Loading...
Loading...
Ten plain-English questions covering the security basics every UK SME should have in place. No technical knowledge needed. If you are not sure of an answer, that is an answer in itself.
Multi-factor authentication
Is multi-factor authentication (MFA) enforced for every user account, including administrators?
Conditional access
Do you restrict sign-ins based on location, device, or risk using conditional access policies?
Admin accounts
Are day-to-day accounts kept separate from admin accounts, with admin access limited to those who need it?
Device encryption
Are all laptops and desktops encrypted, for example with BitLocker?
Patching
Are operating systems and applications patched automatically within a defined timescale?
Endpoint protection
Do all devices run managed endpoint protection that someone actually monitors?
Backups
Is your Microsoft 365 data (email, SharePoint, OneDrive) backed up outside Microsoft, and are restores tested?
Leaver process
When someone leaves the business, is their access removed the same day through a documented process?
Phishing protection
Do you have anti-phishing protections in place, and have staff had any security awareness training?
Monitoring & alerts
Would you know within hours if one of your accounts was compromised?
Once you have answered all the questions above, tell us where to send your results.