Let’s talk

Cyvora / Cyber Learning Hub

Cyber security starting checklist for organisations

Identify the systems, responsibilities and improvements that deserve attention before choosing a larger security program.

A practical discussion guide for business owners and teams

By Cyvora · Published and updated 6 October 2026

01 / Map what matters

List the systems that support revenue, customers and daily operations. Identify sensitive information, key suppliers and the people accountable for each area. Record dependencies so an outage or incident can be discussed in business terms.

02 / Review the security foundations

Check account access, multi-factor authentication, software updates and backups. Confirm who removes access when people leave. Test that essential data can be restored rather than assuming a backup will work.

03 / Agree response responsibilities

Decide who leads incident decisions, who contacts technology providers and how staff report concerns. Keep important contacts accessible if normal systems are unavailable. Plan how recovery priorities and communications will be agreed.

04 / Choose the next assessment

Use business risk and known gaps to decide whether you need advisory, control review, penetration testing, privacy advice or operational support. Agree the objective, scope, authorisation, evidence and deliverables before work begins.

05 / Track improvement

Assign owners and realistic target dates to actions. Review progress and evidence of completion. Use a suitable framework as a planning aid, while confirming whether any contractual or regulatory requirement applies.

Turn the checklist into an action register

Record each gap in a way that another person can act on. Include the affected business service, the reason it matters, the action owner, the agreed next step and the evidence needed to show completion. Give dependencies a place in the record: an access review may need a current staff list, while a recovery exercise may need help from your IT provider.

Example: account access after staff departures

The issue is unclear ownership of account removal. The next step is to agree who notifies IT, which applications must be checked and how completion is confirmed. The evidence may be a completed offboarding record and a review of the relevant accounts. This is more useful than recording only “improve access management”.

A short, maintained list with accountable owners is a better starting point than a long plan nobody can update. Review unresolved actions when your technology, suppliers or business priorities change.

Choose the assessment that answers your question

Explore cyber security consulting for prioritisation, identity and access management for account controls, or penetration testing for authorised technical assurance. The small business cyber security page connects these options to a proportionate improvement plan.

Continue learning

This is a general starting point. Adapt the actions to your environment and responsibilities.

Read the official supporting guidance