CyberSafe · Security guide
Identity hardening baseline
Identity is the control plane. Do these in order. Check the box only when verified, not when “the vendor said so.”
- Inventory every admin: cloud, Microsoft 365 / Google, domain, firewall, vCenter, backups.
- Phishing-resistant MFA on those admins. No SMS for privileged roles if you can avoid it.
- Separate admin identities from daily email identities.
- Disable legacy protocols that skip MFA.
- Mailbox forwarding and inbox rules: weekly review for finance and executives.
- Conditional access / device checks for admin paths.
- Leaver process: same day, not next week.
- Break-glass accounts: stored offline, tested, monitored.