Skip to main content
NorthWave Guide · IT Baseline · 12 min read

The NorthWave Small Business IT Baseline.

25 practical checks to help a UK small business understand whether its technology foundations are dependable, secure, documented and recoverable.

A small business does not need a complicated enterprise architecture to have good IT foundations. It does need to know what it relies on, who can access it, what is being maintained, what is protected and what would happen if something important stopped working.

This baseline is NorthWave Solutions' practical way of organising those questions. It is deliberately broader than a cyber security checklist: reliable IT also depends on devices, connectivity, software, suppliers, documentation and the ability to recover when something goes wrong.

How to use this guide

Work through the 25 checks with the person responsible for IT. Mark each item Yes, Needs attention or Not applicable. Do not try to fix everything at once. Start with identity, recovery and the systems that would cause the greatest business disruption.

The 25-point baseline

Start with the foundations that matter most.

The checks below are grouped so a business can review its environment without needing to start with a long technical audit.

Priority 1

Protect access & recovery

Identity, administrator access, MFA and recoverable backups come first.

Priority 2

Maintain the everyday

Devices, software, email, network controls and suppliers need ownership.

Priority 3

Make it repeatable

Documentation, reviews, monitoring and incident planning prevent knowledge gaps.

1

You know which systems the business depends on.

List the systems that would stop or seriously disrupt the business if unavailable: email, finance, customer records, line-of-business applications, websites, file storage, phones or production systems.

2

Every important account has a named owner.

Avoid accounts that only one person understands. Record ownership for Microsoft 365, domain/DNS, hosting, finance, backup, security and other critical services.

3

MFA or stronger sign-in protection is enabled where appropriate.

Prioritise email, administrator accounts, finance, remote access and other high-impact services. Where passkeys are supported, consider them for important accounts.

4

Administrator access is limited and reviewed.

Know who has privileged access and why. Use separate administrator and everyday user accounts where practical, and remove access that is no longer required.

5

Leaver and role-change processes actually remove access.

When someone leaves or changes role, review Microsoft 365, shared drives, cloud services, devices, VPNs, social accounts and third-party systems—not just their main mailbox.

6

Important data is backed up independently of the working environment.

Identify what must be recoverable and where the copies live. A synchronised folder is not automatically the same thing as a recoverable backup.

7

Backups are tested by restoring data.

A successful backup job does not prove that recovery will work. Test a representative file or system and record what happened.

8

The business knows how quickly critical services need to return.

For each critical service, define a realistic recovery priority. A system needed within an hour has different recovery requirements from one that can wait two days.

9

Windows, macOS, mobile devices and applications are maintained.

Supported software should receive security updates. Keep an inventory so unsupported or forgotten devices do not become invisible risk.

10

Endpoint protection and firewall controls are enabled.

Check that built-in or managed security controls are active and have not been disabled by a local setting, conflicting software or poor configuration.

11

Business email has strong sign-in protection and sensible configuration.

Email often provides access to other systems through password resets and sensitive information. Protect it as a critical business service.

12

Staff know how to challenge suspicious requests.

Train people to pause when asked to transfer money, disclose credentials, open unexpected attachments or bypass normal approval processes.

13

Microsoft 365 access and sharing are understood.

Review users, groups, administrator roles, external sharing, OneDrive and SharePoint access, and the services that are actually being used.

14

Cloud subscriptions have an owner and renewal process.

Record who owns each service, billing account, renewal date and recovery contact. Forgotten subscriptions can become both cost and security problems.

15

The network is documented at a useful level.

Record the main router/firewall, switches, Wi-Fi, important servers, remote access and key configuration details. Documentation should help someone troubleshoot without guessing.

16

Remote access is limited to what the business actually needs.

Review VPNs, remote desktop, third-party support tools and other external access paths. Remove old connections and protect active ones appropriately.

17

Critical suppliers are known and access is controlled.

List IT providers, software vendors, accountants, website providers and other suppliers with system access. Know what they can access and how access is removed.

18

Supplier security responsibilities are understood.

For important outsourced services, understand what the supplier protects and what remains your responsibility. Avoid assuming that “cloud” means every security control is automatically handled.

19

Devices are tracked through their lifecycle.

Know which devices exist, who uses them, whether they are supported, and what happens when they are lost, replaced or retired.

20

Important configurations and credentials can be recovered securely.

A backup of business files is not enough if nobody can rebuild the firewall, access the domain, restore Microsoft 365 administration or retrieve other critical configuration information.

21

There is a simple record of the IT environment.

Keep an up-to-date list of users, devices, critical services, suppliers, network equipment, licences and important contacts.

22

Security and operational alerts have somewhere to go.

Someone should know when important security or availability events occur. Avoid creating alerts that nobody reviews, but do make sure high-impact warnings have an owner.

23

A basic incident response plan exists.

Write down who should be contacted, which systems should be isolated, where key information is stored and how customers, suppliers or insurers should be involved when appropriate.

24

The business has tested at least one recovery scenario.

Choose a realistic scenario such as accidental deletion, lost laptop, compromised account or unavailable server. Walk through the response and record the gaps.

25

The baseline is reviewed after meaningful change.

New offices, acquisitions, major software changes, cloud migrations, new suppliers and staff growth can all change the risk profile. Recheck the baseline rather than treating it as a one-off exercise.

Turning checks into decisions

What a healthy baseline looks like

A healthy baseline does not mean every business has identical technology. A five-person consultancy and a 40-person manufacturer will have different systems, budgets and operational requirements.

The useful question is whether the business can explain its technology environment and make sensible decisions about it. You should be able to answer basic questions such as: Who has access to our most important systems? What happens when someone leaves? Which data would hurt us most to lose? How would we restore it? Who can change the firewall or domain? Which suppliers can access our systems? What happens if the person who normally manages IT is unavailable?

If those questions have clear answers, the business has a much better foundation for improving security and reliability.

Where to start if you find problems

Do not turn the baseline into a shopping list. A common mistake is to respond to every gap by buying another security product or service. Start by fixing ownership and the highest-impact weaknesses.

  • First: protect important identities, administrator accounts and email.
  • Second: confirm that critical data can actually be restored.
  • Third: bring unsupported devices and software under control.
  • Fourth: remove unnecessary access, especially for former staff and old suppliers.
  • Fifth: document what matters so recovery does not depend on one person's memory.

This order is intentionally practical. It focuses first on controls that can prevent a serious account compromise or make recovery possible after an incident.

How often should a business run the baseline?

For a small business, a full review every three to six months is a sensible starting point, with smaller checks after major changes. The exact interval should reflect the business rather than a rigid calendar.

For example, a company that has just moved email, opened a new office, introduced remote working, changed IT providers or acquired another business should review its baseline immediately. The same applies after a significant security incident or recovery test that exposes weaknesses.

External guidance

Use the baseline alongside trusted UK guidance.

The NorthWave baseline is our practical business checklist, not a certification or a replacement for professional advice. The UK National Cyber Security Centre provides detailed guidance on accounts, devices, email, backups and incident preparation.

NorthWave view

Good IT is an operating discipline, not a pile of products.

Security software, cloud services and managed support can all be useful, but technology works best when there is a clear operating model behind it. Someone owns the systems. Someone reviews access. Someone knows what must be recovered. Someone keeps documentation current.

That is why this baseline deliberately combines security with ordinary IT management. An unpatched laptop, an unknown administrator account, an undocumented firewall or an untested backup can each create a problem even when a business has already purchased security products.

The goal is not to make a small business feel like an enterprise IT department. The goal is to make important technology understandable, maintainable and recoverable.

01

Know what matters

Identify critical systems, data, accounts, devices and suppliers before deciding what to protect.

02

Protect access

Secure identities, restrict privilege and remove access that no longer has a business reason.

03

Prove recovery

Do not assume you can recover. Test the process and document what needs improvement.

Need a second pair of eyes?

Turn the baseline into an action plan.

If you have identified gaps and want help prioritising them, NorthWave can review the environment and discuss practical next steps.