The essentials every small business should have in place.
Security doesn’t need to be complicated to be effective. Most small businesses don’t need dozens of controls, specialist tools, or enterprise processes. They need a clear baseline that reduces real risk and stands up to reasonable scrutiny.
This checklist covers the core security foundations we expect most small businesses to have in place.
It’s designed to help you sense-check where you are today, prioritise what matters, and avoid spending time on things that won’t meaningfully improve your security.
How to use this checklist.
This is a practical starting point, not a compliance exercise or audit prep document.
Our top tips:
- Work through each item honestly
- Focus on whether the control exists and is actually being used
- Don’t worry if everything isn’t in place yet
- Use the gaps to decide what to tackle next, in order of impact
If you’re at an early stage, this helps establish sensible foundations. If you’re further along, it’s a quick way to spot weaknesses before customers, investors, or auditors do.
Small business security foundations checklist
Do you know what you’ve got?
- You have an accurate list of company devices (laptops, phones, tablets)
- You know what software and cloud services are in use
- There’s a single source of truth for assets (not conflicting spreadsheets or dashboards)
Are your devices protected?
- Company devices are enrolled in device management
- Full disk encryption is enabled
- Endpoint protection (antivirus / EDR) is installed and running
- You’d know if endpoint protection stopped working
Is access properly controlled?
- Multi-factor authentication is enabled on all business-critical systems
- MFA is in place for email, file storage, and admin consoles
- Staff accounts are removed promptly when people leave
- Admin access is limited and uses separate accounts
- Shared passwords and generic accounts aren’t used
Are systems configured securely?
- Default passwords have been changed
- Remote access is disabled unless explicitly needed
- Auto-run features are disabled
- Cloud services have been reviewed and hardened
Is patching happening?
- You know which systems have outstanding security patches
- Critical patches are applied within a week
- Other security patches are applied within 30 days
- Automatic updates are enabled where possible
Would you know if something went wrong?
- Key security events are logged
- Someone reviews alerts regularly
- Alerts are tuned so real issues don’t get lost
- Staff know how to report something suspicious
Is your data backed up?
- Critical data is backed up regularly
- Backups are stored separately from primary systems
- Backups have been tested and can be restored
- You know how long recovery would take after an incident
Are you protected against email threats?
- Email filtering is in place
- Staff have basic training on spotting phishing
- There’s a clear process for reporting suspicious emails
Do you have a plan if things go wrong?
- A basic incident response process is documented
- Staff know who to contact during an incident
- A business continuity plan exists for major outages
- Key contacts and recovery steps are accessible
Can you prove it?
- You can evidence your security controls when asked
- You meet your cyber insurance security requirements
- You could demonstrate due diligence after an incident
How did you do?
Take a look at how many items you were able to tick confidently.
- Most items ticked
You likely have solid security foundations in place. A focused review can help confirm this and identify any smaller gaps before customers or auditors do.
- Some items ticked, some gaps
Very common for growing businesses. The basics are partly there, but prioritising the most important gaps will make the biggest difference.
- Very few items ticked
You’re not alone. Many small businesses start here. The good news is that these fundamentals can usually be put in place relatively quickly and will significantly reduce risk.
Next steps
If you’d like help assessing where you stand and building proportionate security controls, get in touch for a conversation about our Security Foundations service.
We help small businesses:
- understand which gaps genuinely matter
- prioritise fixes based on real risk
- avoid over-engineering security too early
We’ll be happy to help you work out the most sensible next step.
Contact Us