Starting point based on ISO/IEC 27001 and the Dutch AVG (GDPR).
The Basics ๐ย
Handle these first for a solid security foundation:
Create a clear overview of team members, roles and accountabilities โ within your organization (single source of truth).
Enable SSO โ (preferred option) / MFA (alternative option) everywhere. Enforce this where possible via software settings for all team members (e.g. in Google Workspace and Slack this is possible) ( full list hereโ ).
If devices are managed by the organisation: enable/enforce all steps from โ โ How to: devices ๐ป๐ฑโ .
Apply the principle of least privilege to your document managementโ (e.g. Google Drive): do colleagues only have access to information they need for their work? Is there sensitive data on the shared drive?
1. Policy & Documentation ๐ย
Draw up an โ โ Information Security policy for employeesโ required Describe goals, responsibilities and approach, and what you consider acceptable use of company assets. Have all employees sign it.
Draw up loan agreements required For company laptops and office tags/keys for example. Have all employees sign it.
Have non-disclosure agreements (NDAs) signed required By employees and external contractors. Can be part of the employment agreement.
Document a data breach procedureโ required Who does what in the event of an incident? GDPR reporting obligation = 72 hours to the supervisory authority.
Maintain a processing register recommended GDPR obligation: keep track of which personal data you process and why.
2. Access & Identity ๐ย
Enforce a strong password policy required Minimum 14 characters, no reuse. Use a password manager (e.g. Proton Pass). Always have new passwords generated by the password manager.
Enable SSO (preferred) / MFA everywhere required Plus set up a check (e.g. twice a year) to spot-check whether employees have SSO/MFA enabled on all tools where you cannot enforce it automatically. See also: โ โ SSO, yes or no?โ and โ โ SSO & MFA overview โ all toolsโ
Apply the principle of least privilege required Give employees access โ only to what they need for their work.
Onboarding and offboarding required Ensure that employees are granted or revoked access to the appropriate software and roles/permissions when joining or leaving.
Run an annual Drive access review recommended
Check for people who've left but still have accessโ , role changes not yet reflected in Drive permissions, and documents shared to personal accounts or set to "anyone with the link."
Avoid shared/generic accounts recommended Each employee gets their own account for traceability.
3. Devices & Endpoints ๐ปย
Enable disk encryption on all devices required BitLocker (Windows) or FileVault (Mac) on laptops and workstations.
Enable automatic updates required Keep OS, browsers and critical software always up to date.
Install antivirus/EDR software required On all company devices. E.g. Microsoft Defender, Malwarebytes.
Set screen lock after inactivity recommended Maximum 5 minutes, requires password or biometrics.
Establish a BYOD policy (personal devices) recommended Rules for when employees use their own devices for work (e.g. their phone).
Set up a remote IT support tool recommended So staff can get help with device issues remotely. See Remote IT Support Toolsโ for a comparison of options (TeamViewer, AnyDesk, Splashtop, and free built-in alternatives).
4. Cloud & Software โ๏ธย
Maintain an inventory of all software and services in use required Know which SaaS tools are in use (prevent shadow IT). E.g. in an authorization matrix.
Enter into data processing agreements with cloud providers required GDPR requirement when they process personal data on your behalf.
Set up and test regular backups โ required Test recovery of backups periodically and consult critical suppliers if needed.
Secure configuration of cloud environments recommended Use security benchmarks (e.g. CIS) for Microsoft 365, Google Workspace.
No sensitive data in personal cloud services recommended No company data in personal Dropbox, personal mailbox, etc.
5. Network ๐ย
Separate business Wi-Fi from guest Wi-Fi required Set up a dedicated guest network so visitors get internet access only, with no visibility into internal systems, files, or devices. Look for "Guest Network" in your router's settings, or search for your router model and "guest network setup" to find your manufacturer's instructions.
Firewall active on router and devices required Both at network level and at endpoint level.
Change the default router password required Replace factory settings immediately, keep firmware up to date.
6. People & Awareness ๐ฅย
Clear reporting point for security incidents required Everyone knows who to report suspicious situations to.
Provide security awareness training upon joining required Minimum: recognizing phishing, passwords, reporting procedure.
Conduct phishing simulations recommended Periodically test employees with simulated phishing emails.
Schedule annual refresher training recommended Keep security awareness alive with current examples of threats and best practices.
7. Monitoring & Auditing ๐ย
Enable logging for critical systems recommended Who logged in when? Changes to sensitive files.
Conduct an annual internal security review recommended Go through the checklist, update policies where necessary.
Periodically assess suppliers optionalCheck security certifications of critical suppliers.
Have a vulnerability scan or penetration test carried out optionalHave external testing done once customer data or critical systems are involved. Recommended if you deliver digital services to customers or process sensitive personal data at scale.
This checklist continues here: