Starting point based on ISO/IEC 27001 and the Dutch AVG (GDPR).
The Basics
Handle these first for a solid security foundation:
Create a clear overview of team members, roles and accountabilities within your organization (single source of truth).
Enable SSO (preferred option)/ MFA (alternative option)everywhere. Enforce this where possible via software settings for all team members (e.g. in Google Workspace and Slack this is possible) (full list here).
If devices are managed by the organisation: enable/enforce all steps from How to: devices 💻📱.
Apply the principle of least privilege to your document management (e.g. Google Drive): do colleagues only have access to information they need for their work? Is there sensitive data on the shared drive?
Draw up an information security policyrequiredDescribe goals, responsibilities and approach, and what you consider acceptable use of company assets. Have all employees sign it.
Draw up loan agreementsrequiredFor company laptops and office tags/keys for example. Have all employees sign it.
Have non-disclosure agreements (NDAs) signedrequiredBy employees and external contractors.
Document a data breach procedurerequiredWho does what in the event of an incident? GDPR reporting obligation = 72 hours to the supervisory authority.
Maintain a processing registerrecommendedGDPR obligation: keep track of which personal data you process and why.
2. Access & Identity
Enforce a strong password policyrequiredMinimum 14 characters, no reuse. Use a password manager (e.g. Proton Pass). Always have new passwords generated by the password manager.
Enable SSO (preferred) / MFA everywhererequiredPlus set up a check (e.g. twice a year) to spot-check whether employees have SSO/MFA enabled on all tools where you cannot enforce it automatically. See also: SSO, yes or no? and SSO & MFA overview — all tools
Apply the principle of least privilegerequiredGive employees access only to what they need for their work.
Onboarding and offboardingrequiredEnsure that employees are granted or revoked access to the appropriate software and roles/permissions when joining or leaving.
Run an annual Drive access reviewrecommended
Check for people who've left but still have access, role changes not yet reflected in Drive permissions, and documents shared to personal accounts or set to "anyone with the link."
Avoid shared/generic accounts recommendedEach employee gets their own account for traceability.
3. Devices & Endpoints
Enable disk encryption on all devicesrequiredBitLocker (Windows) or FileVault (Mac) on laptops and workstations.
Enable automatic updatesrequiredKeep OS, browsers and critical software always up to date.
Install antivirus/EDR softwarerequiredOn all company devices. E.g. Microsoft Defender, Malwarebytes.
Set screen lock after inactivityrecommendedMaximum 5 minutes, requires password or biometrics.
Establish a BYOD policy (personal devices)recommendedRules for when employees use their own devices for work (e.g. their phone).
4. Cloud & Software
Maintain an inventory of all software and services in userequiredKnow which SaaS tools are in use (prevent shadow IT). E.g. in an authorization matrix.
Enter into data processing agreements with cloud providersrequiredGDPR requirement when they process personal data on your behalf.
Set up and test regular backups requiredTest recovery of backups periodically and consult critical suppliers if needed.
Secure configuration of cloud environmentsrecommendedUse security benchmarks (e.g. CIS) for Microsoft 365, Google Workspace.
No sensitive data in personal cloud servicesrecommendedNo company data in personal Dropbox, personal mailbox, etc.
5. Network
Separate business Wi-Fi from guest Wi-FirequiredSet up a dedicated guest network so visitors get internet access only, with no visibility into internal systems, files, or devices. Look for "Guest Network" in your router's settings, or search for your router model and "guest network setup" to find your manufacturer's instructions.
Firewall active on router and devicesrequiredBoth at network level and at endpoint level.
Change the default router passwordrequiredReplace factory settings immediately, keep firmware up to date.
Use a VPN for remote workrecommendedMandatory when using public networks. E.g. Proton VPN.
6. People & Awareness
Clear reporting point for security incidentsrequiredEveryone knows who to report suspicious situations to.
Provide security awareness training upon joiningrequiredMinimum: recognizing phishing, passwords, reporting procedure.
Conduct phishing simulationsrecommendedPeriodically test employees with simulated phishing emails.
Schedule annual refresher trainingrecommendedKeep security awareness alive with current examples of threats and best practices.
7. Monitoring & Auditing
Enable logging for critical systemsrecommendedWho logged in when? Changes to sensitive files.
Conduct an annual internal security reviewrecommendedGo through the checklist, update policies where necessary.
Periodically assess suppliersoptionalCheck security certifications of critical suppliers.
Have a vulnerability scan or penetration test carried outoptionalHave external testing done once customer data or critical systems are involved. Recommended if you deliver digital services to customers or process sensitive personal data at scale.