IT security is potentially very confusing with a LOT of different guidelines.

We’ve waded through the best practice and distilled it to our minimum recommendations below – it’s very possible that you are already doing many of these, perhaps some informally, but we believe that it’s essential you are doing all of them, and formally.

  1. Audit your IT and build an asset list/inventory, so you know what needs to be managed (CES)
  2. Policies formalise your IT use, so everyone knows what is expected (especially password management) and assess user understanding (CES)
  3. Train all your staff continuously about security awareness across all IT systems (CES/GDPR)
  4. Backup all your data regularly and to multiple locations and backup systems as required (GDPR). Regularly test all your restore processes.
  5. Encrypt all data wherever it’s stored and whilst in transit (GDPR)
  6. Anti-Malware should be used to protect every device and service (CES)
  7. Update all devices and software promptly with the latest patches (CES)
  8. Multi-Factor Authentication should be enabled wherever it is available (CES)
  9. Default Passwords for devices/services should be disabled or changed on first setup (CES)
  10. Password Managers should be provided to all staff
  11. Restrict Access to data, devices, services to the minimum required (CES)
  12. Monitor everything, all the time, for compliance and alerts

Steps that help compliance with Cyber Essentials (CES) or the General Data Protection Regulations (GDPR) are identified.

