Free resource

Cyber Security Checklist for UK Businesses

A practical, one-page checklist covering Microsoft 365 hardening, phishing defence, backup strategy and cyber resilience — the essentials every UK SME should have in place.

Book a free consultation

1. Identity & Access (Microsoft 365)

  • Enforce MFA for every user, including admins and service accounts.
  • Disable legacy authentication protocols (POP, IMAP, SMTP AUTH where unused).
  • Use Conditional Access to block sign-ins from unexpected countries.
  • Review Global Admins quarterly — aim for two, no more than four.
  • Enable Self-Service Password Reset with strong verification.

2. Email & Phishing Defence

  • Turn on Safe Links and Safe Attachments (Defender for Office 365).
  • Publish SPF, DKIM and DMARC records — DMARC set to at least quarantine.
  • Enable external sender warnings in Outlook.
  • Run a phishing simulation and short training every quarter.
  • Block auto-forwarding to external domains by default.

3. Device & Endpoint Security

  • Full-disk encryption enabled on every laptop (BitLocker / FileVault).
  • OS and browser updates applied within 14 days of release.
  • Endpoint protection (Defender, or equivalent) active and reporting.
  • Screen lock after ≤10 minutes; strong device passcodes.
  • Mobile devices enrolled in Intune (or MDM equivalent).

4. Data, Backup & Recovery

  • Independent third-party backup for Microsoft 365 (mail, OneDrive, SharePoint, Teams).
  • Backups tested with a real restore at least twice a year.
  • Retention meets your regulatory and contractual requirements.
  • Critical shared drives have version history enabled.
  • A written incident response and recovery plan exists.

5. Governance & Resilience

  • Named owner for cyber security (internal or outsourced).
  • Cyber insurance in place and renewed annually.
  • Cyber Essentials certification current (or a plan to achieve it).
  • Vendor access reviewed quarterly — remove ex-suppliers.
  • Leavers offboarded within one business day (accounts disabled, tokens revoked).

Frequently asked questions

Questions about the cyber security checklist

How to use it, who it's for, and what to do once you've worked through it.

What is a cyber security checklist and why does my business need one?

A cyber security checklist is a short, practical list of the controls that prevent the majority of attacks against small businesses — multi-factor authentication, patching, backups, phishing defence and access review. It matters because most SME breaches are not sophisticated: they are stolen credentials, an unpatched laptop or a convincing invoice-redirection email. Working through a checklist converts a vague sense that security ought to be better into a finite set of tasks you can complete and re-check quarterly. It also gives you evidence to show insurers, clients and auditors that basic hygiene is in place, which increasingly determines whether you win certain contracts at all.

How long does it take to work through this checklist?

A competent Microsoft 365 administrator can complete most of it in a focused day, and the highest-impact items in under two hours. Enforcing multi-factor authentication across all users, disabling legacy authentication and reviewing the list of global administrators are the three changes that shift your risk profile most, and each takes minutes in the admin centre. Backup verification, DMARC configuration and Conditional Access policies take longer because they need testing before enforcement. Treat it as a quarterly cycle rather than a one-off project: run through the list every three months and the ongoing effort drops to an hour or so.

Is this checklist aligned with Cyber Essentials?

It covers the same five technical control areas that Cyber Essentials assesses — firewalls and internet gateways, secure configuration, user access control, malware protection and patch management — expressed as practical Microsoft 365 and endpoint actions rather than as certification language. Working through it will put you in a substantially stronger position before a Cyber Essentials assessment and will surface the gaps most likely to fail one. It is not a substitute for certification itself: Cyber Essentials requires a formal self-assessment questionnaire verified by an accredited body, and Cyber Essentials Plus adds a hands-on technical audit. Use this as preparation, not as proof.

Do I need an IT provider to implement these controls?

Not necessarily. Every item on the checklist can be completed by someone comfortable in the Microsoft 365 admin centre, and each is documented by Microsoft. Where a provider helps is judgement rather than clicks: deciding how aggressive a Conditional Access policy should be before it starts blocking legitimate work, or how to enforce DMARC without breaking a newsletter platform. If you have no one in-house, AlwaysOnIT's AI support can walk you through the items one at a time and explain the trade-offs as you go, for £4 per user per month. The controls themselves are free — they are configuration, not products.

How often should we review our cyber security posture?

Quarterly for the full checklist, and immediately after any significant change — a new starter with administrative rights, a leaver, a new SaaS application, an office move or a suspected phishing incident. Administrator accounts and third-party application consents deserve particular attention because they accumulate quietly: permissions granted for a short project routinely survive for years. Annual review is the bare minimum and is genuinely too slow for identity-related controls, where the threat landscape and Microsoft's own defaults both change several times a year. Put the quarterly review in the calendar as a recurring appointment with a named owner, or it will not happen.

© AlwaysOnIT — AI-run IT support for SMEs. Prepared for information only; not a substitute for a full security assessment.