Security
Endpoint security checklist for a small business
Laptops, phones, browsers, and routers are part of the business system. Secure them as a set, with an owner, a recovery path, and a repeatable process for every device and account.
Know what is connected
Keep an inventory of company laptops, phones, tablets, routers, printers, cloud applications, and remote-access tools. Record the assigned user, operating system, support owner, location, warranty, and replacement or wipe process.
Unknown devices and shared administrator accounts make it difficult to investigate a compromise or remove access when someone leaves. Start with the devices that can reach customer, financial, or operational information, then expand the inventory.
Protect identity and access
Use individual accounts, multi-factor authentication, least privilege, screen locks, and a documented offboarding process. Administrators should use separate administrator identities instead of running daily work with full privileges.
Review external sharing, browser extensions, remote-access software, recovery addresses, and stale accounts on a schedule. A strong password does not compensate for a forgotten administrator account or an unprotected recovery method.
Patch the operating environment
Turn on automatic updates where appropriate, record exceptions, and test that critical applications still work after updates. Include operating systems, browsers, productivity software, routers, phones, firmware, and any internet-facing service.
When a device cannot be patched or supported, record the owner, business reason, compensating control, replacement date, and the information it can access. An exception without an end date becomes the permanent security baseline.
Control software and devices
Decide who may install applications, browser extensions, remote-support tools, and personal cloud-sync software. Keep business data out of unmanaged personal devices where the business cannot remove access or recover the information.
Use device encryption, secure screen locks, and a remote-lock or wipe process where the platform supports it. Test the process with a spare or test device before the business needs it during a loss.
Protect email and cloud accounts
Review administrator roles, sign-in alerts, forwarding rules, shared mailboxes, external sharing, and risky sign-ins. Require multi-factor authentication for administrators and users, and keep recovery contacts under business control.
A compromised mailbox can expose invoices, customer conversations, passwords, and reset links. Set a clear escalation path for suspicious forwarding rules, impossible travel alerts, unexpected login prompts, or a lost phone used for authentication.
Patch, back up, and recover
Security software is one layer. Keep an independent recovery path for a lost, stolen, encrypted, or compromised device and document who can approve a restore. A synchronised folder is not automatically an independent backup.
Schedule a small restore, open the recovered file, record the time, and confirm who would handle a full recovery. A green dashboard shows that a job ran; it does not prove that the business can use the result.
Prepare the incident handoff
Record what staff should do when a device is lost, a password is stolen, a suspicious attachment is opened, or a payment instruction changes unexpectedly. Preserve evidence, contain clearly compromised access, and avoid wiping a system before appropriate technical review.
Name the internal decision-maker, IT provider, insurer or legal contact where relevant, and the route for assessing personal-information exposure. This is an operational checklist, not legal advice or a substitute for incident response.
Compare provider scope carefully
A managed IT provider may package endpoint protection, Microsoft 365 administration, backup, monitoring, and incident support. Compare the actual device scope, response terms, ownership, exclusions, onboarding, and exit process rather than choosing a security label.
A provider listing or referral does not prove that a provider can secure the business environment. Check current coverage, credentials, contract terms, and response commitments.
Sources and further reading
Back to all guides Compare support options Compare software Compare hosting