Skip to content

5 min read

Most incidents at small and mid-sized organizations trace back to identity: a reused password, an account without multi-factor authentication, or a departed employee whose access was never removed.

Enforce multi-factor authentication everywhere it is available, starting with email and administrative accounts. Then reduce the number of accounts holding administrative rights.

Run access reviews on a schedule. Ownership of shared mailboxes, file locations and third-party SaaS tools drifts constantly.

Test restores, not just backups. A backup that has never been restored is an assumption.

Write down onboarding and offboarding steps. Consistency is the control that survives staff turnover.