The cyber security checklist

Cyber Security Checklist

Cyber security is a key factor in the running of any small or medium sized business: while larger businesses may have the infrastructure to deal with cyber threats without too much damage to their operations, smaller businesses are faced with the financial, personal, and operational pressures that the aftermath of cyber threats can present. However, knowing what to do and when to do it can often be a ‘to-do’ that slips towards the bottom of the list, especially when the constantly changing work demands that the small business model creates rarely slow down.

So, to help SME’s, we’ve come up with a cyber security checklist to help you make sure that you’re as protected as possible. This isn’t an exhaustible list, but if you’d like to see if there are other considerations that might be specific to your business, you could talk to one of our team here. Before we get to the checklist, however, the most important question that any small business should be asking is what risks the business faces. Are you most vulnerable to physical threats or break-ins? Do you have particular levels of information which are more valuable than others? Do your staff know how to avoid cyber attacks, or at least reduce their likelihood? Thinking about these sorts of questions are key to working out your cyber-security priorities.

  1. Back up your data

Especially if your business is vulnerable to physical threats (i.e., break-ins) then backing up your data regularly and securely is a must. Some businesses still have physical back-up solutions, but if your premises are broken in to, or somehow vulnerable to physical damage, then moving your data to the cloud, as well as having multiple back-up solutions is a must.

  1. Perform risk assessments or drills

If you don’t know the risks your business might face, or aren’t sure if you know all of them, check! Performing risk assessments or cyber-breach drills are quick ways of revealing your blind-spots.

  1. Protect client data

While it may seem obvious, protecting certain, more valuable data is a must. You can do this through having different access levels to various parts of your infrastructure or checking that your current cyber-security protocols are strong enough.

  1. Evaluate ‘BYOD’ (Bring your own device) policies

While some BYOD policies can be a quick way for businesses to save on equipment and upkeep, they can also be a threat to your online security. BYOD policies struggle to regulate personal use of devices also used at work, which means that your systems could be vulnerable to attack from sources that are completely unrelated to the day-to-day function of your enterprise.

  1. Update your security policies and protocols regularly

If you’ve discovered some blind spots, update your systems! Additionally, updating regularly, even if you’re confident in your security, means that you are constantly ahead of any potential threats, making it harder for online criminals to take advantage of any lax protocols or defences.

  1. Protect yourself from malware

Investing in a good anti-malware software of strategy is a key step for any business, as the damage done by a malware attack can be huge. If you’d like to discuss what defences might look like for your business, one of our experts would be happy to talk to you.

  1. Implement Multi-Factor Authentication

MFA is becoming more and more popular, as it is a quick and easy way to add another layer of protection to your business at any level. Especially if you operate with a BYOD policy, then MFA protocols are simple to put in place and be crucial in preventing a breach. You can read more about them here.

  1. Use strong passwords

Related to MFA, passwords are your first line of defence. While they may not seem as important when there are so many other types of online security protocols, having a strong password is key, and incredibly easy to implement. If you’d like to hear more about what a good password could do for your business, you can find out more on our blog.

There are many other steps that a business can take to increase and maintain their cyber security; this is by no means an exhaustive list. Often, the best way to increase cyber security is to tailor your protocols to the needs and vulnerabilities of your business. If you’d like to hear what that could look like, you can speak to one of our experts or read about our managed IT services.