The security basics have not changed — but the attacks have. In 2026, phishing emails are written by AI and are nearly flawless. Attackers buy ready-made ransomware kits and target small businesses precisely because they assume no one is watching. And a new gap has opened up: staff pasting company data into AI tools no one approved. A checklist from three years ago will not cover any of that.
Here is a current, practical checklist you can work through this quarter — no security team of your own required.
The non-negotiables
- Phishing-resistant login. Move beyond SMS codes toward passkeys and app-based multi-factor authentication. AI-written phishing is convincing enough that “spot the typo” advice no longer works — the login method itself has to resist it.
- Modern endpoint detection (EDR/MDR). Traditional antivirus waits for known signatures. Managed detection watches behaviour and stops ransomware as it starts to move.
- A password manager for everyone. Reused passwords are still how one leak becomes ten.
- Automatic patching. Most exploited flaws had a fix available for months. Close that window.
- Immutable, tested backups. Copies an attacker cannot encrypt or delete, and that you have actually restored recently.
The 2026 additions most checklists miss
- An AI-use policy. Your team is already using AI tools. Decide which are approved, what data can go into them, and make it clear — before sensitive information leaks through a chat box.
- Zero-trust access. Stop trusting devices just because they are “inside” the network. Verify every user and device, every time, and grant only what the job needs.
- Tight offboarding. The day someone leaves, every bit of access leaves with them — including the SaaS and AI tools IT never formally set up.
- MFA-fatigue awareness. Attackers now spam approval prompts hoping someone taps “yes.” Staff should know never to.
Match the effort to the risk
You do not need enterprise budgets. Start with phishing-resistant login, managed detection, immutable backups and an AI-use policy — those four close the doors most 2026 attackers walk through. Layer the rest in over the next couple of quarters.
If you would rather not track all of this yourself, that is exactly what a managed security partner is for. We will run the current checklist against your environment across every region you operate in, tell you plainly where you stand, and handle the parts you would rather not think about. Book a free assessment to get your baseline.