{"id":3466,"date":"2026-08-18T06:02:07","date_gmt":"2026-08-18T06:02:07","guid":{"rendered":"https:\/\/acatechsolutions.co.uk\/blog\/startup-it-security-checklist\/"},"modified":"2026-08-18T09:10:37","modified_gmt":"2026-08-18T09:10:37","slug":"startup-it-security-checklist","status":"publish","type":"post","link":"https:\/\/acatechsolutions.co.uk\/blog\/startup-it-security-checklist\/","title":{"rendered":"Startup IT Security Checklist: Microsoft 365, MFA, Devices &amp; Backups"},"content":{"rendered":"<p><strong>A secure startup IT setup does not need to be enterprise-sized.<\/strong> It needs named owners, protected identities, managed devices, recoverable data and a repeatable joiner\/leaver process. Use this checklist before the first employee starts, then review it whenever the team, suppliers or systems change.<\/p>\n<p><em>Reviewed: 18 August 2026<\/em><\/p>\n<h2>Startup IT security checklist at a glance<\/h2>\n<ol>\n<li>Register the domain in a company-controlled account.<\/li>\n<li>Choose Microsoft 365 or Google Workspace as the identity platform.<\/li>\n<li>Give every person their own account; never share logins.<\/li>\n<li>Require multi-factor authentication (MFA), starting with administrators.<\/li>\n<li>Create separate administrator and everyday accounts.<\/li>\n<li>Standardise laptops and phones that can access company data.<\/li>\n<li>Turn on automatic operating-system and application updates.<\/li>\n<li>Encrypt devices and record recovery keys securely.<\/li>\n<li>Deploy password management and remove passwords from chat and spreadsheets.<\/li>\n<li>Protect email with SPF, DKIM and DMARC.<\/li>\n<li>Back up business data independently of normal cloud synchronisation.<\/li>\n<li>Test that a file, mailbox or system can actually be restored.<\/li>\n<li>Document joiners, role changes and leavers.<\/li>\n<li>Maintain a simple asset, supplier and data register.<\/li>\n<li>Give staff a clear route for reporting suspicious messages and lost devices.<\/li>\n<\/ol>\n<h2>1. Put company accounts under company control<\/h2>\n<p>A founder&#8217;s personal email address should not be the permanent owner of the domain, cloud tenant, website, payment account or source-code repository. Use a company-controlled account, record at least two authorised administrators and store recovery details in a business password manager. This reduces the risk of losing access when a founder, contractor or agency relationship changes.<\/p>\n<p>Keep an ownership register with the service name, business purpose, account owner, technical administrator, renewal date and recovery route. Avoid recording live passwords in the register.<\/p>\n<h2>2. Make identity the security perimeter<\/h2>\n<p>For most cloud-first startups, Microsoft 365 or Google Workspace becomes the central identity platform. Create one named account per person and use groups for access. Shared mailboxes such as accounts@ or support@ can be collaborative without staff sharing one password.<\/p>\n<p>Require MFA for everyone. Administrators, finance users and anyone who can change domains or payments should be first. Where supported, prefer phishing-resistant methods such as passkeys or hardware security keys over SMS. Keep emergency recovery accounts tightly controlled, monitored and excluded from daily work.<\/p>\n<h2>3. Separate administration from everyday work<\/h2>\n<p>A user who reads email and browses the web should not remain signed in with full administrative rights. Give administrators a separate privileged account and use it only when a change requires it. This simple separation limits what an attacker or malicious document can do after compromising an everyday session.<\/p>\n<p>Apply least privilege to contractors too. Give access to the project and systems they need, set an expiry date where possible, and remove access when the engagement ends.<\/p>\n<h2>4. Establish a minimum device standard<\/h2>\n<p>Decide which Windows, macOS, iOS and Android versions you will support. Require screen locks, device encryption, supported antivirus or endpoint protection, automatic updates and remote lock or wipe for business devices. Record the serial number, assigned user and status of each device.<\/p>\n<p>Bring-your-own-device policies can work, but they need boundaries: supported versions, separation of work data, reporting for loss, and a clear right to remove company data. For teams handling sensitive customer, health or financial information, company-managed devices are usually easier to secure and support.<\/p>\n<h2>5. Patch automatically, with ownership<\/h2>\n<p>Turn on automatic updates for operating systems, browsers, office applications, password managers and security tools. Assign someone to check exceptions and failed updates rather than assuming automation always succeeds. Internet-facing servers and critical vulnerabilities need a faster, risk-led process; our <a href=\"https:\/\/acatechsolutions.co.uk\/blog\/server-patching-services-uk\/\">server patching guide<\/a> explains that workflow.<\/p>\n<h2>6. Use a business password manager<\/h2>\n<p>A business password manager provides unique credentials, controlled sharing, recovery and offboarding. It also removes the temptation to keep passwords in documents or reuse the founder&#8217;s favourite password. Evaluate admin controls, MFA or passkey support, audit visibility, recovery, export and the process for removing a departing user. See our <a href=\"https:\/\/acatechsolutions.co.uk\/blog\/business-needs-a-password-manager\/\">business password manager guide<\/a> for a fuller comparison framework.<\/p>\n<h2>7. Protect the email domain<\/h2>\n<p>Configure SPF, DKIM and DMARC for every system that legitimately sends mail for the domain. Start DMARC in monitoring mode, review reports, fix legitimate senders and then increase enforcement. Do not publish a strict reject policy before you know what is sending mail. Follow the staged process in <a href=\"https:\/\/acatechsolutions.co.uk\/blog\/the-email-security-trio\/\">SPF, DKIM and DMARC explained<\/a>.<\/p>\n<h2>8. Back up what the business cannot recreate<\/h2>\n<p>Cloud availability and file synchronisation are not the same as an independent backup. List the information needed to trade: email, shared files, accounting data, customer records, source code, website data and critical configuration. Decide how much data the business can afford to lose and how quickly it must be restored.<\/p>\n<p>Keep backups separate from the normal user account and test restores. A successful backup notification proves a job ran; it does not prove that a usable mailbox, database or file can be recovered.<\/p>\n<h2>9. Build joiner and leaver checklists early<\/h2>\n<p>For each new starter, record the approved role, device, groups, applications and data access. For leavers, disable sign-in promptly, revoke sessions and tokens, collect devices, transfer business data, change shared secrets and remove third-party access. Preserve information only for a documented business or legal reason.<\/p>\n<p>A repeatable process is faster than deciding access from scratch and creates evidence when a customer or insurer asks how access is controlled.<\/p>\n<h2>10. Prepare a small incident plan<\/h2>\n<p>Staff should know who to contact if they click a suspicious link, approve an unexpected MFA request, lose a phone or notice an unusual payment request. Record the contacts for your IT provider, bank, cyber insurer, domain registrar and key cloud services somewhere available even when normal systems are down.<\/p>\n<p>The UK National Cyber Security Centre&#8217;s <a href=\"https:\/\/www.ncsc.gov.uk\/collection\/small-business-guide\" target=\"_blank\" rel=\"noopener\">Small Business Guide<\/a> is a practical baseline covering backups, malware, mobile devices, passwords and phishing.<\/p>\n<h2>How often should a startup review this checklist?<\/h2>\n<p>Review it before the first hire, after a funding round or office move, when adopting a major supplier, and at least quarterly while the company is changing quickly. Run leaver checks immediately. Test backups and emergency contacts on a schedule rather than waiting for an incident.<\/p>\n<h2>Need help setting up the foundations?<\/h2>\n<p>ACA Tech Solutions can configure the collaboration, devices, access and practical security controls behind this checklist. Explore <a href=\"https:\/\/acatechsolutions.co.uk\/startup-it\/\">startup IT support<\/a> or begin with an <a href=\"https:\/\/acatechsolutions.co.uk\/it-support\/health-check\/\">IT health check<\/a> to identify the highest-priority gaps.<\/p>\n<h2>Frequently asked questions<\/h2>\n<h3>Does a two-person startup really need managed IT?<\/h3>\n<p>Not always. A very small team may only need a well-designed setup and occasional support. Managed support becomes more valuable when onboarding is frequent, downtime is expensive, compliance demands grow or nobody internally owns updates, backups and access.<\/p>\n<h3>Is Microsoft 365 or Google Workspace more secure?<\/h3>\n<p>Both can provide strong security when configured and administered well. The better choice depends on the applications, collaboration style, customer requirements and internal skills. Poor identity and recovery settings create risk on either platform.<\/p>\n<h3>What should be completed first?<\/h3>\n<p>Secure the domain and administrator identities, turn on MFA, protect devices, confirm backups and document leavers. Those controls reduce several common startup risks quickly.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Secure Microsoft 365 or Google Workspace, MFA, devices, passwords, email and backups with this startup IT checklist for UK founders and first hires.<\/p>\n","protected":false},"author":1,"featured_media":3467,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23,17],"tags":[],"class_list":["post-3466","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber_hygiene","category-information_technology"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":7},"page_structure_type":"type-1"},"_links":{"self":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts\/3466","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=3466"}],"version-history":[{"count":1,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts\/3466\/revisions"}],"predecessor-version":[{"id":3488,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts\/3466\/revisions\/3488"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/media\/3467"}],"wp:attachment":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=3466"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=3466"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=3466"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}