Know what matters
Assign ownership, define acceptable risk, and keep an inventory of critical systems, data, accounts, and suppliers.
Defensive practice guide
A practical starting point for teams that need to protect systems, prepare for incidents, and retain useful evidence for customers, auditors, and internal leaders.
Assign ownership, define acceptable risk, and keep an inventory of critical systems, data, accounts, and suppliers.
Use phishing-resistant MFA where possible, password managers, least privilege, and regular administrator-account reviews.
Track assets, act on actively exploited vulnerabilities, and set clear patch and exception timelines.
Back up important data, protect backup access, and periodically prove that a restore actually works.
Centralize appropriate logs, define who reviews alerts, and preserve enough context to investigate safely.
Keep contacts, decision rights, containment steps, and communications paths current before an incident occurs.
Open a topic for a concise implementation checklist and the evidence that makes the practice repeatable.
List the systems that run the business, the information they hold, the person accountable for each, and whether they are internet-facing or managed by a supplier.
Most security programs become more resilient when access is tied to named people, protected by MFA, and limited to the level needed for the job.
Prioritize internet-facing, critical, and known-exploited weaknesses. Pair scanning or vendor notices with validation, assignment, remediation, and documented exceptions.
Backups are only useful when the right people can restore the right data within the time the business can tolerate. Protect backup administration separately from everyday access.
Define the events that need attention, who owns the response, how to contain safely, and how the organization will communicate and recover.
Third parties and new tools can introduce sensitive data, privileged connections, or business dependency. Treat adoption as a risk decision—not just a purchasing decision.