BG Beter Geregeld ICT
Security zonder IT-afdeling · 2 min leestijd · 23 September 2025 · ★ Pillar-gids

Security for SMBs without an IT department: what should you do this quarter?

No IT team, but still accountable. This pillar gives you a priority stack: do this first, then that, then the less urgent stuff. Each item links to a deeper guide.

You don't have an IT department. Yet you're responsible for company security. That sounds overwhelming — until you know where to start.

\n\n

Quarter 1: the fundamentals

\n
    \n
  1. MFA on everything. See rolling out MFA in M365.
  2. \n
  3. A password manager for everyone. See choosing a password manager.
  4. \n
  5. Disk encryption enabled on all laptops.
  6. \n
  7. A backup strategy you actually test. See backup strategy.
  8. \n
\n\n

Quarter 2: context

\n
    \n
  1. SaaS inventory in order. See SaaS inventory.
  2. \n
  3. Offboarding process defined. See offboarding.
  4. \n
  5. Phishing training for employees. See recognising phishing.
  6. \n
  7. Incident response plan on paper. See incident response.
  8. \n
\n\n

Quarter 3: governance

\n
    \n
  1. Access reviews.
  2. \n
  3. Start an ISO 27001 trajectory if customers are asking for it. See ISO 27001.
  4. \n
  5. Dismantle shadow IT. See cleaning up shadow IT.
  6. \n
\n\n

Quarter 4: maturity

\n
    \n
  1. Vendor risk management. See vendor risk.
  2. \n
  3. Security awareness embedded in onboarding.
  4. \n
  5. Periodic phishing tests.
  6. \n
\n\n

What never to do?

\n
    \n
  • Think you're "not interesting enough" to be targeted. 90% of attacks are opportunistic, aimed at vulnerable systems regardless of company name.
  • \n
  • Treat security as something a virus scanner alone can handle.
  • \n
  • Wait for "the big security overhaul" — do one thing every week.
  • \n
\n\n

See also: access management pillar, GDPR pillar, ISO 27001 pillar.

Onderwerpen

#mkb #start-hier #security

Volledige gids: Seguridad para pymes sin departamento de TI: ¿qué haces este trimestre?

Dit artikel is onderdeel van onze uitgebreide Security zonder IT-afdeling-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →