AHANIX working resource
Cybersecurity Basics Checklist
A small-business starting point for accounts, devices, email, updates, backups, suppliers and incident preparation.
For: UK small businesses organising basic cyber risk responsibilities.
Section 01
People and accounts
- Use unique passwords and a suitable password manager.
- Enable MFA on email, finance, website, cloud and administrator accounts.
- Remove leavers and review shared or privileged access.
- Give staff a clear route to report suspicious messages or account activity.
Section 02
Systems and information
- Maintain supported devices, operating systems, applications and website software.
- Encrypt and lock portable devices appropriately.
- Limit access to sensitive information and record important suppliers.
- Keep protected backups and test recovery.
Section 03
Prepared response
- Write down incident contacts and immediate containment steps.
- Preserve useful evidence rather than deleting everything in panic.
- Plan legal, regulatory, insurer, supplier and customer escalation where relevant.
- Review lessons and controls after incidents or major near misses.