Key takeaways

  • Individual accounts and MFA limit the consequences of a compromised password.
  • Updates and EDR should cover both devices and servers.
  • A guest network, firewall and VPN limit unnecessary access.
  • Backups and an incident response procedure are just as important as protective tools.

The most important layers of protection

Identity

Individual accounts, MFA, separate administrator accounts and access reviews.

Devices

Updates, disk encryption, antivirus/EDR and disabling unused services.

Network

Firewall, VLANs, secure Wi-Fi, VPN and a separate guest network.

Data

Backups, retention, restricted sharing and a recovery plan.

How should you assess the current situation?

  • Does every employee have their own account and MFA?
  • Do we know about every administrator account?
  • Do devices receive updates?
  • Does email use SPF, DKIM and DMARC?
  • Is the business network separated from the guest network?
  • Are backups monitored and tested?
  • Do we know who responds to an incident?

Common mistakes

Shared accounts

They make accountability and the rapid revocation of access more difficult.

Protection without testing

An outdated backup or untested alerts may fail at a critical moment.

Excessive permissions

Every permission should follow from a person's role and be reviewed periodically.

Step-by-step action plan

  1. Secure accounts. Enable MFA and remove unused access.
  2. Update devices. Establish a patching and encryption cycle.
  3. Organise the network. Separate guests, IoT and critical systems.
  4. Check email. Configure domain and phishing protection.
  5. Verify backups. Perform a recovery test.
  6. Prepare your response. Record contacts, the sequence of actions and the documentation process.

Checklist

  • MFA works for users and administrators.
  • Devices are kept up to date.
  • The firewall and VPN configurations are backed up.
  • Email has essential domain protection.
  • A backup is held outside the primary environment.
  • The business has an incident response procedure.

Frequently asked questions

Is antivirus alone enough?

No. It protects one layer, while security also requires identity controls, updates, network protection and backups.

Should MFA be enabled for everyone?

It should cover at least administrator accounts and services accessible from the internet, and ultimately every user.

Where should a business with a small budget start?

Start with MFA, updates, backups, restricting permissions and separating the guest network.

Related service

Would you like to find out which security measures are most important for your business?

Explore cybersecurity

Do you need to get the essentials in order?

We can identify the most important risks and arrange the actions in an order suited to your business.

Let's talk about your IT