If devices are managed by the organisation: enable/enforce all steps from How to: devices 💻📱.
Apply the principle of least privilege to your document management (e.g. Google Drive): do colleagues only have access to information they need for their work? Is there sensitive data on the shared drive?
Periodically test employees with simulated phishing emails.
Schedule annual refresher trainingrecommended
Keep security awareness alive with current examples of threats and best practices.
7. Monitoring & Auditing
Enable logging for critical systemsrecommended
Who logged in when? Changes to sensitive files.
Conduct an annual internal security reviewrecommended
Go through the checklist, update policies where necessary.
Periodically assess suppliersoptional
Check security certifications of critical suppliers.
Have a vulnerability scan or penetration test carried outoptional
Have external testing done once customer data or critical systems are involved. Recommended if you deliver digital services to customers or process sensitive personal data at scale.