DRAG
InstaIT InstaIT InstaIT

Trusted IT solutions for Small and Medium Cork businesses. Infrastructure, cloud, networking, security and professional services.

Get In Touch

Cork Ireland

BUSINESS IT · CYBERSECURITY

Cybersecurity Checklist for Small Businesses in Ireland

A practical starting point for business owners: know what matters, protect access and make sure you can recover when something goes wrong.

Start with the systems your business relies on

Before buying another security product, list the systems you would struggle to operate without: email, customer records, accounts, bookings, payments and shared documents. Record who owns each account, where the data is kept and who can provide support.

Include laptops, phones, network equipment and services managed by external providers. A simple inventory can reveal an old administrator account or a critical service that only one person knows how to access.

Check: Can you identify an owner and recovery contact for every essential system? The NCSC recommends identifying your important assets as a starting point. Read its asset guidance.

1. Protect business accounts

Enable multi-factor authentication (MFA) for business email, administrator accounts, remote access and other important services that support it. This adds a verification step beyond a password. Choose the strongest method supported by the service, and keep recovery arrangements secure.

Use individual accounts instead of sharing one login across the team. Give people the access they need for their job and remove access when they leave. Keep administrator privileges separate from everyday work where practical.

Use unique passwords and a suitable password manager. Never approve a sign-in prompt you did not initiate; report it through your agreed support route.

Check: Review the account list, MFA status and recovery details with the person responsible for IT. NCSC guidance explains how MFA protects accounts.

2. Keep devices and software supported

Assign responsibility for operating-system, browser and application updates. Include phones, routers and firewalls, not just office computers. Identify unsupported products and plan their replacement.

Automatic updates can help, but someone should check for failures and overdue restarts. Critical business applications may need testing and a recovery plan before changes. Security fixes should be prioritised according to their urgency rather than left indefinitely for a convenient date.

Check: Ask for a list of devices with missing updates or unsupported software and agree an owner for each exception. The NCSC’s update guidance also highlights the need to understand responsibilities when systems are externally managed.

3. Check everyday device protection

Review device encryption, screen locks, firewall settings and endpoint protection. Confirm that protection is active and alerts reach someone who will act on them.

Agree what happens when a laptop or phone is lost. Staff should know whom to contact promptly, and business access should be removable. Keep guest Wi-Fi separate from business systems where appropriate.

For businesses managing several devices, Microsoft Intune device management may help apply and review policies. Suitability depends on the devices, licences and support arrangements you already have.

Check: Can you see which business devices meet your agreed protection settings? Compare your approach with the NCSC’s basic protection measures.

4. Prove that important data can be restored

Identify what is backed up, how frequently, how long copies are retained and who can restore them. Cloud storage and synchronisation are not automatically the same as a separate backup arrangement.

Keep backup access protected and use copies that an attacker on your normal network cannot readily alter. Choose a schedule based on how much work you can afford to lose, rather than using the same schedule for every system.

Test restoring a sample file and, where necessary, a complete application. Record how long it takes and what access is required. A successful backup notification alone does not demonstrate that the business can recover.

Check: Record the date and outcome of your last restore test. See NCSC backup guidance and our backup and disaster recovery services.

5. Give staff a clear way to report concerns

Use examples relevant to your business: an unexpected invoice, a supplier requesting new bank details or an email asking for a password. Encourage staff to pause and verify unusual requests using a known contact method.

Agree who receives suspicious-message reports and make reporting mistakes straightforward. If someone clicks a suspicious link, you want to hear about it quickly.

Check: Ask a colleague what they would do with an unexpected payment-change request. If the answer is unclear, write down a short verification process and share it with the team.

Turn the checklist into a short action plan

For each gap, record the system affected, an owner, the next action and a review date. Start with exposed important accounts, unsupported systems and uncertain recovery arrangements. An IT provider can help prioritise changes around the way your business operates.

Keep support and recovery contact details accessible even if normal email is unavailable. Review the checklist after staff changes, new systems or a move of premises, as well as at a regular agreed interval.

This is a practical starting point, not a security certification or a legal compliance assessment. For independent Irish guidance, the NCSC’s SME CORE resource provides advice for small businesses. InstaIT is not affiliated with or endorsed by the NCSC.

MAKE THE NEXT STEP PRACTICAL

Need help closing the gaps?

Explore our cybersecurity services in Cork, or tell us which systems and concerns you would like reviewed.

Discuss your IT security

← Back to business guides