Addressing those questions during the change helps the team build something dependable. It also makes it easier to try new ideas within understood limits.
Cyber security belongs in the design of the work, the choice of suppliers and the responsibilities people take on after launch.
Start with the work you need to protect
Choose an important service and follow how it operates. Identify the information, accounts, devices and suppliers it relies on. Include the small dependencies: the email account used to reset passwords, the person who holds administrator access and the spreadsheet exported before a payment run.
Ask what would happen if information were disclosed, changed without permission or unavailable. Different failures need different responses. A lost customer record and a payment instruction altered by an attacker are both serious, but they do not create the same problem.
The ICO's data security guidance explains why protecting personal information involves organisational measures as well as technology, including the ability to restore access after an incident. Use that as part of the discussion with the people responsible for your data protection obligations.
Set priorities around the consequences for customers, colleagues and the organisation. That gives security decisions a purpose the whole team can understand.
Apply it to your work
Four checks before the service changes
- Access
Who needs an account, and who removes access?
- Maintenance
Who keeps the system and its safeguards current?
- Suppliers
What does the service depend on outside your organisation?
- Recovery
Can the team restore the work when something fails?
Make account access a deliberate choice
Decide who needs to see information and who needs to change it. Give people the access required for their role, and separate routine work from administrator privileges. Include a clear process for starters, role changes and leavers.
Protect the accounts that allow access to other accounts, especially email and identity services. The NCSC recommends passkeys where they are supported. Where passwords remain in use, use strong, unique passwords and two-step verification. Check recovery arrangements too, so a lost device does not leave the organisation unable to regain access safely.
Apply the same care to connections between systems. An integration or automated assistant may hold permissions long after the person who set it up has changed roles. Record what it can do, who owns it and how access can be revoked. Test new connections with limited permissions and a defined scope.
Review access as the work changes. The NCSC's account guidance includes removing accounts that are no longer needed and keeping administrator access separate from everyday use.
Agree who maintains the basics
Find out which devices and applications still receive security updates, who applies them and how you know the process is working. Include equipment used away from the office and personal devices approved for work.
An unsupported product needs a replacement or a properly assessed alternative arrangement. Keeping old technology indefinitely can leave a risk that an otherwise careful team cannot fix. The NCSC's device guidance covers updates, access protection and removing unused or unsupported software.
Cyber Essentials provides a useful technical baseline across firewalls, secure configuration, security updates, user access and malware protection. Check its current requirements when planning an assessment. Certification has a defined scope; the organisation still needs to manage the risks of its particular services and information.
Ask suppliers questions you can act on
A supplier may run part of the service, but you still need to understand the arrangement. Establish what they provide and what remains your responsibility.
For an important system, ask:
-
What information will the service hold, and which other providers are involved?
-
How are customer accounts, administrator access and support access controlled?
-
What will we be told if something goes wrong, and through which contact?
-
What can be restored after deletion, corruption or an attack, and who performs that work?
-
Can we export usable information and move to another service if necessary?
Ask for evidence proportionate to the risk. A badge or questionnaire answer should lead to a clearer decision about the service you will actually use. The NCSC's supply chain principles begin with understanding what needs protection and the dependencies that could affect it.
Record important answers and revisit them when the service, contract or information involved changes.
Practise recovering the work
Backups need to cover the information the organisation depends on, and somebody needs to know how to restore it. Check the retention period, who can delete copies and whether an attacker with ordinary account access could also reach the recovery copy.
Test restoration before an incident. The NCSC's backup guidance recommends keeping backups separate from the devices they protect and checking that recovery works.
Then consider the wider service. How would the team contact each other if email were unavailable? Which work could continue safely? Who would speak to the supplier and decide what customers need to know?
Run through a realistic scenario with the people involved. Keep essential contacts and instructions accessible if the main system is down. Record the gaps the exercise reveals and give each one an owner.
Make it easy to raise a concern
People need a straightforward way to report a suspicious message, an unexpected access request or a mistake. Make the route visible and explain what will happen after they use it.
A person who thinks they have entered a password on the wrong page needs help quickly. A reporting process that feels punitive can make that conversation harder. Use incidents and near misses to improve the service as well as individual understanding.
Before a digital change goes live, check that the team knows who owns access, updates, supplier contact and recovery. After launch, revisit those responsibilities and test the arrangements.
That is how security supports change: the organisation understands what it relies on, gives people usable safeguards and can respond when something goes wrong.
Based on Yopla source material from 2023. Refreshed for this edition.
All insights