Cybersecurity
A baseline cybersecurity checklist for companies
Cybersecurity is not one product. Antivirus, firewall and MFA each address part of the risk. Business resilience appears when identity, devices, network, data, monitoring and response operate as a connected system.
The first goal is not another tool. It is a view of critical assets, major gaps, named owners and the sequence of measures that reduce business risk most.
Identity and administrative access
Most environments should begin with administrative accounts, MFA, privilege and access-removal processes. Shared accounts and permanent privilege weaken both prevention and investigation.
Separate everyday accounts from administrative work. Supplier and remote access should have an owner, expiry and recorded approval.
- MFA for critical and remote access
- least privilege
- access removal when roles change
- separate administrative accounts
Devices, network and data
Devices need a known owner, supported operating system, centrally managed policy and visible protection. Network rules should reduce unnecessary exposure and separate critical systems when justified.
Classify data by business impact. For critical information, define where it may be stored, who can access it, how it is shared and how it is recovered.
- current device inventory
- patching and managed protection
- controlled remote access
- data storage and sharing rules
Monitoring, response and proven recovery
Without relevant logs and agreed escalation, a company discovers events late and loses time finding an owner. Monitoring should focus on critical systems and signals that require action.
The response plan defines decision makers, secure incident reporting, isolation conditions and involvement of legal, communication and business owners. Backup and recovery form the final resilience layer and must be tested.
- retained relevant logs
- named escalation
- secure incident channel
- regular recovery testing