Turn on phishing-resistant MFA for admins
A stolen admin password is the fastest path to a full takeover. Start here.
IT-01 guide →A high-level starting sequence for resource-constrained DIB teams — the handful of highest-leverage moves, in order. Each links into the full practice and cloud setup guides when you’re ready to go deeper.
Do these in order; don’t try to do everything at once. Two weeks in, you’ll have closed the biggest doors and be ready to build a full 30/60/90-day roadmap. For a plan tailored to your answers, use the 30-day plan builder.
A stolen admin password is the fastest path to a full takeover. Start here.
IT-01 guide →You can't protect what you can't see. One living list is the foundation for everything after.
IT-02 guide →Vendor and remote access is a favorite way in — broker it, log it, time-box it.
Remote access →You can't investigate what you never recorded. Turn on audit logs now, not after an incident.
Cloud setup guides →An untested backup is only a hope. One real restore tells you where you actually stand.
IT-09 guide →Most breaches use known, unpatched holes. Start scanning and read the top ten findings.
IT-06 guide →Containment keeps one breached device from becoming ten. Draw the zones you need.
IT-05 guide →Turn these first moves into an owned, sequenced roadmap with owners and dates.
Plan builder →