CyberSafe · Security guide

Identity hardening baseline

Identity is the control plane. Do these in order. Check the box only when verified, not when “the vendor said so.”

  1. Inventory every admin: cloud, Microsoft 365 / Google, domain, firewall, vCenter, backups.
  2. Phishing-resistant MFA on those admins. No SMS for privileged roles if you can avoid it.
  3. Separate admin identities from daily email identities.
  4. Disable legacy protocols that skip MFA.
  5. Mailbox forwarding and inbox rules: weekly review for finance and executives.
  6. Conditional access / device checks for admin paths.
  7. Leaver process: same day, not next week.
  8. Break-glass accounts: stored offline, tested, monitored.

CyberSafe · Fenolink Enterprises · Jul 2026