This checklist is based on three sources: the NCSC's Cyber Essentials technical controls, the ICO's guidance on UK GDPR technical measures, and what we most commonly find missing when we onboard new clients across Nottingham, Derby, Leicester and the wider East Midlands.
Work through it honestly. For each item, the question isn't "do we have this?" but "do we have this configured correctly and is it actually working?"
Section 1: Accounts and Access
- Multi-factor authentication (MFA) is enabled for all users - especially on Microsoft 365, email, and any application accessible from the internet. This alone prevents the majority of account takeover attacks.
- Admin accounts are separate from standard user accounts - day-to-day work is done with a standard account; admin accounts are only used when needed and are separate credentials.
- User accounts have appropriate permissions - no blanket admin rights for all users; access is role-appropriate.
- Leaver process is defined and followed - accounts are disabled immediately when a staff member leaves; access to email, systems and shared resources is revoked promptly.
- Default passwords are changed on all devices - routers, switches, printers, NAS devices: none use their factory default passwords.
- Password policy requires strong passwords - minimum 12 characters; ideally enforced by a password manager rather than complexity rules that lead to predictable patterns.
Section 2: Devices and Endpoints
- Full disk encryption is enabled on all laptops - BitLocker on Windows, FileVault on Mac. If a laptop is stolen, this prevents data access.
- All devices have endpoint security (EDR/antivirus) - managed centrally, not just installed and forgotten. You should be able to see the protection status of every device.
- Operating systems are up to date - no unsupported versions (Windows 10 reaches end of life in October 2026; plan your upgrades now).
- Software is patched within 14 days of critical updates - high-risk patches should be deployed promptly, not left to auto-update whenever convenient.
- Personal mobile devices used for work are enrolled in MDM - or at minimum have a PIN enforced and remote wipe capability.
- BIOS/UEFI passwords are set on laptops - prevents boot from external media.
Section 3: Network Security
- Firewall is configured at the network perimeter - inbound connections are restricted to only what's necessary; default passwords on the firewall/router are changed.
- Wi-Fi networks are secured with WPA2 or WPA3 - WEP and WPA are insecure and should not be used.
- Guest Wi-Fi is separated from the business network - visitors (and personal devices) should be on a separate VLAN or guest network with no access to business systems.
- Remote Desktop Protocol (RDP) is not exposed to the internet - if staff need remote access, this should be via VPN or a zero-trust solution, not a directly exposed RDP port.
- Network switches are managed and monitored - you know what's connected to your network.
Common gap: RDP exposed directly to the internet (port 3389 open) is one of the most common entry points for ransomware attacks. If you're not sure whether this applies to you, ask your IT provider to check your firewall configuration.
Section 4: Email Security
- SPF, DKIM and DMARC records are configured for your domain - these prevent attackers from sending emails that appear to come from your domain. DMARC should be set to at least p=quarantine.
- Email filtering scans attachments and links - Microsoft Defender for Office 365 or equivalent, not just basic spam filtering.
- Staff have received phishing awareness training in the last 12 months - ideally including simulated phishing exercises.
- Sensitive data is not sent by unencrypted email - a process exists for securely sharing personal or confidential data (encrypted email, secure portal, SharePoint link with access controls).
Section 5: Backup and Recovery
- All business-critical data is backed up daily - including data stored in Microsoft 365 (which requires a separate third-party backup - Microsoft's native retention is not a backup).
- Backup copies are stored off-site or in the cloud - a backup stored on the same network as your primary data doesn't protect against ransomware or fire/flood.
- At least one backup copy is immutable - cannot be modified or deleted, even by an administrator.
- Backup restores are tested regularly - at minimum quarterly; you know that the backup actually works and how long a restore takes.
- A documented disaster recovery plan exists - your team knows what to do in an incident, who to call, and in what order to restore systems.
Section 6: Software and Applications
- Only licensed, supported software is in use - no pirated software, no applications that have reached end of vendor support.
- Software is sourced only from official channels - apps from official stores or vendor sites, not third-party download sites.
- Unused applications are uninstalled - software you don't use is still a potential vulnerability if it has unpatched flaws.
- Browser extensions are reviewed and controlled - malicious browser extensions are a significant and underappreciated threat vector.
Section 7: Policies and Processes
- An acceptable use policy exists and has been signed by all staff - covers what's permitted on business devices and accounts.
- A remote working policy is in place - covers device requirements, home network standards, and what to do with a lost or stolen device.
- A security incident response process is documented - staff know how to report a suspected incident, and someone is responsible for responding.
- Cyber insurance is in place - covers costs of incident response, recovery, and legal liability. Requirements vary - most insurers now require MFA as a condition.
How Many Did You Score?
If you ticked everything above, your security posture is genuinely strong for a UK small business and you're likely close to Cyber Essentials certification already.
If you have gaps - particularly in MFA, encryption, backups, or email security - those represent real risk that should be addressed as a priority.
CloudHost offers a free IT security review for businesses across the East Midlands. We'll work through your current setup against these controls, identify gaps, and give you a clear, costed action plan. Book your review here.