01
Know what matters
Identify critical systems, data, accounts, devices and suppliers before deciding what to protect.
25 practical checks to help a UK small business understand whether its technology foundations are dependable, secure, documented and recoverable.
A small business does not need a complicated enterprise architecture to have good IT foundations. It does need to know what it relies on, who can access it, what is being maintained, what is protected and what would happen if something important stopped working.
This baseline is NorthWave Solutions' practical way of organising those questions. It is deliberately broader than a cyber security checklist: reliable IT also depends on devices, connectivity, software, suppliers, documentation and the ability to recover when something goes wrong.
How to use this guide
Work through the 25 checks with the person responsible for IT. Mark each item Yes, Needs attention or Not applicable. Do not try to fix everything at once. Start with identity, recovery and the systems that would cause the greatest business disruption.
The 25-point baseline
The checks below are grouped so a business can review its environment without needing to start with a long technical audit.
Priority 1
Identity, administrator access, MFA and recoverable backups come first.
Priority 2
Devices, software, email, network controls and suppliers need ownership.
Priority 3
Documentation, reviews, monitoring and incident planning prevent knowledge gaps.
List the systems that would stop or seriously disrupt the business if unavailable: email, finance, customer records, line-of-business applications, websites, file storage, phones or production systems.
Avoid accounts that only one person understands. Record ownership for Microsoft 365, domain/DNS, hosting, finance, backup, security and other critical services.
Prioritise email, administrator accounts, finance, remote access and other high-impact services. Where passkeys are supported, consider them for important accounts.
Know who has privileged access and why. Use separate administrator and everyday user accounts where practical, and remove access that is no longer required.
When someone leaves or changes role, review Microsoft 365, shared drives, cloud services, devices, VPNs, social accounts and third-party systems—not just their main mailbox.
Identify what must be recoverable and where the copies live. A synchronised folder is not automatically the same thing as a recoverable backup.
A successful backup job does not prove that recovery will work. Test a representative file or system and record what happened.
For each critical service, define a realistic recovery priority. A system needed within an hour has different recovery requirements from one that can wait two days.
Supported software should receive security updates. Keep an inventory so unsupported or forgotten devices do not become invisible risk.
Check that built-in or managed security controls are active and have not been disabled by a local setting, conflicting software or poor configuration.
Email often provides access to other systems through password resets and sensitive information. Protect it as a critical business service.
Train people to pause when asked to transfer money, disclose credentials, open unexpected attachments or bypass normal approval processes.
Review users, groups, administrator roles, external sharing, OneDrive and SharePoint access, and the services that are actually being used.
Record who owns each service, billing account, renewal date and recovery contact. Forgotten subscriptions can become both cost and security problems.
Record the main router/firewall, switches, Wi-Fi, important servers, remote access and key configuration details. Documentation should help someone troubleshoot without guessing.
Review VPNs, remote desktop, third-party support tools and other external access paths. Remove old connections and protect active ones appropriately.
List IT providers, software vendors, accountants, website providers and other suppliers with system access. Know what they can access and how access is removed.
For important outsourced services, understand what the supplier protects and what remains your responsibility. Avoid assuming that “cloud” means every security control is automatically handled.
Know which devices exist, who uses them, whether they are supported, and what happens when they are lost, replaced or retired.
A backup of business files is not enough if nobody can rebuild the firewall, access the domain, restore Microsoft 365 administration or retrieve other critical configuration information.
Keep an up-to-date list of users, devices, critical services, suppliers, network equipment, licences and important contacts.
Someone should know when important security or availability events occur. Avoid creating alerts that nobody reviews, but do make sure high-impact warnings have an owner.
Write down who should be contacted, which systems should be isolated, where key information is stored and how customers, suppliers or insurers should be involved when appropriate.
Choose a realistic scenario such as accidental deletion, lost laptop, compromised account or unavailable server. Walk through the response and record the gaps.
New offices, acquisitions, major software changes, cloud migrations, new suppliers and staff growth can all change the risk profile. Recheck the baseline rather than treating it as a one-off exercise.
Turning checks into decisions
A healthy baseline does not mean every business has identical technology. A five-person consultancy and a 40-person manufacturer will have different systems, budgets and operational requirements.
The useful question is whether the business can explain its technology environment and make sensible decisions about it. You should be able to answer basic questions such as: Who has access to our most important systems? What happens when someone leaves? Which data would hurt us most to lose? How would we restore it? Who can change the firewall or domain? Which suppliers can access our systems? What happens if the person who normally manages IT is unavailable?
If those questions have clear answers, the business has a much better foundation for improving security and reliability.
Do not turn the baseline into a shopping list. A common mistake is to respond to every gap by buying another security product or service. Start by fixing ownership and the highest-impact weaknesses.
This order is intentionally practical. It focuses first on controls that can prevent a serious account compromise or make recovery possible after an incident.
For a small business, a full review every three to six months is a sensible starting point, with smaller checks after major changes. The exact interval should reflect the business rather than a rigid calendar.
For example, a company that has just moved email, opened a new office, introduced remote working, changed IT providers or acquired another business should review its baseline immediately. The same applies after a significant security incident or recovery test that exposes weaknesses.
External guidance
The NorthWave baseline is our practical business checklist, not a certification or a replacement for professional advice. The UK National Cyber Security Centre provides detailed guidance on accounts, devices, email, backups and incident preparation.
NorthWave view
Security software, cloud services and managed support can all be useful, but technology works best when there is a clear operating model behind it. Someone owns the systems. Someone reviews access. Someone knows what must be recovered. Someone keeps documentation current.
That is why this baseline deliberately combines security with ordinary IT management. An unpatched laptop, an unknown administrator account, an undocumented firewall or an untested backup can each create a problem even when a business has already purchased security products.
The goal is not to make a small business feel like an enterprise IT department. The goal is to make important technology understandable, maintainable and recoverable.
01
Identify critical systems, data, accounts, devices and suppliers before deciding what to protect.
02
Secure identities, restrict privilege and remove access that no longer has a business reason.
03
Do not assume you can recover. Test the process and document what needs improvement.
Continue reading
Cyber Security
Work through practical checks for identity, devices, email, backups and incident readiness.
Open checklist →Cyber Security
A practical look at everyday security gaps and how to reduce avoidable risk.
Read article →Microsoft 365
Five practical areas to review across identity, access, email and devices.
Read article →Need a second pair of eyes?
If you have identified gaps and want help prioritising them, NorthWave can review the environment and discuss practical next steps.