6 minute read

Start with identity, not tools
The majority of intrusions we investigate begin with a valid login rather than a technical exploit. Strong identity controls remove the cheapest route into your systems, and they cost far less than the tooling most vendors recommend first.
Enforce multi factor authentication on every account, remove shared logins, and review administrative access quarterly. These three actions typically close more risk than a new security product.
- Multi factor authentication on all accounts, including service accounts where supported
- Named administrator accounts with separate day to day logins
- Quarterly access reviews tied to your joiners and leavers process
Make patching a scheduled operation
Unpatched systems remain one of the most common findings in our assessments. The issue is rarely awareness, it is ownership. When nobody is accountable for a monthly cycle, updates slip until an incident forces attention.
Assign an owner, agree a maintenance window, and report completion to leadership in the same way you report any other operational metric.
Test your backups before you need them
A backup that has never been restored is an assumption. We recommend a documented restore test at least twice a year, covering both a single file and a full system, with the elapsed time recorded.
That recorded time becomes your real recovery objective, and it often differs sharply from what the business expects.
Defend the inbox
Email remains the primary delivery route for credential theft and payment fraud. Configure SPF, DKIM, and DMARC, enable advanced phishing protection in your mail platform, and run short quarterly awareness sessions with realistic examples from your own sector.
Write the incident response plan now
During an incident, decisions are made under pressure and with incomplete information. A two page plan naming who decides, who communicates, and who contacts insurers and regulators will save hours at the worst possible moment.
Rehearse it once a year with a tabletop exercise. The exercise usually surfaces gaps that no assessment report would find.
Key takeaways
- Identity controls deliver the largest risk reduction per dollar spent
- Patching fails on ownership, not awareness
- An untested backup is an assumption, not a control
- A short, rehearsed incident plan outperforms a long, unread one
