A practical security baseline for freelancers and small teams
Prioritize identity, devices, access, backups, and reporting without building a large security program.
Start with the situation
A freelancer or small team rarely needs a complex security program first. It needs clear ownership and a few controls that are maintained.
The decision to make
Protect the accounts and information that would most disrupt the work, then make the baseline repeatable for every person and device.
A practical sequence
- Use unique passwords in a password manager, enable MFA, and avoid shared accounts.
- Turn on supported automatic updates, disk encryption, screen locking, and appropriate endpoint protection.
- Give each person only the access needed, separate daily and administrative work, and remove access promptly when roles change.
- Keep tested backups appropriate to the data and ensure at least one recovery path is not writable from the everyday environment.
- Name the person or provider to contact and make early reporting safer than silence.
Real-world examples
- Use named accounts instead of one shared administrator login.
- Review access when a contractor finishes rather than waiting for an annual audit.
- Test restoring one important file instead of assuming a completed backup can be recovered.
Common mistakes
- Buying tools without assigning anyone to maintain them.
- Using administrator privileges for routine browsing and email.
- Treating a synchronized cloud folder as the only backup without checking recovery behavior.
What to do next
Record the baseline in one page, assign an owner, and review it after staff, supplier, device, or service changes.
A small baseline that is owned and tested is stronger than a long checklist nobody maintains.
Trusted official references
- CISA
Cyber Guidance for Small Businesses
Prioritized cybersecurity actions and incident-planning guidance for small organizations.
View official source - UK NCSC
Small organisations guide to cyber security
Practical guidance covering accounts, devices, backups, scams, and shared responsibility.
View official source
