Technical foundations
The IT security foundations every business should have
Six controls that rule out most realistic scenarios, and why most organizations already own part of them without knowing it.
Key points
- Six controls cover most of the realistic scenarios a smaller business faces.
- They are treated in order: access first, because a weakness there cancels out the rest.
- A significant share is often already included in current licences, simply never enabled.
- None requires an in-house team; all require that someone be accountable for them.
Why six controls, and not thirty?
Because the scenarios that actually affect smaller businesses are few and repetitive: a hijacked account, an opened attachment, an unusable backup, an unpatched component. The controls that rule them out are therefore few as well. The rest belongs to a higher level of rigour, useful later.
This economy of means is not a sales simplification: it is what public authorities recommend, publishing deliberately short baseline control lists aimed at small organizations.
The opposite error exists too. An organization deploying thirty controls without having handled the first six ends up with a sophisticated, fragile posture: plenty of tooling, and a door still open.
Order therefore matters as much as the list. We always start with access, because a weakness there renders everything done elsewhere ineffective.
What are the six foundations?
Multi-factor authentication, tested 3-2-1 backups, patch management, least privilege, segmented remote access, and email protection. They overlap heavily with what insurers and enterprise customers now require: treating them serves several ends at once.
- Multi-factor authentication. On email, remote access and administrative accounts. It is the control with the best ratio of effort to risk removed, and the one most undermined by exemptions granted for convenience.
- Tested 3-2-1 backups. Three copies, two media, one off-site, and above all a restore actually performed on a known date. A backup never restored remains a hypothesis.
- Updates and patching. A process, however simple, covering workstations, servers and network equipment. The absence of a process shows: it is always the same machines that get forgotten.
- Least privilege. Administrative accounts separated from day-to-day accounts, and a periodic review of who holds what. Rights accumulate quietly over the years.
- Segmented remote access. Limit what remote access can reach, rather than opening the whole network to anyone who connects.
- Email protection. Domain authentication, filtering, and monitoring of automatic forwarding rules: a quiet and frequently used vector.
What you already pay for and do not use
A significant share of these foundations is frequently included in licences already held (enterprise productivity suites in particular)and has simply never been enabled. That finding changes the nature of the work: configure and document, rather than acquire.
There is nothing unusual about this. These capabilities are rarely on by default, enabling them requires decisions that affect users, and nobody has time to inventory what a licence contains.
It has a practical consequence. Before recommending any purchase, we check what the existing estate already covers. It also makes our recommendations verifiable: we resell no licences, so concluding "you already own the tool" costs us nothing.
Where a purchase remains necessary, you make it directly with the vendor or your usual reseller.
What about the impact on users?
It is real, and it is prepared for. Multi-factor authentication adds a daily step; least privilege removes rights some people were using. Treating these controls as a purely technical rollout is the surest way to see them worked around.
The sequence that works is always the same: announce it, explain the reason, deploy in groups, and handle the edge cases before they turn into permanent exceptions.
Exceptions deserve particular attention. They are almost always requested by the people whose access is most sensitive (executives, finance, administration)that is, exactly the people an attacker targets first.
An exception can be justified. It must then be written down, time-limited, and reviewed. A verbal, permanent exception is a gap documented nowhere.
Frequently asked questions
Less than people expect, provided the right method is chosen and it is not demanded at every action. On a familiar device in a familiar place, verification is infrequent. What creates resistance is not the control itself but rolling it out with no explanation or support, and that is precisely the part we handle with you.
The only way to know is to restore. A backup that runs without error is not a verified backup: you have to have recovered a file, a database, a whole server, and measured how long it took. Many organizations discover on that occasion that restoration is possible but would take several days, which changes their continuity plan entirely.
Not necessarily, and we always start by checking what the existing estate covers. In many situations the required capabilities are present in current licences but switched off. We recommend a change only where the gap is real and documented, and since we resell no licences, that recommendation earns us nothing.
Possible, but rarely advisable. Deploying six controls simultaneously multiplies friction points and makes it impossible to identify what is causing trouble. We proceed in stages, starting with access, with a checkpoint at each step. The pace adapts to your capacity to absorb it, not the other way round.
Someone named, internally or at a provider, with a periodic checkpoint. It is not a heavy load, but it cannot be implicit: without a designated owner these controls degrade silently. That is one of the reasons ongoing support exists.
Sources
- Canadian Centre for Cyber Security: Baseline cyber security controls for small and medium organizations · reference control list
- Canadian Centre for Cyber Security: Backing up and recovering your data · guidance on the 3-2-1 rule
- Commission d'accès à l'information du Québec · requirement for security measures proportionate to the sensitivity of the information
Is your infrastructure ready for the next threat?
An initial assessment, free and without commitment, to evaluate your security posture.