Registered office
20 Wenlock Road
London N1 7GU
Registered office
20 Wenlock Road
London N1 7GU

Secure Microsoft 365 or Google Workspace, MFA, devices, passwords, email and backups with this startup IT checklist for UK founders and first hires.
A secure startup IT setup does not need to be enterprise-sized. It needs named owners, protected identities, managed devices, recoverable data and a repeatable joiner/leaver process. Use this checklist before the first employee starts, then review it whenever the team, suppliers or systems change.
Reviewed: 18 August 2026

A founder’s personal email address should not be the permanent owner of the domain, cloud tenant, website, payment account or source-code repository. Use a company-controlled account, record at least two authorised administrators and store recovery details in a business password manager. This reduces the risk of losing access when a founder, contractor or agency relationship changes.
Keep an ownership register with the service name, business purpose, account owner, technical administrator, renewal date and recovery route. Avoid recording live passwords in the register.
For most cloud-first startups, Microsoft 365 or Google Workspace becomes the central identity platform. Create one named account per person and use groups for access. Shared mailboxes such as accounts@ or support@ can be collaborative without staff sharing one password.
Require MFA for everyone. Administrators, finance users and anyone who can change domains or payments should be first. Where supported, prefer phishing-resistant methods such as passkeys or hardware security keys over SMS. Keep emergency recovery accounts tightly controlled, monitored and excluded from daily work.
A user who reads email and browses the web should not remain signed in with full administrative rights. Give administrators a separate privileged account and use it only when a change requires it. This simple separation limits what an attacker or malicious document can do after compromising an everyday session.
Apply least privilege to contractors too. Give access to the project and systems they need, set an expiry date where possible, and remove access when the engagement ends.
Decide which Windows, macOS, iOS and Android versions you will support. Require screen locks, device encryption, supported antivirus or endpoint protection, automatic updates and remote lock or wipe for business devices. Record the serial number, assigned user and status of each device.
Bring-your-own-device policies can work, but they need boundaries: supported versions, separation of work data, reporting for loss, and a clear right to remove company data. For teams handling sensitive customer, health or financial information, company-managed devices are usually easier to secure and support.
Turn on automatic updates for operating systems, browsers, office applications, password managers and security tools. Assign someone to check exceptions and failed updates rather than assuming automation always succeeds. Internet-facing servers and critical vulnerabilities need a faster, risk-led process; our server patching guide explains that workflow.
A business password manager provides unique credentials, controlled sharing, recovery and offboarding. It also removes the temptation to keep passwords in documents or reuse the founder’s favourite password. Evaluate admin controls, MFA or passkey support, audit visibility, recovery, export and the process for removing a departing user. See our business password manager guide for a fuller comparison framework.
Configure SPF, DKIM and DMARC for every system that legitimately sends mail for the domain. Start DMARC in monitoring mode, review reports, fix legitimate senders and then increase enforcement. Do not publish a strict reject policy before you know what is sending mail. Follow the staged process in SPF, DKIM and DMARC explained.
Cloud availability and file synchronisation are not the same as an independent backup. List the information needed to trade: email, shared files, accounting data, customer records, source code, website data and critical configuration. Decide how much data the business can afford to lose and how quickly it must be restored.
Keep backups separate from the normal user account and test restores. A successful backup notification proves a job ran; it does not prove that a usable mailbox, database or file can be recovered.
For each new starter, record the approved role, device, groups, applications and data access. For leavers, disable sign-in promptly, revoke sessions and tokens, collect devices, transfer business data, change shared secrets and remove third-party access. Preserve information only for a documented business or legal reason.
A repeatable process is faster than deciding access from scratch and creates evidence when a customer or insurer asks how access is controlled.
Staff should know who to contact if they click a suspicious link, approve an unexpected MFA request, lose a phone or notice an unusual payment request. Record the contacts for your IT provider, bank, cyber insurer, domain registrar and key cloud services somewhere available even when normal systems are down.
The UK National Cyber Security Centre’s Small Business Guide is a practical baseline covering backups, malware, mobile devices, passwords and phishing.
Review it before the first hire, after a funding round or office move, when adopting a major supplier, and at least quarterly while the company is changing quickly. Run leaver checks immediately. Test backups and emergency contacts on a schedule rather than waiting for an incident.
ACA Tech Solutions can configure the collaboration, devices, access and practical security controls behind this checklist. Explore startup IT support or begin with an IT health check to identify the highest-priority gaps.
Not always. A very small team may only need a well-designed setup and occasional support. Managed support becomes more valuable when onboarding is frequent, downtime is expensive, compliance demands grow or nobody internally owns updates, backups and access.
Both can provide strong security when configured and administered well. The better choice depends on the applications, collaboration style, customer requirements and internal skills. Poor identity and recovery settings create risk on either platform.
Secure the domain and administrator identities, turn on MFA, protect devices, confirm backups and document leavers. Those controls reduce several common startup risks quickly.