Most security advice is a list. The list is the problem.

A list gives you thirty things to do and tells you nothing about which one matters most, what depends on what, or which ones cost nothing. Faced with thirty items and no order, most owners do the one that is easiest to buy - and buying is almost never the first step.

This is the order I actually use with customers. Seven phases, each one built on the phase before it. The first one costs nothing and you can finish it in two weeks without hiring anyone, including us.

How the phases fit together

If you have seen our process described as Assess, Secure, Manage, this is that process with the detail filled in. The assessment comes before Phase 1. Phases 1 through 5 are Secure. Phases 6 and 7 are Manage - and Phase 6 sends you back to a fresh assessment, which is what makes it a cycle instead of a project.

Phase 1 - Stabilize

Immediate. Almost entirely zero-cost. Two weeks.

These reduce the most risk for the least money, and every one produces a dated record you can show someone later.

  1. Verify full-disk encryption on every computer that touches company information, and write down the date and the result. If a machine is not encrypted, turn it on today.
  2. Create standard, non-administrator accounts for daily work. Nobody should be doing email in an admin account.
  3. Confirm the data protection agreements with your major platform vendors are executed and on file.
  4. Designate who owns security, in writing, dated and signed. It can be the owner. It cannot be nobody.
  5. Remove consumer and gaming software from work machines, and stop using personal messaging apps for anything work-related.
  6. Free up disk space anywhere a machine is close to full. A full disk silently breaks updates and backups, and you find out during the incident.
  7. Inventory which outside tools hold your customer information, and whether you have an agreement with each one. Anything live without an agreement is your most urgent item.
  8. Adopt what I call the twenty-second rule. Any unexpected link or request gets twenty seconds of scrutiny before anyone acts on it and, when in doubt, a phone call to a number you already had - never the number in the message. Twenty seconds is short enough that people actually do it, and long enough to catch almost everything.
  9. Move credentials into an encrypted password manager and delete every stored password list, spreadsheet, and sticky note.

Most of that costs nothing. It is yours to do whether or not you ever buy anything from anyone. Doing it this month materially changes what you can say about your business in a review.

Phase 2 - Establish

Documentation. Effectively zero-cost. Thirty to forty-five days.

This is where work you have already paid for becomes provable. Nothing here requires a purchase. It requires decisions written down and signed.

  1. Build the core policy set: privacy, acceptable use, access control, passwords, data confidentiality, mobile devices and BYOD, disaster recovery and business continuity, breach response, remote access, asset disposal, security awareness, third-party access, and user termination. Add a short policy governing how policies get reviewed.
  2. Pair each policy with evidence. A screenshot of enforced multi-factor settings attached to your access control policy is worth more than ten pages of policy language.
  3. Have every employee sign every policy, and keep the signatures.
  4. Write a one-page incident response plan: who gets notified, who decides, who calls your attorney and your insurance carrier, and what your state's breach notification clock actually requires.
  5. Write a short data handling standard - what must be encrypted, where files are allowed to live, what is never emailed, and what is never pasted into an outside tool.
  6. Make the AI decision now. Confirm whether the AI assistants your team uses are the licensed versions running inside your own tenant and covered by your vendor agreement, or the consumer versions. Those are different products with different data handling, and staff generally cannot tell them apart.
  7. Build a vendor inventory: every platform touching customer information, what each one holds, whether an agreement is on file, and the date it was signed. Flag anything signed under a prior business name.
  8. Set a retention standard in writing, once, so nobody has to decide it under pressure.
  9. Test a restore from backup and document what you restored and how long it took. A backup you have never restored is a hypothesis.

Structure creates freedom. Right now every decision about customer data lives in someone's head, which means every decision gets re-made under pressure. Writing it down once removes that weight permanently, and it is the highest-value unpaid work available to you.

Phase 3 - Build

Managed endpoints. The foundation everything above depends on.

The devices have to be under control before access policy can depend on their health.

  1. Managed patching - operating system and application updates applied and verified on a schedule.
  2. Managed endpoint protection - real detection and blocking on the machines themselves, not only at the email gateway.
  3. Proactive monitoring and alerting, with a defined escalation path when something fires. An alert nobody receives is not a control.
  4. Enforced secure configuration - encryption, screen lock, firewall, and baseline settings enforced and reported rather than assumed.
  5. Responsive help desk coverage. Technical problems get fixed before they turn into workarounds, and workarounds are how security controls quietly get disabled.
  6. Documented asset and configuration records you can produce on request.

It is worth being blunt about why this matters at small headcounts. Two unmanaged computers holding customer information carry the same obligation as twenty. If one is lost or stolen, your ability to prove it was encrypted, patched, and monitored is what determines whether it becomes a reportable breach or a bad afternoon.

Phase 4 - Protect

Identity and cloud. Sequenced after devices, because it depends on them.

  1. Conditional access tied to device compliance - access granted only to enrolled, healthy, recognized devices. A stolen session token on an unrecognized laptop stops working. This is the actual fix for session hijacking; everything else is mitigation.
  2. Centralized identity governance - enforced multi-factor authentication, least-privilege roles, and administrative identities kept separate from daily-use accounts.
  3. Data loss prevention across the whole tenant, not just outbound email - how information moves through file storage, chat, and collaboration tools too.
  4. Mobile device management for any phone or tablet that reaches company information: encryption, screen lock, app protection, and remote wipe.
  5. Zero-touch deployment, so a new computer arrives configured correctly and security does not depend on someone remembering a checklist.
  6. Centralized audit logging and retention - sign-in and activity records you can actually produce for a reviewer or a carrier.
  7. For fully remote teams, secure access applied at the point of connection rather than at an office network you no longer have.

Most of these capabilities are already sitting inside the cloud platform you pay for. They do very little until they are configured, monitored, and managed as a system.

Phase 5 - Govern

People and program. After the systems work is underway, not before.

  1. Annual training for every employee, with a completion record for each person.
  2. Weekly micro-trainings and reminders. Habits come from repetition, not from one long session in January.
  3. Phishing simulation with a one-click way for staff to report anything suspicious. The number that matters is whether reporting goes up and clicking goes down.
  4. Dark web credential monitoring, so you learn a password appeared in someone else's breach before an attacker uses it.
  5. Training built around the platforms your team actually opens, not generic theory.
  6. A risk assessment repeated on a schedule, because your environment and the threats both keep moving.
  7. Policy management with attestation tracking - who signed what, when.
  8. Two tabletop exercises, run and documented: a ransomware scenario, and a systems-are-down-mid-workday scenario covering how work continues on paper.

Training comes here rather than first for a specific reason. Teaching people to protect systems that are not yet protected teaches the wrong lesson. Something goes wrong anyway, and the training takes the blame for a gap it was never going to close.

Phase 6 - Validate

Stop asserting the controls work. Prove it.

  1. A refreshed independent assessment. Running one after Phases 1 through 5 produces the single most persuasive document you can hand anyone: a before and after.
  2. Ongoing external verification that the remediation held.
  3. Right-sized cyber liability and commercial crime coverage, placed with your broker.
  4. An evidence binder in one place: assessment, remediation plan, signed policies, training records, vendor agreements, device inventory, restore test, and tabletop documentation.

Phase 7 - Sustain

Compliance is a rhythm, not an achievement.

  1. Annual risk analysis and annual policy review, both dated and signed.
  2. Annual training cycle, with records retained.
  3. Update the plan as items close, so it always reflects reality rather than intentions.
  4. Trigger a fresh assessment when any of these happen: a new location, a new line of business, a platform change, a net change of about five staff, a new major customer or partner integration, or any security incident - whether or not it became a breach.

Where most businesses actually are

Phase 1, unfinished, without knowing it. That is not a criticism. It is what happens when security advice arrives as an unordered list and the only items with a price tag are the ones that get bought.

If you do nothing else after reading this, do Phase 1. It is free, it takes two weeks, and it changes what you are able to say about your business the next time someone asks.