Security for SMBs without an IT department: what should you do this quarter?
No IT team, but still accountable. This pillar gives you a priority stack: do this first, then that, then the less urgent stuff. Each item links to a deeper guide.
You don't have an IT department. Yet you're responsible for company security. That sounds overwhelming — until you know where to start.
\n\nQuarter 1: the fundamentals
\n- \n
- MFA on everything. See rolling out MFA in M365. \n
- A password manager for everyone. See choosing a password manager. \n
- Disk encryption enabled on all laptops. \n
- A backup strategy you actually test. See backup strategy. \n
Quarter 2: context
\n- \n
- SaaS inventory in order. See SaaS inventory. \n
- Offboarding process defined. See offboarding. \n
- Phishing training for employees. See recognising phishing. \n
- Incident response plan on paper. See incident response. \n
Quarter 3: governance
\n- \n
- Access reviews. \n
- Start an ISO 27001 trajectory if customers are asking for it. See ISO 27001. \n
- Dismantle shadow IT. See cleaning up shadow IT. \n
Quarter 4: maturity
\n- \n
- Vendor risk management. See vendor risk. \n
- Security awareness embedded in onboarding. \n
- Periodic phishing tests. \n
What never to do?
\n- \n
- Think you're "not interesting enough" to be targeted. 90% of attacks are opportunistic, aimed at vulnerable systems regardless of company name. \n
- Treat security as something a virus scanner alone can handle. \n
- Wait for "the big security overhaul" — do one thing every week. \n
See also: access management pillar, GDPR pillar, ISO 27001 pillar.
Volledige gids: Seguridad para pymes sin departamento de TI: ¿qué haces este trimestre?
Dit artikel is onderdeel van onze uitgebreide Security zonder IT-afdeling-gids. Lees de pillar voor het complete plaatje.
Lees de pillar →