Free checklist · Nothing to download
Feel safer by Friday. Ten things a manager can put in place without an IT department, a budget round, or a single meeting about strategy.
Most attacks aren’t clever. In the Government’s own Cyber Security Breaches Survey 2025/2026, 43% of UK businesses identified a breach or attack in the previous year — and over half of those experienced phishing and nothing else. The ten steps below block the big four: dodgy emails, stolen passwords, ransomware, and fake payment requests.
Being straight with you: ticking all ten does not make you secure, and anyone who tells you a checklist can is selling something. What it does is shut the easy doors, so an attacker has to work for it — and most of them won’t bother. That is worth more than it sounds.
Complete these 10 essential steps to secure your business
Turn on the "code to your phone" step for email, banking, Microsoft 365, payroll, and anything sensitive. If it's important, it needs the extra step.
Make one rule: everyone uses long, unique passphrases (think 3–4 random words). Store them in a trusted password tool so people don't have to remember them.
Phones, laptops, apps. Set them to update automatically so fixes install while you sleep.
Back up your key files daily (or at least weekly). Once a month, actually restore one file to prove it works. Five-minute spot check.
Run a 10-minute scam awareness reminder monthly. Golden rule: if you weren't expecting an attachment, link, or bank-detail change—don't click, don't pay, don't reply.
No money leaves without a second person verifying changes to bank details by calling a known number (not the one in the email). Simple, powerful fraud blocker.
Set screens to auto-lock after a few minutes. Require a PIN/Face/Thumb to get back in. If a device goes missing, know who to tell and what to do.
Only trusted people can add apps. Everyone else asks first. Quarterly tidy-up: remove anything unused or unknown.
When someone joins, moves role, or leaves: add the right access, remove the wrong access, and shut down old accounts the same day.
Who to call, how to isolate a dodgy device (unplug Wi-Fi/ethernet), where to find backups, and who talks to customers. Print it and stick it by the kettle.
Where this list comes from
This isn’t a list I made up. Six of the ten — the second step on logins, password re-use, automatic updates, device locking, who can install software, and what happens when someone joins or leaves — are things a Cyber Essentials assessor will ask you about. That’s the UK Government-backed scheme, and plenty of public sector contracts now won’t start without it.
The other four — backups you’ve actually tested, teaching people to pause before they click, two pairs of eyes on payments, and a one-page plan for when something goes wrong — are not in the scheme. I’ve put them in anyway, because in fifteen years of doing this they are the four that decide whether a bad morning becomes a bad year.
If you need the certificate rather than just the habits, that sits inside the QuantumCare packages — prices published, no quote required.
No. It’s a practical worksheet you can use today. If you want help implementing it, that’s optional.
A simple, non‑technical set of 10 actions any manager can lead this week to cut the biggest day‑to‑day risks: dodgy emails, weak passwords, missed updates, payment fraud, and poor off‑boarding.
This checklist is for managers and business owners who want easy, practical wins they can implement this week to lower business risk — no jargon, no provider change, just clear actions. Ideal for teams of 5–100 on Microsoft 365 or Google Workspace.
You can start today. Most items are “set and forget.” Aim to complete the list by Friday, then test backups monthly and refresh the reminders monthly.
Keep day‑to‑day users without admin. Where admin is necessary, keep it to named people and time‑boxed tasks. Misuse of admin access can sit outside service guarantees — we’ll help you lock this down with minimal friction.

Innovation
Fresh, creative solutions.


Excellence

Systems Secure® Limited·Registered in England and Wales, company no. 07295869 6 The Meadow, Copthorne, West Sussex RH10 3RG·07702 896 910·[email protected]
How to check you’re dealing with usServing Crawley, East Grinstead, Brighton and businesses across Sussex · UK-wide remote support
Copyright 2026. Systems Secure. All Rights Reserved.