SME cybersecurity checklist: 10 essential measures | ALAconnect

Guide · Cybersecurity

Cybersecurity checklist for SMEs: 10 essential measures to check now

The ten security measures every small and medium-sized business should have, in order of impact, with what to check for each.

ALAconnect · Published on 7 October 2026 · 6-minute read

At a glance

  • Most attacks on SMEs exploit stolen passwords, unpatched systems and phishing emails.
  • Multi-factor authentication, updates and protected backups remove much of the risk at low cost.
  • The same measures are required by NIS2 and help demonstrate GDPR compliance.

This checklist covers the security measures ALAconnect checks first when it takes over a company's infrastructure. For each one you will find what to check: if the answer is "no" or "don't know", it needs fixing.

1. Multi-factor authentication (MFA)

Enable MFA on email, Microsoft 365, VPN, remote access and administration panels. A stolen password without the second factor is useless to an attacker. To check: are there accounts, including service accounts or those of former employees, without MFA?

2. System and software updates

Operating systems, firewall and NAS firmware, browsers and applications must be updated regularly, prioritising critical vulnerabilities and those already exploited by attackers. To check: are there servers or devices running unsupported operating systems?

3. Backup following the 3-2-1 rule

Three copies, on two media, one off-site, plus an immutable copy against ransomware, with regular restore tests. Read more in the guide Business backup: the 3-2-1 rule.

4. Next-generation firewall

An up-to-date firewall with traffic inspection, web filtering, IPS and protected VPNs is the first barrier between the company network and the Internet. To check: are rules documented, and are only the necessary services exposed to the Internet?

5. Endpoint protection

PCs and servers need centrally managed protection (EDR) that blocks suspicious behaviour, not just known viruses. To check: do all workstations show as protected and up to date in the console?

6. Least privilege and separate admin accounts

Users work without administrator rights; administrators use dedicated accounts only for management tasks. To check: how many accounts have administrative privileges, and do they all really need them?

7. Anti-phishing training

Phishing remains the main entry point for attacks. Short, regular training with simulations teaches staff to recognise suspicious emails and links and to report them immediately.

8. Email security

Configure SPF, DKIM and DMARC on the company domain to reduce spoofed emails sent in the company's name, and enable advanced anti-spam and anti-malware filters.

9. Device and software inventory

You cannot protect what you do not know about. Keep an up-to-date list of computers, servers, network devices, cloud services and installed software, with the owner of each.

10. Monitoring and incident response plan

A security event monitoring system flags attacks in progress; a written procedure defines who does what in an incident, including notification to the Data Protection Authority and, for NIS2 entities, to CSIRT Italia within 24 hours.

Where to start

If more than two items need fixing, start with MFA, updates and backup: they offer the best ratio between cost and risk reduction. For companies subject to NIS2 these measures are mandatory: see NIS2 compliance. Many of them can also be funded with the Cloud & Cybersecurity Voucher, as explained in Grants and funding.

How ALAconnect works

ALAconnect checks these ten points with an initial assessment, proposes a prioritised action plan and manages firewalls, endpoint protection, backup and monitoring over time. Discover the Cybersecurity service or request an assessment.

Need support?
Need support?