Where should
business security start?
Start with what keeps your business working: data, accounts and systems. Identify the impact of losing them, check access and recovery, then choose the scope of an assessment and prioritise changes.
At a glance
- First identify the processes whose interruption would stop work.
- Confirm who has access and whether data can be restored.
- Give every action an owner and evidence of completion.
What must keep working?
List the processes needed to serve customers, fulfil orders and handle billing. For each, note the applications, accounts, documents and suppliers it depends on. An inventory of computers alone will not show where an outage could stop the business.
Consider the impact of lost access, disclosed data and incorrect changes to information. Record who owns each area and how much interruption the business can tolerate. You do not need to price every risk immediately; start with concrete operational consequences.
Who can access your data?
Review accounts in email, applications and administration panels. Compare permissions with people’s actual duties. Pay attention to former collaborators, shared sign-ins and administrator accounts used for everyday work.
Enable MFA where available, starting with accounts that have the greatest impact on the business. Also agree a secure way to recover access. MFA reduces account takeover risk, but does not replace appropriate permissions or system updates.
- Who approves new access and who removes it?
- Can the business regain control if the only person with access is unavailable?
Can you resume work after an outage?
A successful backup notification is not a recovery test. Establish what the backup covers, where it is stored and who can restore it. Then test recovery in a controlled environment without overwriting live data.
Illustrative example: an application has daily backups, but needs configuration that nobody has backed up. A test exposes that gap. The result should be a working environment and a recorded recovery time, rather than just a file downloaded from a backup.
How do you turn findings into a plan?
A security assessment helps review agreed areas and organise risks. A penetration test examines selected ways safeguards might be bypassed within a defined scope. Implementing fixes is a separate task: a report alone does not change configurations.
Before a discussion, prepare a list of critical systems, access arrangements, backups and known problems. Agree what will be checked, how priorities will be set and who will make changes. Define how the outcome of each action will be verified. This guide is a starting point, not an audit or a statement of your company’s compliance.
Sources and next step
These sources describe mechanisms and good practices. They do not confirm your company’s configuration or compliance. The examples in this guide are illustrative.
To apply these questions to your business, explore the related service. A description of your situation is enough for an initial discussion; do not send passwords or confidential data through the form.
Explore our cybersecurity services