1. Identify the data the business cannot operate without
List the information needed to serve customers, take payment, meet legal obligations and continue work. Include email, customer records, finance, bookings, documents, website data, cloud services and paper records. Record where the authoritative copy lives and who owns the system.
2. Check access rather than assuming it
For each important service, list active users, administrators and recovery addresses. Remove accounts that no longer need access. Replace shared logins with named users where the service supports them, and check that the business controls at least two appropriate administrator or recovery routes.
3. Verify backups with a restore
Cloud storage and synchronisation are useful, but they are not automatically a separate recovery copy. Record what is backed up, how often, how long versions are retained and who receives failure alerts. Then restore a sample file to a different location and open it.
4. Review devices and accounts
- Supported operating systems and current security updates
- Screen locks and device encryption where appropriate
- Multi-factor authentication on important online accounts
- Separate administrator access from everyday work where practical
- A documented process for lost devices and departing staff
5. Decide how the business would recover
Choose one realistic incident—lost laptop, compromised mailbox, deleted folder or unavailable website—and write the first five actions. The plan should identify who makes decisions, how providers are contacted, where recovery codes are held and how customers or regulators would be informed if necessary.
Turn observations into priorities
Rate each gap by business impact and likelihood. An unsupported computer holding the only copy of customer records is more urgent than a tidy-up of unused software. Assign every action an owner and date; an unowned recommendation is unlikely to become a control.
Data protection is risk-based
The right measures depend on the type and sensitivity of the personal data, the harm an incident could cause and the way the business operates. This checklist is operational guidance, not legal advice. The ICO's small-organisation resources explain UK data-protection responsibilities, while the NCSC small organisations guide covers practical cyber-security basics.
Need help applying this to your business?
Vengera can assess the current setup, explain the priorities and scope any practical improvements.