Workspace with laptop and notes during a systems review

Home / Guides & Insights / IT security checklist

The 20-point IT security checklist for 10–250-person companies

The working baseline we hold our own clients to — with checkboxes you can actually tick, why each item matters, and the three everyone skips. No products to buy. Mostly discipline.

Twenty controls across five areas — identity, devices, network, data, and operations — form a defensible security baseline for a 10–250-person company. Most cost little or nothing beyond attention. Work through them in order inside each section; the checkboxes below are tickable, and your browser will keep them ticked while you work through the page.

This is the checklist we run when a company asks "where do we actually stand?" It maps loosely to CIS Controls and NIST CSF, but it's written in plain language, ordered by payoff, and shaped by what we find broken in real environments — including the ones that looked fine on paper. Tick honestly. "Sort of" is a no.

Identity — who can get in

Devices — the machines themselves

Network — the paths between things

Data — what you can't afford to lose

Operations — the habits that hold it together

Ticked less than you'd like? That's normal — most environments we assess start under 12 of 20. Have us run this against your environment and hand you the honest scorecard.

The three items everyone skips

After enough assessments, the pattern is embarrassingly consistent. Restore tests (#15) — everyone has backups, almost nobody has restores; the difference surfaces at the worst possible moment. Offboarding (#5) — every company past 20 people has at least one ex-employee with something still live; we've found VPN access years stale. DMARC (#17) — an hour of DNS work, deferred indefinitely, while attackers spoof the company's own invoices to its own customers. If you do nothing else this month, do those three.

How to use this list without drowning

Don't try to close all twenty in a sprint. Take them by section: identity first (it's where the attacks are), then data (it's what limits the damage), then devices, network, operations. One or two items a week is a realistic pace for a working company, and in a quarter you'll be somewhere meaningfully different. Where a formal security assessment adds value over self-service is prioritization against your specific risks, evidence for insurers and auditors, and a fix plan sequenced so it actually gets done — but the twenty above are the spine either way.

What we actually find, by company size

Running this list against real environments produces patterns worth knowing before you start. At 10–50 people, the classic profile is strong cloud hygiene with physical-world gaps: Google Workspace or M365 reasonably configured, MFA mostly on — but the office router still has its ISP password, backups run to a NAS sitting on the same network they're protecting (#14 fails), and nobody has ever restored a file to prove they can (#15 fails). The fixes are cheap; the finding is that nobody owned the physical layer.

At 50–250 people, the profile inverts: there's tooling everywhere — often overlapping — but process debt. Offboarding drifts (#5: we routinely find former staff with live VPN or shared-mailbox access), admin separation erodes as convenience wins (#4), logs exist but land in four consoles nobody correlates (#19), and segmentation that made sense at 40 people never got redrawn for 150 (#10). Here the fixes are organizational: owners, calendars, and a quarterly hour of verification. The tooling budget usually doesn't need to grow at all — attention does.

Make it a ritual, not a project

The list decays; that's its nature. New hires arrive, servers appear, an exception made in March becomes permanent by June. The maintenance dose is small: quarterly, one hour — walk the twenty items, tick honestly, and open tickets for drift. Assign the hour to a named person, put it on the calendar, and have them keep the dated scorecards. Those scorecards quietly become your evidence pack for insurance renewals, customer questionnaires, and auditors — the same hour serves three masters. Companies that treat security as a annual heroic project stay perpetually behind; companies that treat it as a boring quarterly ritual stay quietly ahead.

Frequently asked questions

How much does it cost to implement all twenty?

Less than most owners fear. Roughly half are configuration and discipline (segmentation, offboarding, admin separation, DMARC, restore tests) with near-zero product cost. The paid items — EDR, password manager, DNS filtering, backup tooling — typically land in the tens of dollars per user per month combined at SMB scale.

What order should we tackle them in?

Identity first: MFA everywhere and same-day offboarding close the doors attackers actually use. Then ransomware-resistant backups with a tested restore. Then EDR and patching. That sequence buys the most risk reduction per week of effort.

Is this enough for compliance like SOC 2 or HIPAA?

It's the technical foundation, not the full frame. Frameworks add governance: policies, risk assessment, vendor management, evidence collection. But an auditor who sees these twenty genuinely working starts friendly — and gap-closing from here is far cheaper than from zero.

How long does it take to verify all twenty items?

The first honest pass is a focused afternoon if you have admin access and don't accept "probably" as evidence. Fixing what you find is the real timeline — typically a quarter at a sane pace. The quarterly re-check afterwards is an hour, which is the whole point of doing the painful first pass properly.

We have an IT provider — isn't this their job?

Ask them to walk this exact list with you, item by item, showing evidence rather than assurances. A good provider will enjoy the conversation. Evasiveness on #14, #15, or #19 tells you something important about what you're actually paying for.

Get your environment scored How our assessment works

Baseline guidance informed by CIS Controls v8.1 and NIST CSF 2.0, shaped by field experience. Checkbox state stays in your browser only — nothing is sent to us.