Practical cyber security guidance

Small business cyber security checklist

A useful cyber security checklist should answer a simple question: if an account, device or supplier is compromised tomorrow, have you reduced the chance of the attack spreading and can you recover quickly? Use this page as a leadership-level starting point.

Frequently asked questions

6 practical answers.

### What are the first cyber security checks a small business should make?

Check that MFA is required for important accounts, administrator access is controlled, devices and software are supported and updated, email protection is configured, backups are protected and restorable, and staff know how to report suspicious activity.

### Should every user have administrator rights?

No. Routine users should normally have only the access they need. Privileged access should be limited, separately protected and reviewed.

### How should we protect Microsoft 365?

Use strong authentication, restrict privileged roles, review risky sign-ins and forwarding rules, configure email and domain protection, manage devices where appropriate, and maintain an independent recovery plan for important data.

### What should we check about backups?

Confirm what is actually backed up, how long data is retained, who can alter or delete backups, whether MFA protects backup administration, whether failures are monitored and whether restores are tested.

### How often should the checklist be reviewed?

Review it whenever there is a major change and at regular leadership intervals. New staff, suppliers, cloud services, offices, acquisitions and major software changes can all alter the risk.

### Does a checklist replace a cyber security assessment?

No. A checklist helps expose obvious gaps, but an assessment should consider how controls interact, whether they are operating consistently and who owns each action.

Related guidance

Keep improving the control set.