Back to blog
SecurityPublished on September 19, 20268 min read

Where Should an SMB Start With IT Security?

A prioritised roadmap for an SMB new to cybersecurity: high-impact actions first, without scattering effort or buying everything unnecessarily.

Faced with cybersecurity, many SMB owners are paralysed by the flood of contradictory advice and solutions being sold to them. Yet the key is not to do everything, nor to buy everything, but to do the right things in the right order. A euro and an hour invested in the right place protect far more than a scattered budget spread across ten half-finished projects. Here is a roadmap prioritised by impact, applicable even without technical expertise and without a significant budget, taking you from a vulnerable state to a solid foundation in three steps.

Step 1: lock down access

Stolen credentials remain the leading cause of company compromise, far ahead of sophisticated attacks. This first step therefore offers the best immediate return on investment, at almost no cost.

  1. 1Enable MFA on all accounts, users and administrators alike.
  2. 2Block legacy authentication, which allows MFA to be bypassed.
  3. 3Limit admin rights to the strict minimum necessary.
  4. 4Put a strong password policy in place and raise awareness about password reuse.

These actions cost nothing extra if you are already on Microsoft 365: they are included in your licenses. They close the door to the vast majority of real attacks, the ones that exploit a weak or reused password rather than a rare technical flaw.

Step 2: secure devices and data

Once accounts are protected, ensure the endpoints are healthy and the data stays available and recoverable even in the event of an incident or ransomware.

  1. 1Encrypt all disks with BitLocker or FileVault to protect against loss and theft.
  2. 2Enable Defender antivirus and automatic system updates.
  3. 3Require device compliance through Conditional Access before any access.
  4. 4Regularly verify that critical data is backed up and genuinely restorable.

The last point deserves special attention: a backup never tested is not a backup. The only way to know it works is to attempt a restore calmly, before you need it in the emergency of a ransomware attack.

Step 3: formalise and maintain

Security is not a project that ends but a state to maintain. This final step embeds good practices over time and prepares regulatory compliance.

  • Regularly train employees to spot phishing and common fraud attempts, the most frequent entry point.
  • Document clear onboarding and offboarding procedures for employees.
  • Periodically review the access granted and the fleet's compliance state.
  • Align all of these practices with ISO 27001, NIS2 or GDPR depending on your obligations.
Order matters: identity first, then devices, then processes.

Why this order and not another

The order is not arbitrary: it follows the ratio of effort to impact. Locking down identity costs almost nothing and blocks the majority of attacks; that is why it is the first rung. Securing devices takes a little more work but protects data where it lives. Formalising comes last, because it only makes sense once the technical protections are in place.

Starting with the most visible is not starting with the most useful

The temptation is to buy the most visible or most heavily marketed solution, often an antivirus or a firewall. But if accounts are not protected by MFA, that investment does not close the main gap. Following the effort/impact order avoids this costly trap.

Measuring your progress

A roadmap is only worth as much as your ability to see where you stand. A compliance dashboard showing the percentage of accounts on MFA, encrypted devices and compliant endpoints turns a vague intention into concrete progress, step after step.

A worked example

A 30-person SMB starts with no formalised security at all. In a first session, it enables MFA for everyone and blocks legacy authentication: the most common gap is closed in an hour, with no purchase. The following week, it enrols the devices in Intune, enables encryption and antivirus, and sets up Conditional Access. Finally, it documents its onboarding and offboarding procedures. In three staggered steps, without a consultant or new budget, it moves from a vulnerable state to a foundation aligned with common frameworks.

Common mistakes to avoid

  • Buying tools before locking down identity, the most cost-effective action.
  • Trying to tackle everything at once and finishing nothing.
  • Confusing "having a backup" with "having a tested, restorable backup".
  • Neglecting employee awareness, when phishing remains the leading entry point.
  • Treating security as a one-off project rather than a state to maintain.

The reassuring point of this roadmap is that it requires almost no extra purchase if you are already on Microsoft 365. The protections described are included in your Business Premium or E3/E5 licenses: the work is to turn them on correctly and maintain them, not to invest in costly new tools. What most SMBs lack is not budget but a clear order of operations and the confidence to act without breaking anything.

Staying on course over time

The hardest part is not starting, but keeping it up. An SMB that turns everything on in January can find, for lack of follow-up, that its fleet has drifted by autumn: new devices never enrolled, temporary exceptions never removed, departed employees whose access lingers. Staying on course means a light, regular ritual rather than one big annual project.

In practice, a monthly review of a few minutes is enough: check the share of accounts on MFA, the compliance state of devices, and that arrivals and departures were handled. This ritual, backed by a clear dashboard, turns security from a one-off project into a sustainable habit within reach of a non-technical team. It is that regularity, far more than a costly tool, that sets genuinely protected organisations apart.

How AuPoint helps

AuPoint turns this roadmap into a list of concrete Intune actions, deployable in a few clicks and already prioritised for you. Thanks to impact preview, plain language and full reversibility, you move step by step without ever risking locking out your team, and you can measure your progress over time.

  1. 1Follow the roadmap step by step, each action already prioritised.
  2. 2Preview the impact before applying so you lock no one out.
  3. 3Measure your compliance continuously with a clear dashboard.
  4. 4Document and prove your progress for your regulatory obligations.
Every protection you enable brings you closer to measurable, documented compliance.

FAQ

What is the very first thing to do?

Enable MFA on all accounts, no exceptions. It is the action with the best effort-to-impact ratio: it blocks the vast majority of stolen-credential attacks and costs nothing extra on Microsoft 365.

Do you need a big budget to start?

No. If you are already on Microsoft 365, most of the protections are included in your licenses. The main investment is time and method, which the right tooling strongly reduces.

When should you worry about ISO 27001 or NIS2?

Once the technical protections are in place. Formalisation and regulatory alignment are step three: they build on technical foundations that are already solid and documented, not the other way around.

Every protection you enable brings you closer to a measurable, documented level of compliance. Starting in the right place, in the right order, has never been this simple for an SMB. With AuPoint, this roadmap becomes a set of concrete actions, without PowerShell, aligned with ISO 27001, NIS2 and GDPR, that you carry out at your own pace and in complete safety.

Secure your tenant in 15 minutes

Free trial