1. Backups you have actually restored
Keep more than one copy, keep one of them away from your production environment, and restore something on a schedule. A backup job with a green tick is not evidence that your data is recoverable.
2. Multi-factor authentication everywhere
Email, remote access, finance systems, admin accounts — all of them. Stolen passwords are traded in bulk, and MFA is the single control that most reliably stops them being useful. App-based or hardware factors are stronger than SMS.
3. Patching that happens without anyone remembering
Operating systems, browsers, and the applications your staff actually use. Attackers rely on known vulnerabilities far more than novel ones, so automated patching with reporting closes most of the gap.
4. Endpoint protection on every device
Including laptops that leave the office and any personal devices touching company data. Protection you can see centrally is worth more than protection installed and forgotten.
5. Least-privilege access
Staff should have the access their role needs and no more, administrator rights should be separate from daily accounts, and departures should trigger same-day removal. Old accounts are a standing invitation.
6. Monitoring on the things that matter
Servers, internet connectivity, firewalls, and backup jobs. Knowing something failed at 1am is the difference between a quiet fix and a lost morning.
7. An incident plan on one page
Who to call, in what order, with what information. Include your provider, your insurer, and the internal decision-maker who can authorise taking systems offline. Write it before you need it and keep a copy outside your systems.
8. Documentation that isn't in one person's head
Network layout, key accounts, licence details, vendor contacts, and how the important systems fit together. This is the difference between a two-hour recovery and a two-day archaeology project.
9. Licence and asset visibility
Know what you own, what you're paying for, and what's no longer used. Most businesses that audit their subscriptions find something to switch off.
10. A defined path for support
Staff should know exactly how to raise an issue, and it should not be a text message to whoever is best with computers. A single intake point produces history, patterns, and problems that get solved permanently rather than repeatedly.
Want this handled for you?
CoreTech provides 24/7 monitoring, security operations and help desk support for businesses across Auckland and New Zealand.