In this guide
A useful cybersecurity review ends with a few specific actions and responsible people. It should not leave a small co-op staring at a percentage score without knowing what matters. Start with the ways an incident could interrupt your work, expose people’s information or divert money.
This checklist is a practical starting point, not a certification or assurance that your systems are safe. Adapt it to the information you handle and the services you provide. If you operate specialist or high-impact systems, obtain advice appropriate to that work.
Identify the work you cannot easily lose
Spend the first part of the review naming the essential services: email, orders, member records, finance, website, document storage and any operational equipment. Identify who can control each and what happens if it becomes unavailable for a working day.
Use the NCSC small-organisations guide as a baseline. Its current guidance covers email, important accounts, devices, backups and spotting attacks. Your review should turn these subjects into local decisions and evidence.
An illustrative worker co-op might discover that its domain and backups both depend on one founder's personal account. Resolving that dependency may be more urgent than buying another security product. A community venue might prioritise the shared reception computer and the mailbox used for booking payments.
Review these controls with evidence
- Ownership: the organisation has an account register, current billing contacts and a workable succession route.
- Sign-in: important services use suitable strong authentication, with tested recovery.
- Permissions: administrators are identified; routine users have appropriate access; former role holders have been reviewed.
- Devices: supported operating systems and applications receive updates; devices lock when unattended; lost-device arrangements are understood.
- Files: sensitive records are restricted and external sharing is intentional.
- Backups: essential data has a defined recovery method and a recent relevant restore test.
- Payments: bank-detail changes and unusual requests are verified independently.
- Reporting: everyone knows a trusted route for suspicious messages, lost devices and accidental disclosure.
- Suppliers: support, maintenance and recovery responsibilities are recorded.
For each line, ask to see a small piece of evidence: an access list, a checked renewal entry, a restore record or a written payment procedure. Avoid collecting passwords, sensitive screenshots or unnecessary personal data merely to prove that a review occurred.
Prioritise by impact and dependency
Use three working categories. “Act promptly” covers exposed high-impact access, unsupported critical systems, suspected compromise or an essential service with no workable recovery. “Schedule” covers defined improvements with an owner and date. “Investigate” covers uncertainty that needs a specific answer before you can judge it.
Do not label an unknown system safe because nobody has reported a problem. Equally, do not turn every minor imperfection into an emergency. Describe the possible consequence and the next proportionate action.
A worked action could read: “Only the former secretary can receive the registrar recovery email. Current secretary to verify account control with the registrar, establish approved recovery and record the result by the agreed date.” That is more useful than “improve domain security”.
Run a short review meeting
- Confirm the three services most important to current operations.
- Walk through the checklist and record verified facts separately from unknowns.
- Select the highest-impact unresolved items.
- Assign each item one accountable owner, a next action and a review date.
- Confirm who can authorise necessary changes or expenditure.
- Arrange a follow-up that checks the evidence of completion.
Use the sign-in and recovery guide or the restore-test exercise when those subjects need a deeper review. Keep learning approachable: people should be able to report a mistake without fearing humiliation.
Repeat the review when important systems, suppliers or responsibilities change, and at an interval your co-op can maintain. The value comes from completing and checking the actions, not from accumulating increasingly elaborate checklists.
Start your local action list with the technology health check.