A security conversation can start with the products already installed: antivirus, a firewall, a backup subscription. Those are useful things to review. To judge whether they address your needs, first connect them to the business systems and information they are meant to protect.
Write down what happens if an important system stops working, information is exposed, or records are changed without permission. That gives you a basis for comparing priorities. Without it, a familiar product renewal can receive attention while a less visible dependency, such as a registrar account or shared administrator login, goes unreviewed.
So start earlier than the products. Start with the inventory.
Step one: write down what you actually have
Begin with a shared document that the right people can maintain. Aim to list:
- The systems that hold your money — banking, payment processing, payroll, accounting.
- The systems that hold other people's data — customer records, patient or client files, HR records.
- The identity systems everything else depends on — your email tenant, your single sign-on, your domain registrar.
- The systems your daily operations stop without — scheduling, point of sale, specialist applications your team depends on.
- Every place your business data physically or logically lives, including the personal devices people use for work and storage accounts created for individual projects.
The exercise can reveal overlooked accounts and dependencies. Pay particular attention to email and identity systems: some services send password resets through a mailbox, so access to that mailbox may affect other accounts. Check the actual recovery arrangements rather than assuming every system works the same way. Include devices and applications as well; the priorities depend on your environment.
Step two: ask what a bad day looks like
For each item on the list, answer three questions in one sentence each. What happens to the business if it becomes unavailable for a day? What happens if the data in it is exposed? What happens if the data in it is quietly altered and nobody notices for a month?
Consider a hypothetical twelve-person professional services firm. The team might be able to keep serving existing clients during a website outage, while an email outage interrupts approvals and a file-store incident requires a separate assessment of confidentiality and recovery. Another firm could depend primarily on online orders and rank the website first. The useful result is a documented comparison based on how this particular business operates.
That ranking is the whole point. It converts an unbounded worry into a short list of things that deserve money and attention first.
Step three: fix the foundations before the sophisticated parts
Review foundational controls alongside any specialist protection your systems require. Check whether each control is enabled, maintained and appropriate for the information involved.
Multi-factor authentication is the clearest example. CISA's guidance to small and medium businesses treats it as an essential layer: something you know combined with something you have, so a stolen password alone is not enough. Turn it on for email, for the domain registrar, for banking, for remote access, and for administrator accounts everywhere it is available. MFA reduces the risk from a stolen password alone. It does not prevent every attack, and available methods differ in their resistance to phishing.
Next, review administrator rights with the people responsible for each system and remove unnecessary access through an agreed change process. Test restoration from backups and review whether separate administration or immutable storage would help protect those copies. Assign ownership for updates and document the departure process, including account access, company devices and confirmation that each step is complete.
Step four: document decisions and responsibilities
Documentation helps an improvement survive staff and provider changes. Record why a setting matters so a future administrator can assess the consequences before changing it.
Keep a short living record: what you have, who is responsible, what has been changed and why, and what you have consciously decided not to do yet. That last category matters. A deferred item needs an owner, a reason and a review date so it does not disappear from view.
A realistic first-quarter plan
- Start an inventory, then ask system owners to check the gaps.
- Rank the top five systems by consequence rather than by cost.
- Enable multi-factor authentication on email, domain registrar, banking and remote access.
- Review administrator accounts and remove what is not needed.
- Verify a real restore from backup, end to end, and note how long it took.
- Write the staff-departure checklist and name who runs it.
- Record what you deferred, and put a date on revisiting it.
What this does not achieve
These steps provide a starting point for managing risk. Controls reduce likelihood and limit damage; they do not eliminate risk. A determined attacker, a supply-chain compromise, or a well-crafted message on a bad day can still get through a competent setup.
A clear inventory, consequence ranking and documented decisions can support an incident response. Determining what was exposed still requires evidence and investigation, but knowing the systems, contacts and recovery arrangements gives the responding team a more useful starting point.
Choose an owner for the follow-through
For each action, name the person who can approve it, the person who will carry it out and the evidence that will show it worked. A backup task, for example, should produce a restore result rather than only a screenshot of a successful backup job. An access review should record whose permissions were checked and what exceptions remain. Keep sensitive account details in your approved credential system rather than in the inventory itself.
Schedule a short review after the first changes. Ask whether the inventory is still accurate, whether anyone is working around a new control, and whether an unresolved dependency affects the next step. This turns a list of good intentions into work that can be checked and maintained.
Your next step
Do the inventory. Not the ideal version — the version you can finish this week on one page. Then look at the top three lines and ask whether the protection around them matches the consequence you just wrote down.
ALCO USA Inc helps organizations assess, strengthen and document their technology so improvements follow a plan rather than a product catalog. If you would rather work through it with someone, that is what the conversation is for.
Sources and further reading
CISA on requiring multi-factor authentication: https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/require-multifactor-authentication
ALCO services: https://alcohq.com/services