Free resource · Security
The IT Security Review Checklist
The right firewall, not the biggest. What to check before you buy anything, the controls that actually stop what happens to businesses here, and how to tell a real review from a product pitch.
This is the checklist we work from when we review a business network. It is written so you can use it with any provider, including one that isn't us.
Most security selling in this market works by making you frightened and then selling you the largest box on the price list. That is not a review. A review starts by finding out what you have, what would actually hurt if you lost it, and how somebody would realistically get in — and in the UAE the realistic answer is almost never a Hollywood hacker. It is an invoice email, a stolen password, or a laptop nobody had encrypted.
Nothing below requires you to buy anything from us. Several items cost nothing at all and remove more risk than a firewall upgrade.
1Before anyone sells you anything
- What are you actually protecting: customer data, designs, financial records, a production line, or a licence to operate
- What would genuinely hurt — being down for a day, losing the data permanently, or it becoming public
- How many staff, how many devices, how many sites
- Who has administrator rights today, and can anyone name them all
- What is already in place, with model numbers, licence expiry dates and who supports it
- Has anyone written down what happened the last time something went wrong
- Any contractual or regulatory obligation you have signed up to — a parent company policy, a client's supplier requirements, a sector regulator
2The things that actually happen to businesses here
Ranked by how often we are called about them, not by how alarming they sound.
- Invoice fraud. Someone reads your email long enough to learn who pays whom, then sends a real-looking invoice with changed bank details. Controls: MFA on every mailbox, alerts on mailbox forwarding rules, and a rule that bank detail changes are verified by phone on a number you already held
- Stolen or reused passwords. One password used on a shopping site turns up in a breach and opens your email. Controls: MFA everywhere, a password manager, and no shared logins
- Ransomware arriving through a normal-looking file. Controls: tested backups held offline or immutable, endpoint protection, and users who are not local administrators
- The leaver who still has access. Controls: a joiner-mover-leaver process someone actually follows
- The laptop in the back of a taxi. Controls: full-disk encryption, screen lock, and the ability to wipe remotely
- The forgotten remote-access door left open by a supplier or a previous IT provider
3Identity — the part that matters most
- Multi-factor authentication on every account, not just the directors'
- MFA specifically on finance, HR and any shared mailbox that receives invoices
- No shared logins. If a department shares one, that is a finding, not a habit
- Administrator accounts separate from everyday accounts, and used only when needed
- A count of how many global administrators exist. If nobody knows, that is the answer
- A break-glass admin account, written down, stored somewhere safe, excluded from normal policy
- Mailbox forwarding rules reviewed — attackers create them quietly and read your mail for weeks
- Conditional access or sign-in restrictions where the platform supports it
- Password manager in use, so people stop reusing the same password everywhere
4The firewall and the network
- Sized to your throughput with inspection turned on, not the headline number on the datasheet
- Licence and subscription expiry dates known and diarised. An expired UTM licence is a plain router
- Firmware version current, and someone named as responsible for updating it
- Rules reviewed with a reason recorded for each. Any/any rules identified and justified or removed
- Nothing published to the internet that does not need to be. Every open port has a named owner
- Remote access through VPN or ZTNA with MFA — never a port forwarded straight to a machine
- Guest wifi genuinely separated from the business network, not just a different password
- Admin interfaces not reachable from the internet
- Logging enabled and going somewhere, with someone who would notice
5Devices
- Full-disk encryption on every laptop. Check it is actually on, device by device
- Users are not local administrators on their own machines
- Endpoint protection deployed everywhere, with a console someone actually looks at
- Operating systems still supported. An out-of-support machine is a permanent open door
- Patching happening on a schedule, including third-party software
- Screen lock enforced, with a sensible timeout
- Remote wipe available for laptops and phones that hold company mail
- Personal devices: decided policy, either properly managed or properly excluded
6Data and backup
- You know where the important data actually lives — including the copy on somebody's desktop
- Backups exist for everything that matters, including cloud mail and files. Microsoft replicating your data is not a backup
- At least one copy is offline or immutable, so ransomware cannot encrypt the backup too
- A restore has been tested. Ask when, and what was restored. "It runs green every night" is not an answer
- Retention period decided deliberately, not by default
- Who can access which shared folders, reviewed at least once a year
- Data residency understood if your bank, auditor or parent company cares where it sits
7People and process
- A joiner-mover-leaver process, written down, that someone follows on the day
- Accounts disabled the same day someone leaves — not at the end of the month
- Staff told, in plain language, how invoice fraud works and what to do about it
- A named person to report something suspicious to, and no blame for reporting a false alarm
- Suppliers with access to your systems listed, with what they can reach and when it was last reviewed
- Someone in the business who owns this, even if the work is outsourced
8When something goes wrong
- Who is called first, at 2am, with real phone numbers
- Where the incident contact list lives — not only inside the system that might be down
- How you would communicate if email were unavailable
- Which obligations you have to report, to whom, and within what timeframe
- Your insurer's requirements, if you carry cyber cover, checked before you need to claim
- Whether anyone has ever walked through this as a conversation, even for twenty minutes
UAE organisations should confirm reporting obligations with the UAE Cyber Security Council and any sector regulator. Requirements as of August 2026 and subject to change. Ontrac is an IT provider, not a legal or compliance adviser.
9How to judge the review you are given
- Findings are ranked by risk to your business, not by severity score from a scanner
- At least some findings cost nothing to fix. If every recommendation is a purchase, be suspicious
- Each finding says what could actually happen, not just what is technically true
- You are told what is good as well as what is wrong
- The report is in language you can hand to a non-technical director
- You own the report and the evidence behind it
- Anything the reviewer would sell you is declared as such
10The ones that catch people
The expired licence. The firewall is still there, still blinking, still inspecting nothing. Nobody notices because nothing visibly breaks.
MFA on the directors only. Attackers do not target the person with the most authority. They target the person who processes payments.
The mailbox rule. A quiet forwarding rule that copies every invoice to an outside address. It has usually been there for weeks before anyone looks.
The backup nobody restored. Green every night for two years, and unusable on the one day it is needed.
The previous IT provider. Still has admin access, sometimes years later, occasionally without realising it themselves.
The one unsupported machine running the one application nobody will replace. It only takes one.
Want the printable version?
Leave an email and the checklist arrives in your inbox straight away. No newsletter, no drip campaign. You can also just print this page.
We will also look over a security proposal you have had from someone else and tell you what is missing, at no charge — including whether you are being sold something you do not need.