These twelve controls do most of the work, in this order: know what you have, phishing-resistant MFA, a password manager, fast patching, monitored endpoint detection, tested immutable backups, least privilege, email authentication, logging, a drilled incident plan, device encryption, and vendor requirements.
Most security advice fails because it's a catalogue rather than an order of operations. This is the order of operations — twelve controls, sequenced by the evidence that they reduce actual loss. They map to CISA's Cross-Sector Cybersecurity Performance Goals and CIS Controls Implementation Group 1 — the two publicly citable floors — so you can point an auditor, an insurer, or a board at them.
The twelve
1. Know what you have. An inventory of systems, accounts, SaaS applications, and internet-facing devices. You cannot patch, monitor, or decommission something you don't know exists. (CIS 1–2 · CPG Identify)
2. Phishing-resistant MFA on email, remote access, and admin accounts. Passkeys or hardware security keys — not text messages, and not push approval prompts, both of which are routinely defeated. Administrators first. (CPG 2.H · CIS 6)
3. Unique passwords via a password manager, and no default credentials anywhere. (CPG 2.A–2.C · CIS 5)
4. Patch fast, prioritised by evidence of exploitation. Anything internet-facing or on CISA's exploited-vulnerabilities list: days, not weeks. Everything else on a schedule. (CPG 1.E · CIS 7)
5. Endpoint detection on every device, with someone actually watching it. If you have no 24/7 staff, that someone is a managed detection service. An unwatched console is a compliance artefact. (CIS 10, 13)
6. Backups: three copies, two media, one offsite, one immutable or offline — and restore-tested. (CPG 2.R · CIS 11)
7. Least privilege. No daily-driver administrator accounts. Access removed the day someone leaves. (CPG 2.E · CIS 5–6)
8. Email security plus a reporting button people actually use. Get SPF, DKIM and DMARC to enforcement — it's free and stops your domain being used against your own customers. (CPG 2.G · CIS 9, 14)
9. Logging on, and retained. Authentication logs and cloud audit logs, kept long enough to investigate. Default cloud retention is usually too short. (CPG 2.T · CIS 8)
10. A one-page incident response plan, drilled. Names a decision-maker, a technical lead, and a communicator. Lists out-of-band contacts including your insurer's hotline. (CPG 5.A · CIS 17)
11. Encrypt laptops and phones, with auto-lock. In most US states, provable encryption at the time of loss is the difference between an incident and a notifiable breach. (CIS 3)
12. Know your critical vendors, and require MFA and security terms in contracts. Third parties were involved in roughly half of breaches in the 2026 DBIR. (CPG 1.G–1.I · CIS 15)
If you can only do three
Do 2, 6, and 4 — phishing-resistant MFA, tested immutable backups, and fast patching of internet-facing systems.
Those three address the top initial access vectors in every major breach dataset, and they're the three that insurers price. Everything else is real, but these are the ones that change outcomes.
Why these twelve and not others
Multi-factor authentication blocks the overwhelming majority of account-compromise attacks, according to Microsoft's own telemetry across hundreds of millions of accounts. The reason we specify phishing-resistant is that attackers now defeat weaker factors at scale — by wearing people down with repeated prompts, or by sitting invisibly between the user and the real login page. Passkeys and hardware keys don't have that failure mode, because the credential is cryptographically bound to the real site.
Backups are the difference between a ransomware incident and a ransomware catastrophe. But only 54% of victims successfully restored from backup in 2025, a six-year low in Sophos's annual survey — usually because nobody had ever tried. And attackers now deliberately target backup infrastructure before deploying encryption, which is why "immutable or offline" matters more than "backed up."
Patching is losing a race. VulnCheck found around 28% of newly exploited vulnerabilities being exploited within a day of disclosure, while the 2026 DBIR put median time-to-patch at roughly 43 days. You will not win this race on everything, so win it on the things that are internet-facing and known to be exploited.
Inventory is first on every serious framework's list because every other control silently fails on the asset you forgot. The recurring post-mortem finding isn't "we had no EDR" — it's "we had EDR everywhere except the server that got hit."
Vendor access made this list because the data moved. Third-party involvement in breaches climbed roughly 60% in a year, per the 2026 DBIR, and the newer mechanism is connected applications — the OAuth integrations that quietly hold access to your email and CRM. Most organizations can't produce that list.
What's deliberately not on the list
A SIEM. Log aggregation without a tuned detection programme and someone to watch it is an expensive storage bill. Get managed detection first.
A penetration test. If you don't yet have MFA and tested backups, a penetration test will tell you things you already know, for several thousand pounds. Fix the known gaps first, then test.
Security awareness training as a primary control. It reduces click rates, but evidence on durable behaviour change is mixed. Train people — and build systems where a single click isn't fatal.
A compliance certification. SOC 2 and ISO 27001 prove a process existed and was audited. They don't prove you're secure. Target was PCI-compliant weeks before its 2013 breach; Change Healthcare was HIPAA-covered and lacked MFA on the portal attackers used.
Where to go once you've done all twelve
You're at the level CIS calls essential cyber hygiene, and where most cyber-insurance applications will stop asking hard questions. The next stage is a named security owner, vulnerability management with real SLAs, monitored detection, and an annually tested incident plan. Our maturity model lays out the levels and — more importantly — warns against buying tools from a level you're not operating at yet.
The most expensive mistake available in security is a threat intelligence platform purchased by an organization that hasn't finished this page.
Cost
For a ten-person business, all twelve for roughly $10,000–$30,000 a year, most of it in a bundled productivity suite that already includes endpoint protection, device management and identity, plus managed detection and a backup product. Several items — DMARC, inventory, least privilege, the IR plan, credit-style hygiene — cost nothing but attention.
Full line-item budgets by organization size are in what security actually costs.
What to do next: Work down the list and mark each item done, partial, or missing. The first "missing" is your next project. If you want a second opinion on where you stand, the security maturity assessment takes about five minutes.
Related: Security maturity model · What security actually costs · Incident response playbooks · How to choose an EDR
Sources: CISA Cross-Sector Cybersecurity Performance Goals 2.0 (Dec 2025). CIS Controls v8.1 Implementation Group 1 (Jun 2024). Verizon 2026 DBIR — third-party involvement and patch timelines. Sophos State of Ransomware 2025 — backup restoration rates. VulnCheck — exploitation timelines. Microsoft Entra telemetry — MFA effectiveness.