Five IT Security Projects Worth Doing This Year
Security plans fail when they're a list of everything. This is a list of five things, in the order that gets you the most protection per hour spent. Done properly, the whole set takes a small business a few months of occasional effort — not a full-time program.
1. Close every gap in your MFA coverage
Effort: a week · Cost: usually nothing new
Not "turn on MFA" — you probably did that already. The project is finding what's still exempt. Every rollout leaves residue: the service account for the scanner, the shared mailbox, the break-glass admin, the contractor added last spring, the domain registrar nobody has logged into since 2019.
Pull a report of accounts without MFA registered and work through it. Then block legacy authentication, which lets old mail protocols bypass MFA entirely and quietly undoes the whole exercise. The full walkthrough is in how to roll out MFA.
This is first because nothing else you can do in a week changes your risk as much.
2. Restore from backup and time it
Effort: an afternoon · Cost: nothing
Not review the backup dashboard. Restore. Pick a file from three months ago and a mailbox, bring them back, and write down how long it took.
That number is your actual recovery time, and it is routinely several times what people assumed. You'll also find out whether the backup covers what you think it covers — the two most common surprises being Microsoft 365 data that was never backed up at all, and a critical server excluded from the job years ago.
While you're there, confirm at least one copy is immutable or genuinely offline. Ransomware looks for backup systems first, and a backup your servers can reach is a backup the attacker can reach.
3. Take administrator rights away from daily accounts
Effort: two to four weeks · Cost: nothing
Most small businesses have more administrators than they realize, usually because granting admin rights was the fastest way to resolve a problem at some point and nothing was ever revoked.
The goal: nobody uses an administrator account for daily work. Admins get a separate privileged account used only when needed. When a standard user gets phished, the attacker gets a standard user — which is a bad afternoon rather than a catastrophe.
Expect some friction, and expect to find one or two applications that genuinely need elevated rights. Handle those specifically rather than abandoning the project. More on the reasoning in the principle of least privilege.
4. Write the one-page incident plan
Effort: an afternoon, plus an hour to test · Cost: nothing
Who to call, in order, with mobile numbers. Your cyber insurance policy number and claims line. Where backups are and how to reach them without the network. Which systems come back first. Who is authorized to take systems offline at 3am without asking permission.
Print it. Store it somewhere that isn't the file server that might be encrypted. Then spend an hour walking through a scenario out loud with your team — the gaps surface immediately and cost nothing to find that way. Details in building an incident response plan.
5. Fix the payment verification process
Effort: one meeting · Cost: nothing
Business email compromise costs small businesses more than ransomware does, and no security product prevents it, because there's nothing technically malicious in the email. Somebody impersonates your owner or a vendor and asks for a payment or a change of bank details.
The control is a rule: any change to payment details, and any unusual payment request, gets verified by voice on a number you already had on file — never a number from the email. It applies to the owner too. Staff must know they will never be criticized for making that call, because the entire attack depends on people feeling awkward about checking.
One meeting, written down, and you've closed off the most expensive attack category there is.
What we deliberately left off
Plenty of worthwhile things aren't on this list: security awareness training, network segmentation, a formal risk assessment, vulnerability scanning, SIEM. They're all valid. They're also what people reach for when they want a security program to look comprehensive, and they deliver less per hour than the five above.
Do these five properly first. Then add training — aimed at fast reporting rather than perfect detection — and go from there.
A realistic schedule
- Month 1: MFA gap audit, block legacy authentication
- Month 2: Backup restore test; fix whatever it reveals
- Month 3: Payment verification rule; write the incident page
- Months 4–5: Administrator rights cleanup
- Month 6: Tabletop exercise; review what's drifted since month 1
Half a year, mostly using licensing you already pay for, and you'd be ahead of most businesses your size. The recurring part matters as much as the projects — MFA gaps reopen as people join, and backups break quietly. Put the checks on a calendar.
Want help working through the list?
Vulcan365 provides managed IT and security for businesses across Birmingham and Central Alabama. We'll tell you which of these five you've already got covered and which ones have quietly slipped.
Book a security review