Begin with ownership
For each computer, account and important application, name the person responsible for updates, access and recovery. A tool nobody checks is not a reliable control. Keep the register free of plaintext passwords and give it only to people who need it.
Free-first means using suitable built-in and open-source capabilities before purchasing something. It does not mean that staff time, replacement hardware or storage are free, or that every existing licence includes every advertised security feature.
Check the essentials
- Accounts: remove obsolete access, use unique passwords and enable available MFA. Review administrator privileges and keep a tested recovery method.
- Devices: check supported versions, update completion, the active antivirus provider and firewall state. Include rarely connected laptops.
- Network: document remote access, remove unnecessary public exposure and change default management credentials. Do not make the router's admin panel publicly accessible for convenience.
- Data: identify important information, limit access and verify a backup restore. Store a separated copy that ordinary compromised credentials cannot easily overwrite.
Use monitoring for a concrete purpose
An existing Zabbix installation can help identify disk, service or availability problems. An existing Wazuh deployment can collect selected security events. Both need hardware, maintenance and someone to respond. Do not introduce a large monitoring stack solely to add a product name to the checklist.
Choose a few useful alerts, such as sustained low disk space, backup failure and unexpected authentication patterns. Confirm a test event reaches the intended recipient. Reduce noise with deliberate conditions, not by disabling every alert.
Train one repeatable decision
Teach staff how to verify bank-detail changes and unexpected sign-in requests using an independent contact route. Provide a simple way to report a suspicious message without punishment for asking. Use harmless examples rather than real customer data in training.
Verify with evidence
Once a month, sample a patched device, an account with MFA, a restore and an alert-delivery path. Record the result and owner of any gap. For a critical business application, check that security changes do not break its supported workflow.
Common mistakes
RAID is not an independent backup, a green antivirus icon is not a full assessment and a password change does not remove every cloud session. Cloudflare web protection does not secure every endpoint or private service. Each control needs a defined scope.
Keep improving
Use the current Essential Eight guidance to prioritise the next gaps. Document what is implemented, what is unverified and what genuinely requires resources you do not yet have. An honest small checklist is more useful than an unsupported claim that the business is fully secure.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.