SECURITY BASELINE / 01
Define the scope
Start with the processes that keep the business moving. Consider how your team delivers work, communicates with customers, processes payments and accesses important records. Identify the systems and suppliers behind those processes.
An asset overview should help people make decisions. Record the system, its business purpose, who owns it and where responsibility sits. Include cloud services and systems managed by an external IT provider, so that the review reflects how work actually happens.
Read this section SECURITY BASELINE / 02
Review everyday controls
Review how access is granted, changed and removed. Pay particular attention to administrator accounts, multifactor authentication and accounts that remain active after someone leaves. Clarify who is responsible for checking those controls.
Check the process for updates and vulnerability remediation. Finding a weakness is only the first step: someone needs to assess its importance, agree a fix and verify that the change worked.
Read this section SECURITY BASELINE / 03
Set practical priorities
A long list of findings can leave a small team unsure where to begin. Relate each gap to the affected business process, the plausible impact and the protections already in place. Separate urgent remediation from improvements that need a planned project.
For each action, record an owner, a target date, dependencies and how completion will be checked. Agree where your internal team, your IT provider and a security specialist need to work together.
Read this section SECURITY BASELINE / 04
Keep useful evidence
Keep a record of the review scope, findings, decisions and completed changes. Useful evidence can include configuration records, restoration test results, access reviews and a remediation register. Keep it organised and proportionate to the work.
A baseline is a starting point. Revisit it after significant changes to systems, suppliers or business requirements, and agree a review schedule that your team can maintain.
Read this section SECURITY BASELINE / 05
Choose your next move
Explore our security baseline review and the other attackless offers, or see how we work. Start with the business risk or deadline you need to address.
Further reading: BSI guidance for SMEs and ENISA’s cybersecurity guide for SMEs.
Read this section