
Home / Guides & Insights / IT security checklist
The 20-point IT security checklist for 10–250-person companies
The working baseline we hold our own clients to — with checkboxes you can actually tick, why each item matters, and the three everyone skips. No products to buy. Mostly discipline.
Twenty controls across five areas — identity, devices, network, data, and operations — form a defensible security baseline for a 10–250-person company. Most cost little or nothing beyond attention. Work through them in order inside each section; the checkboxes below are tickable, and your browser will keep them ticked while you work through the page.
This is the checklist we run when a company asks "where do we actually stand?" It maps loosely to CIS Controls and NIST CSF, but it's written in plain language, ordered by payoff, and shaped by what we find broken in real environments — including the ones that looked fine on paper. Tick honestly. "Sort of" is a no.
Identity — who can get in
Devices — the machines themselves
Network — the paths between things
Data — what you can't afford to lose
Operations — the habits that hold it together
The three items everyone skips
After enough assessments, the pattern is embarrassingly consistent. Restore tests (#15) — everyone has backups, almost nobody has restores; the difference surfaces at the worst possible moment. Offboarding (#5) — every company past 20 people has at least one ex-employee with something still live; we've found VPN access years stale. DMARC (#17) — an hour of DNS work, deferred indefinitely, while attackers spoof the company's own invoices to its own customers. If you do nothing else this month, do those three.
How to use this list without drowning
Don't try to close all twenty in a sprint. Take them by section: identity first (it's where the attacks are), then data (it's what limits the damage), then devices, network, operations. One or two items a week is a realistic pace for a working company, and in a quarter you'll be somewhere meaningfully different. Where a formal security assessment adds value over self-service is prioritization against your specific risks, evidence for insurers and auditors, and a fix plan sequenced so it actually gets done — but the twenty above are the spine either way.
What we actually find, by company size
Running this list against real environments produces patterns worth knowing before you start. At 10–50 people, the classic profile is strong cloud hygiene with physical-world gaps: Google Workspace or M365 reasonably configured, MFA mostly on — but the office router still has its ISP password, backups run to a NAS sitting on the same network they're protecting (#14 fails), and nobody has ever restored a file to prove they can (#15 fails). The fixes are cheap; the finding is that nobody owned the physical layer.
At 50–250 people, the profile inverts: there's tooling everywhere — often overlapping — but process debt. Offboarding drifts (#5: we routinely find former staff with live VPN or shared-mailbox access), admin separation erodes as convenience wins (#4), logs exist but land in four consoles nobody correlates (#19), and segmentation that made sense at 40 people never got redrawn for 150 (#10). Here the fixes are organizational: owners, calendars, and a quarterly hour of verification. The tooling budget usually doesn't need to grow at all — attention does.
Make it a ritual, not a project
The list decays; that's its nature. New hires arrive, servers appear, an exception made in March becomes permanent by June. The maintenance dose is small: quarterly, one hour — walk the twenty items, tick honestly, and open tickets for drift. Assign the hour to a named person, put it on the calendar, and have them keep the dated scorecards. Those scorecards quietly become your evidence pack for insurance renewals, customer questionnaires, and auditors — the same hour serves three masters. Companies that treat security as a annual heroic project stay perpetually behind; companies that treat it as a boring quarterly ritual stay quietly ahead.
Frequently asked questions
How much does it cost to implement all twenty?
Less than most owners fear. Roughly half are configuration and discipline (segmentation, offboarding, admin separation, DMARC, restore tests) with near-zero product cost. The paid items — EDR, password manager, DNS filtering, backup tooling — typically land in the tens of dollars per user per month combined at SMB scale.
What order should we tackle them in?
Identity first: MFA everywhere and same-day offboarding close the doors attackers actually use. Then ransomware-resistant backups with a tested restore. Then EDR and patching. That sequence buys the most risk reduction per week of effort.
Is this enough for compliance like SOC 2 or HIPAA?
It's the technical foundation, not the full frame. Frameworks add governance: policies, risk assessment, vendor management, evidence collection. But an auditor who sees these twenty genuinely working starts friendly — and gap-closing from here is far cheaper than from zero.
How long does it take to verify all twenty items?
The first honest pass is a focused afternoon if you have admin access and don't accept "probably" as evidence. Fixing what you find is the real timeline — typically a quarter at a sane pace. The quarterly re-check afterwards is an hour, which is the whole point of doing the painful first pass properly.
We have an IT provider — isn't this their job?
Ask them to walk this exact list with you, item by item, showing evidence rather than assurances. A good provider will enjoy the conversation. Evasiveness on #14, #15, or #19 tells you something important about what you're actually paying for.
Get your environment scored How our assessment works
Baseline guidance informed by CIS Controls v8.1 and NIST CSF 2.0, shaped by field experience. Checkbox state stays in your browser only — nothing is sent to us.