Start with what the business depends on

List the systems, accounts and data your business cannot operate without. Assign an owner to each. An asset inventory makes it easier to prioritise improvements and avoid leaving critical services outside the security programme.

Protect accounts and everyday work

Review multi-factor authentication, administrator permissions, joiner and leaver processes, endpoint protection, patching and email security. Check that controls work in practice rather than only appearing in a policy.

Test whether recovery is possible

Backups matter only if the business can restore from them. Define recovery priorities, restrict access to backups and run proportionate restore exercises. Keep response contacts and decision responsibilities available when primary systems are disrupted.

Separate a good baseline from a legal obligation

These are practical security foundations, not a claim that every business must buy a particular service. CERT-In directions and sector rules may impose specific obligations. Review applicability, incident reporting and logging arrangements with the appropriate specialist.