UK-based • Microsoft 365–centric • Governance-led approach
It focuses on what must be true, what you should be able to show, and who owns it.
This checklist is for you if your business is:
A 10-25 person, owner-managed SMEs in Sussex & Kent (or the South East)
Already using Microsoft 365 day-to-day
Limited (or no) in-house IT capacity
Want baseline clarity before making IT/security decisions or to help meet supplier expectations
5 sections mapped to CE control themes (Firewalls, Secure configuration, User access control, Malware protection, Security update management)
Evidence prompts (what you should be able to show)
Owner prompts (internal / supplier / shared)
A short misconceptions box
A clear “what next” path (Triage → Baseline Review)