Guides
Guides and best practices
Practical, vendor-neutral checklists you can act on this week. Written by our engineers from real incident and recovery work.
Ransomware readiness checklist
Ten things to verify before an attack, not after. If you can tick every item, a ransomware incident becomes an inconvenience rather than a crisis.
- Keep at least one backup copy offline or immutable, so it cannot be encrypted
- Test a full restore of a critical system at least twice a year, and record how long it took
- Enforce multi-factor authentication on email, VPN and all administrative accounts
- Remove standing administrator rights from everyday user accounts
- Write down who to call, in what order, in the first hour, and keep it on paper
The 3-2-1-1-0 backup rule
The classic 3-2-1 rule has been updated for the ransomware era. Here is what each digit means and how to apply it in a small environment.
- Three copies of your data, including the live production copy
- Two different types of storage media, so one failure mode cannot take both
- One copy off-site, in another building or a cloud region
- One copy offline, air-gapped or immutable, beyond the reach of an attacker
- Zero errors in the verification report, checked by a human, not just by the software
NIS2 readiness in seven steps
A pragmatic route from unsure to defensible, aimed at companies without a dedicated compliance team.
- Confirm whether you are in scope, as an essential or important entity, and record the reasoning
- Assign accountability at management level, since NIS2 makes leadership responsible
- Carry out a risk assessment covering your systems, suppliers and dependencies
- Close the basics first, that is patching, multi-factor authentication, backups and access control
- Prepare incident reporting, so you can notify within the required deadlines
- Train staff and management, and keep the attendance records
Microsoft 365 security baseline
The settings we enable on day one for every Microsoft 365 tenant we take over, in rough order of impact.
- Enforce multi-factor authentication for every user, with no permanent exclusions
- Block legacy authentication protocols that bypass modern sign-in security
- Restrict administrative roles, and use just-in-time elevation where licensing allows
- Enable audit logging and keep it long enough to investigate a slow-burn incident
- Add a third-party backup for mailboxes, files and Teams data, since retention is not backup