Security spending often starts with the most interesting product rather than the most useful one. The result is an organisation with a monitoring tool and no control over who can sign in.
These five controls are unglamorous. Between them they remove the largest share of the risk that small organisations actually face.
1. A second factor on every account
A stolen password should not be enough to read somebody’s mail. That means a second check at sign in for every account, including the administrator accounts and including the people who find it inconvenient.
This is the single highest return change available, because the common attack is not clever. It is a working password bought in bulk.
2. Updates that actually get applied
Operating systems, browsers, the applications people use and the network equipment nobody looks at. Most successful intrusions use a flaw that had a fix available.
The useful part is not the policy. It is the monthly evidence that machines are on the version you think they are, including the laptop of the person who never restarts.

3. A backup you have restored from
A backup that has never been tested is a hope rather than a control. Pick a file, pick a mailbox, restore them and write down the date.
Check also that the backup cannot be deleted by somebody with access to your normal systems. That is what separates a backup from a copy.
4. Email filtering and the habit behind it
Filtering removes most of the volume. It will not remove the careful message that arrives from a supplier’s real address and asks you to change bank details.
The control that catches that one is a rule: any change of payment details is confirmed by phoning a number you already hold. Written down, applied to everybody, no exceptions for urgency.
5. Nobody with more access than they need
Administrator rights handed out years ago, accounts still active for people who left, shared logins that several people use. Each one widens what a single mistake can reach.
Start with a list of who has administrator rights. In most organisations that list is longer than anybody expects, and shortening it is free.
What to do after those five
Once they are genuinely in place, the next steps are worth considering: device encryption, controlling which devices can reach your files, logging that somebody reviews, and awareness training that uses your own examples rather than generic ones.
Monitoring and testing come after that. They are useful, and they are wasted on an environment where the five controls above are still open.
How to know where you stand
- Can you say, today, how many accounts have a second factor?
- When was the last successful restore, and who watched it?
- How many people hold administrator rights, and why?
- What is the current rule for changing a supplier’s bank details?
- Which machine has the oldest version of anything?
Five questions, five plain answers. If any answer is a guess, that is where to start.
How to evidence each control
Having a control and being able to prove you have it are different things, and it is the second one that clients, insurers and funders ask about. For each of the five, this is the evidence worth keeping.
A second factor on every account. Keep a report from your identity platform showing registered methods per account, with the administrator accounts visible. A statement that it is enabled is not evidence. A list with the number of accounts still not covered is.
Updates applied. A monthly summary showing each machine and the version it is on, including the laptops that were switched off. The useful number is not the percentage patched, it is the name of the machine that is behind.
A backup you have restored from. A dated note of what was restored, by whom, and how long it took. One line per test. This is the single piece of evidence most organisations cannot produce and the one that carries the most weight.
Email rules and the payment check. The written rule itself, plus a note of when it was last explained to the people who pay invoices. If somebody can be asked at random and can state the rule, that is worth more than a policy document nobody has opened.
Least privilege. A current list of who holds administrator rights, with a reason beside each name, and the date it was last reviewed. Shorter is better, and the reasons are what stop the list growing again.
Keep all five in one place, updated as things change, rather than assembling them when a form arrives. That file is what turns a security questionnaire from a fortnight of chasing into an afternoon.
One more point about evidence. Do not overstate it. If a control is partly in place, say which part, and put the rest on a dated plan. An honest answer with a plan behind it reads better to an insurer than a confident yes that falls apart under a follow up question, and it is the version you can defend if something does go wrong later.
Where to read more
Our cybersecurity page sets out the layers we look at and the order we would work through them. The account and update work sits inside IT support, and the Microsoft side is on the Microsoft 365 page.
Ask us to review the five controls above and we will tell you which ones are already in place.