As we enter another year, business and technology leaders face growing challenges in protecting their organisations. Not enough qualified security professionals. Legacy systems that need modernising. Increasingly sophisticated attacks. In the face of all of this, you might reasonably ask: where do I start?

Cyber security is not a one-time event. It is a continuous process that requires ongoing attention. But that does not mean it has to be overwhelming. Here are five practical steps you can start taking today.

Security does not have to be complicated. The basics, done well, stop the majority of attacks. Start here.

1. Identify and document your systems

Create a list of all your information technology systems: the hardware, software, and network components that enable your organisation to collect, process, store, and communicate data. This inventory tells you what you have, where it is, what it does, and what data it holds.

Without this list, you are trying to protect something you cannot fully see. It also helps you prioritise where to focus your security efforts and provides a starting point for any security review. Plan to review and update it regularly as your environment changes.

2. Enforce multi-factor authentication on important systems

Multi-factor authentication (MFA) is one of the most effective security measures available. It adds an extra layer of verification beyond a password, making it significantly harder for attackers to access your systems even if they have stolen credentials.

MFA alone blocks the vast majority of account-based attacks. If you are not using it on your critical systems today, that is where to start. For Microsoft 365, you can report on MFA status across your user base to identify gaps and exceptions. Exceptions are sometimes unavoidable but they should be documented and reviewed regularly.

3. Create an incident response plan

An incident response plan outlines how your organisation will handle a cyber security incident. It helps you detect and contain threats quickly, minimise disruption, and recover as fast as possible. Without one, a minor incident can become a major one simply through confusion about who does what.

A good incident response plan will help you:

  • Reduce the likelihood and impact of cyber attacks
  • Quickly detect and contain threats before they spread
  • Minimise disruption to your operations
  • Improve your posture over time by learning from each incident

Every organisation is different, so the plan needs to be tailored to your specific context. And one practical note: print it out and put it somewhere safe. If your systems are down, you still need to be able to read it.

4. Patch everything, and without delay

Patching is the process of updating software to fix known security vulnerabilities. Attackers actively look for unpatched systems because they represent a known, easy way in. The longer you wait to apply a patch, the longer that window of exposure stays open.

A patch management policy sets out how your organisation will prioritise and apply patches, including timeframes based on severity. Do not forget to include network infrastructure such as switches and firewalls, not just workstations and servers. If a patch is delayed, the reason and the risk should be documented and communicated to whoever owns that risk in your organisation.

5. Uplift your staff capability

Your people are both your biggest vulnerability and your strongest asset in cyber defence. Attackers target them because social engineering and phishing work. But a well-trained, security-aware team is also your first line of defence.

A comprehensive training programme should include phishing simulations, in-person or remote education sessions, and computer-based training that adapts to individual knowledge levels. One-size-fits-all annual training is a compliance checkbox, not a security programme. The goal is genuine behaviour change, not a completed module count.

These five steps are not a complete security programme. They are the foundation. Get these right first, then layer on top.

Where to from here?

As a leader, you can be confident that starting with these foundations will significantly improve your security posture. Not every organisation needs a Security Operations Centre or a CISO. But every organisation needs to know what it has, protect its accounts, have a plan for when things go wrong, keep its software current, and invest in its people.

If you are not sure where you stand on any of these, a security assessment is a practical starting point. We will tell you honestly what is working, what is not, and what to prioritise.

Want to know where your organisation actually stands?

A security assessment gives you a clear picture and a prioritised list of what to do next.

Learn about security assessments