Security

No CISO, no problem: the first ten security controls for a company without a security team

Most breach stories start the same way, not with genius hackers, but with a missing basic. Ten controls, ordered by protection per dirham, that a company can implement without hiring anyone.

No CISO, no problem: the first ten security controls for a company without a security team

Security vendors sell fear by the enterprise shelf-full, and small companies conclude, wrongly, that real protection starts at budgets they do not have. The truth is less dramatic: most incidents we see exploit the absence of unglamorous basics. Here are the first ten controls, in the order protection-per-dirham actually runs.

Identity first (controls 1–3)

  1. Multi-factor authentication everywhere. Email first, then everything that supports it. The single highest-value change any company can make; most account takeovers die here.
  2. A password manager. Because the alternative is one password reused across forty services, and one leaked service unlocking all of them.
  3. Same-day leaver process. A written checklist that closes every account the day someone leaves. Quiet, boring, and the source of some of the ugliest incidents when skipped.

Machines second (4–6)

  1. Updates on autopilot. Operating systems and browsers patching automatically. Most ransomware walks in through a known, fixed, unapplied vulnerability.
  2. Disk encryption on every laptop. One setting, and a lost laptop stops being a breach notification.
  3. Proper endpoint protection. The built-in tools configured centrally beat the forgotten free antivirus from 2019.

Survival third (7–8)

  1. Backups that follow 3-2-1. Three copies, two media, one off-site or offline, because ransomware hunts backups first.
  2. A tested restore. Pick one system quarterly and actually restore it. A backup you have never restored is a rumour.

Humans fourth (9–10)

  1. Payment-change verification. A rule that any change of bank details or urgent payment request is confirmed by a phone call to a known number. This one sentence of policy defeats the most profitable fraud pattern in the region.
  2. Fifteen minutes of awareness, quarterly. Real examples, not compliance videos: what the fake invoice looked like, what the fake “CEO” message said.

What this list does not do

It does not make you certifiable, and it will not satisfy an enterprise client’s 200-row questionnaire, that is what assessments and frameworks are for, later. What it does is close the doors that actual incidents actually use, at a cost measured in configuration time rather than products. When you outgrow it, you will know: the questionnaire arrives, the audit is announced, and then the next step is an assessment, not panic.

Self-check

The baseline, honestly scored

Ten controls that stop most of what actually happens to small and mid-sized companies. Tick only what is true for everyone, not for the IT team.

A baseline, not an assessment. It says nothing about your specific systems, your suppliers, or the risks particular to your sector.

Start with a conversation

An initial consultation with a consultant rather than a salesperson, about your IT, security or systems question.