Essential 8. This is by the Australian Government - things to start with first.
https://www.cyber.gov.au/acsc/view-all-content/essential-eight/essential-eight-explained
https://www.cyber.gov.au/acsc/view-all-content/publications/essential-eight-maturity-model
5 Knows. This is a really good basic framework
Basics
Passwords
Phishing
Data Storage
Sharing Data
PCI Compliance
Access restriction
Principle of least privilege
Alerts for data changes
eg Email employee if their bank details change on the payroll system
Visibility
Logs
Protecting emails - eg having rules in place for money transfers eg for Email hacking.
SPF / DMARC / DKIM
Add Comment