Free · No sign-up required

The Startup Security Checklist

Everything a small business should have in place from day one — identity, devices, backups, data protection, and more — with a recommended tool for each item. The complete list, free to read and use.

In the portal — free to start

Track it as you go

Check items off, see your progress by category, and pick which tool you actually went with for each one.

 

Get a version built for your business

A short quiz on your size, budget, and industry filters this list down to what actually matters for you, in priority order.

1

Identity & Access

The single most important category. Weak identity is how most breaches start.

Core identity & device platform

The foundation the rest of this category builds on.

Microsoft 365 Business PremiumPaid

The single best investment for identity and security at SME scale. Includes Entra ID (enterprise SSO, MFA, and Conditional Access), Defender for Business endpoint protection, Intune MDM, Teams, SharePoint, and 1TB OneDrive per user. One licence covers identity, devices, collaboration, and email — no separate tools needed for most businesses under 300 people.

Password manager

Pick one and get everyone using it before you grow — much harder to retrofit later.

1Password TeamsPaid

The team password manager most security professionals recommend. Shared vaults, admin visibility of what is stored (not contents), and Watchtower alerts for breached or reused passwords. Establish the habit before you grow — it is much harder to retrofit.

BitwardenFreemium

Open-source alternative to 1Password. The free tier is enough for most small teams. Less polished but trusted by the security community, open-source, and independently audited. A credible choice if cost is a constraint.

  • Use a business domain for email — Not @gmail.com or a personal @outlook.com. Microsoft 365 or Google Workspace includes this. Looks professional and gives you control over the account.
  • Enable MFA on every account — Every account — Microsoft, Google, banking, cloud providers, everything. Use an authenticator app, not SMS. Microsoft Authenticator integrates tightly with M365.
  • Configure Entra ID Conditional Access — Enforce MFA on every sign-in, block legacy authentication protocols, and require compliant devices before granting access to company data.
  • No shared logins — every person gets their own account — If someone leaves, you can disable one account. With shared credentials you have to change passwords everywhere and audit where they were used.
  • Create an offboarding checklist — List every account that needs to be disabled or transferred when someone leaves. Review it each time someone joins — you will remember what you forgot.
2

Devices & Endpoints

Laptops and phones are the physical gateway into your business. Lock them down early.

Device management (company-owned)

Enrol and manage devices the business actually owns.

Microsoft Intune (via M365 Business Premium)Paid

Mobile Device Management (MDM) included in Business Premium. Enrol all company devices, enforce encryption and compliance policies (minimum OS version, screen lock, BitLocker required), deploy and update software remotely, and wipe lost or stolen devices — all from the Microsoft Admin Centre. No separate MDM licence needed if you are already on Business Premium.

RobopackPaid

Application packaging and deployment tool that works alongside Intune. Packages standard .exe installers into the .intunewin format Intune requires for silent deployment. Build your software catalogue once, push updates and new installs to every enrolled device without touching each machine. Critical for device management at any meaningful scale.

Device management for BYOD (personal devices)

A different problem to company-owned devices — protects company data on phones and laptops the business doesn't own, typically without fully enrolling someone's personal device.

Microsoft Intune App Protection Policies (MAM)Paid

A lighter-touch alternative to full device enrolment, built for BYOD: protects and can remotely wipe company data (email, Teams, OneDrive) inside managed apps on a personal phone or laptop, without the business taking control of the whole device. The right tool when someone wants to check work email on their own phone but won't (and shouldn't have to) enrol it fully.

Disk encryption

Built into the OS on both platforms — there isn't really a choice to make here, just make sure it's switched on.

BitLocker (Windows) / FileVault (Mac)Free

Full-disk encryption built into Windows 11 and macOS. If a laptop is stolen, the data is unreadable without the encryption key. Takes under 5 minutes to enable, and can be enforced and verified at scale via Intune compliance policies.

  • Configure Intune compliance policies — Require minimum OS version, encryption, screen lock with PIN, and Defender active. Devices failing compliance can be blocked from accessing email and SharePoint automatically.
  • Use Robopack to package and deploy standard apps via Intune — Build your standard software catalogue (browser, PDF reader, communication tools, line-of-business apps) once. Deploy and update them silently across all devices without visiting each one.
  • Enable automatic OS updates and enforce via Intune policy — Most successful breaches exploit known, patchable vulnerabilities. Patch management is the single biggest reducer of attack surface. Intune can enforce update rings so devices stay current.
  • Set a screen lock timeout of 5 minutes — Enforceable via Intune policy. Covers unattended devices in public places — coffee shops, client offices, shared workspaces.
  • Review the Intune device inventory quarterly — Intune shows every enrolled device. Remove devices that are no longer in use — ex-employees, retired hardware. An ex-employee device still enrolled is a live risk.
3

Email & Comms

Email is the most common attack surface. A few DNS records and good defaults go a long way.

Business email & productivity suite

Microsoft 365 Business PremiumPaid

Exchange Online for business email, Teams for communication, SharePoint and OneDrive for file storage. Microsoft's anti-spam and anti-phishing filtering is best-in-class. Defender for Office 365 (included in Premium) adds safe links, safe attachments, and anti-impersonation protection on top.

Google Workspace Business StarterPaid

The main alternative to M365. Gmail, Google Meet, Drive, and Docs. Better UX for some teams and marginally cheaper for the baseline plan. Security tooling is good but less integrated than M365 Premium — you will need third-party tools for endpoint security and MDM.

DNS management

Cloudflare (DNS)Free

Move your domain DNS to Cloudflare on day one. Free DDoS protection at the DNS layer, faster resolution globally, and the cleanest interface for managing SPF, DKIM, and DMARC records. Also makes SSL certificates and subdomain management straightforward. Note: Cloudflare doesn't manage every country-code domain suffix (e.g. .dk and some others require the local registrar's own DNS) — check Cloudflare supports your specific domain before migrating.

  • Set up SPF records for your email domain — A DNS TXT record that tells other mail servers which servers are allowed to send email as you. Prevents basic spoofing. Your M365 or Google Workspace setup guide walks you through this — it takes 5 minutes.
  • Set up DKIM signing — Your email provider gives you a CNAME or TXT record to add to DNS. Cryptographically signs outbound email — reduces spam score and makes impersonation harder.
  • Configure DMARC policy — Start with p=none (monitoring mode) to understand what is sending email as your domain. Move to p=quarantine then p=reject as confidence grows. Use a service like DMARC Analyser to read reports.
  • Store all company files in cloud storage — OneDrive, SharePoint, or Google Drive — not local drives only. If a laptop dies or is stolen, no files are lost. Also makes backup simple: the files are already in the cloud.
  • Enable anti-phishing and safe links protection — M365 Business Premium includes Defender for Office 365 which checks links and attachments in real time. Make sure it is configured — it is not always on by default.
  • Define what data can be shared externally — A simple one-pager: what can go in email, what needs a shared drive link, what should never leave the company. Agree it as a team before you are large enough for this to become a problem.
4

Backups & Recovery

The test of a backup isn't making it — it's restoring from it. Do both.

Cloud backup for devices & files

Microsoft 365 BackupPaid

Backs up Exchange Online email, OneDrive, and SharePoint on a schedule. If you are on M365, your email and files have a safety net here — but verify the backup policy is enabled and check the retention period. It does not replace a separate backup for anything outside of M365.

Backblaze Business BackupPaid

Simple, continuous cloud backup for laptops and desktops. Backs up everything not in cloud storage automatically — local project files, creative assets, application data. Cheap, reliable, and restores are straightforward. Good for anything that lives outside OneDrive or SharePoint.

Infrastructure backup (servers, VMs, databases)

Only relevant if you run anything beyond laptops and M365/Google Workspace.

Azure BackupPaid

Microsoft's cloud backup service for servers, VMs, and databases. If you run any infrastructure on Azure or on-premise servers, use this for policy-driven, consistent backup with geo-redundancy. Integrates natively with Azure Recovery Services.

  • List everything that would hurt to lose — Files, email, databases, code repositories, CRM data, accounting records, configuration. Write it down. Then check each one has a backup.
  • Store backups in a separate location from the original — Not on the same drive, the same server, or even the same cloud account. The 3-2-1 rule: 3 copies of data, 2 different media types, 1 offsite.
  • Test restoring from backup — Pick a folder or database, restore it from backup. Do this before you need it in an emergency. Most organisations discover their backup does not work at the worst possible moment.
  • Document your recovery steps — Even a simple one-page document: what to restore first, how to do it, who to call. The person who set up the backup may not be available when you need to restore.
  • Set a recovery time objective (RTO) — How long can you operate without your systems? 4 hours? 24 hours? Knowing this tells you how much to invest in backup infrastructure and whether you need hot standby systems.
Related guide →
5

Business Systems

The everyday tools — CRM, accounting, contracts — are part of your security posture too.

CRM

HubSpot CRMFreemium

The best free CRM for early-stage businesses. Contacts, deals, email tracking, pipeline view, and basic automation — all free. The free tier is genuinely sufficient for most companies under 50 people. Do not track customers in spreadsheets: you will lose deals, miss follow-ups, and have no audit trail.

Accounting software

Xero / FreeAgentPaid

Cloud accounting software. Xero for most businesses; FreeAgent if you are a freelancer or small consultancy. Non-negotiable — running financials in spreadsheets creates compliance risk, makes tax painful, and gives you no real-time view of your numbers. Both integrate with HMRC Making Tax Digital.

E-signature

OpenSignFreemium

Free, open-source alternative to DocuSign if budget is the priority — legally binding e-signatures with a full audit trail. Self-host it for genuinely free, or use their hosted tier if you don't want to run it yourself. Less polished and fewer integrations than DocuSign, but a credible choice for an early-stage business watching costs.

DocuSign / Adobe Acrobat SignPaid

E-signature software for contracts, NDAs, and agreements. Legally binding in the UK. Provides a full audit trail: who signed, when, from what device and IP. Do not email Word documents for signatures — you have no proof of what was agreed or who agreed it. UK-legal for standard contracts and NDAs (though not every use case — e.g. some deeds still require a witnessed wet signature; check if in doubt).

Data protection registration

A one-off registration, not really a "pick one" decision — but worth tracking here since it's easy to forget.

ICO RegistrationPaid

The ICO is the UK's data protection regulator — this registration is UK-specific. If you process any personal data and are UK-based, UK GDPR requires you to register. Most businesses are Tier 1 (£40/yr). Takes 10 minutes at ico.org.uk. If you're not UK-based, check your own jurisdiction's equivalent (e.g. the relevant EU supervisory authority, or your national data protection authority).

  • Get a basic cyber insurance policy — Increasingly required for government contracts and enterprise tenders. Usually £200–800/yr for SMEs. Covers incident response costs, legal fees, and some business interruption losses.
  • Write a simple acceptable use policy — One page: what employees can and cannot do on company devices and accounts. Matters for insurance claims and demonstrates you took reasonable precautions.

Want this tracked and tailored to your business?

In the Fortify portal, a short quiz on your size, budget, and industry turns this into a prioritised list built for you — then you track progress against it as you actually go through it.