A Practical Security Baseline for Connected Businesses
Security controls only work when people can follow them. This is the baseline we recommend for connected operations — identity, least privilege, data visibility and tested recovery — built so it holds up without slowing delivery down.

Security programmes fail for social reasons more often than technical ones. Controls that are hard to follow get worked around, and a control with a well-known workaround is not a control. A durable baseline is therefore as much a usability exercise as a technical one.
Identity is the perimeter now
With work spread across SaaS, cloud and partner systems, the network boundary no longer describes anything useful. Identity does. Single sign-on across every system that supports it, phishing-resistant multi-factor authentication, and joiner-mover-leaver automation cover the majority of realistic attack paths.
The leaver half of that process is the one most often neglected and the one auditors reliably find. Automate deprovisioning from the HR system rather than relying on a ticket somebody remembers to raise.
- Single sign-on wherever the system supports it.
- Phishing-resistant MFA for administrators without exception.
- Automated deprovisioning triggered by the HR record, not by a ticket.
Least privilege that people can actually live with
Blanket restriction produces shadow IT. The workable version is role-based defaults that cover ninety per cent of daily work, plus a fast, logged path to elevate for the rest. If requesting temporary access takes minutes rather than days, people will use it instead of routing around it.
Review access on a schedule and make the review meaningful: managers confirming a list they do not understand is theatre. Show last-used dates so that revoking unused access is the obvious default.
A control people can follow at speed beats a stricter control they learn to bypass.
Know where the data actually is
You cannot protect data whose location you cannot describe. Map the systems holding customer, financial and personal data, note where each one replicates to, and keep that map current as part of change management rather than as an annual exercise.
This map is also what makes incident response fast. When something does go wrong, the difference between a contained incident and a public one is usually how quickly the team can answer "what data could this have touched?".
- Maintain a living inventory of systems holding sensitive data.
- Record downstream copies, exports and backups, not just primaries.
- Update the map through change management, not through annual audits.
Test recovery, not just backups
Backups that have never been restored are an assumption rather than a control. Restore on a schedule, time it, and record the result. The number worth knowing is not whether a backup exists but how long a full recovery actually takes with your current staffing.
Run the same exercise for your identity provider and your critical SaaS platforms. Their outage is your outage, and the plan for it should exist before it is needed.
Key takeaways
- Treat identity as the perimeter and automate deprovisioning from HR.
- Pair least-privilege defaults with a fast, logged elevation path.
- Keep a living map of where sensitive data lives and replicates.
- Measure recovery time by actually restoring, on a schedule.



