Separate administrator accounts and review access as roles change.

7–9. Email, payments and suppliers

Layer technical protection with verification processes.

What to check

Confirm changed payment details independently and agree supplier access and incident responsibilities.

10–11. Backups and monitoring

Test recoverability and make alerts someone’s responsibility.

What to check

Record restore results, gaps and monitoring coverage rather than assuming licences prove readiness.

12–13. People and incident planning

Make reporting easy and rehearse decisions.

What to check

Explain how staff should report a concern and who leads technical, business and communications actions.

Sources & further reading

ASD: Essential Eight maturity model

ASD: Questions to ask managed service providers

Turn a review into an action plan

Make the next step practical

Talk to ITFR about your business, priorities and the controls that fit.

Explore cyber security

Useful IT ideas, straight to your inbox

Get the monthly ITFR Insights newsletter. Unsubscribe any time.

Choose interests (optional)
What interests you?

Privacy policy