JJC SystemsBook a Consultation
Microsoft Defender · Audit

Security baseline audit checklist

The controls your insurer, your clients and any competent attacker will all test. Twenty checks with binary answers.

Why run this

What this checklist is for

This list is deliberately unexotic. These are the controls that stop the attacks organizations actually experience, rather than the ones that appear in a threat briefing.

It is also, almost exactly, what your cyber insurance questionnaire asks. Answering it honestly gives you an actuarially weighted gap analysis for free.

Run it with

Business owner or managing director

And with

Whoever is responsible for IT

And with

Your insurance broker, for the questionnaire comparison

0 of 0 complete · 0%
The checklist

20 checks, in the order we would run them

Tick only what you can genuinely evidence today. An item you intend to do is not an item you have done, and scoring yourself generously here only produces a comfortable number and an uncomfortable project.

Section 1

Identity

More attack paths run through identity than through anything else on this list.

Section 2

Endpoints and email

Where the intrusion usually starts.

Section 3

Data and backup

What determines how bad a bad day gets.

Section 4

Response and governance

The part that converts detection into a shorter incident.

What your score means

Read this against the number above

These bands are deliberately blunt. The middle band is where most organizations honestly sit, and it is a perfectly reasonable place to proceed from — provided the gaps are written down with owners rather than carried as optimism.

0–59%Significant gaps

Do not proceed yet. More than four in ten items are unaddressed, and the ones that fail here are usually the foundational ones that make everything after them harder.

60–84%Mostly ready, with known gaps

Proceed on a defined scope, with the outstanding items written into the plan as risks with owners and dates. This is the most common honest position.

85–100%Ready

The remaining gaps are small enough to handle during delivery rather than before it. Confirm the unticked items are genuinely minor rather than simply unexamined.

Your score highlights automatically as you tick items above. Nothing is saved, sent or tracked — refreshing the page clears it.

Closing the gaps

If you could not tick these, start here

The four items below are the ones whose absence causes the most trouble downstream. If your unticked items include any of these, they are worth addressing before the rest.

MFA has exceptions

Close them this week. An exempted account is the account that gets used, and this is the highest-value single fix available to you.

Legacy authentication still enabled

Block it. Run in report-only mode for a fortnight first to find what breaks, then enforce.

Backups never restore-tested

Schedule the rehearsal. Finding a broken dependency on a planned Saturday costs a weekend; finding it during an incident costs a week.

Alerts nobody reads

This is a tuning problem, not a staffing problem. Suppress the known-benign patterns and the queue becomes workable.

Want a second opinion on your score?

Send us your current insurance questionnaire and your licence position. We will map which gaps are already covered by entitlements you hold — usually more than expected — and what the remainder would take.

Talk through your result Read the related guides We reply to every message within one business day.
Keep going

Related checklists

Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.