A structured 30-day plan to harden security for companies with 15-80 employees. Week-by-week actions with specific deliverables and verification steps.
Executive summary: This plan provides a structured 30-day sequence for implementing the five core security controls that address 90% of the attack surface for companies with 15-80 employees. Week 1 deploys MFA and conducts an access audit. Week 2 implements email security with sandboxing and DMARC. Week 3 configures automated patching and endpoint protection. Week 4 establishes network segmentation and immutable backup architecture. Each week has specific deliverables, verification steps, and the expected time commitment. The plan is designed for companies without dedicated security staff.
You know your security needs improvement. You have been meaning to address it. But security projects expand to fill all available time unless they are bounded and structured. This plan gives you a 30-day timeline with specific weekly deliverables. Four weeks. Five controls. Proportional security that you can implement alongside running your business.
Security improvements that are not scheduled do not happen. This plan converts abstract security goals into a concrete weekly action plan with deliverables you can verify. Each week's actions are scoped to approximately 8-12 hours of effort — split between your internal team and any external support you engage. After 30 days, you have a documented, verifiable security posture that addresses the threats most likely to affect your business.
At the end of 30 days, you have: MFA enforced on 100% of accounts, email security blocking threats before they reach inboxes, automated patching closing vulnerabilities within 14 days of release, network segmentation limiting lateral movement, and immutable backups verified through test restoration. Each control is documented, and you have a monthly maintenance checklist to keep it current.
Each week builds on the previous. MFA must be verified before email security is deployed because MFA protects the accounts that manage email security. Skipping verification creates gaps in the foundation.
A security control that is configured but not tested may not work as expected. Each week includes specific verification steps — skip them and you have theoretical security rather than actual security.
Security controls degrade over time without maintenance. New accounts need MFA. New systems need patching. Access permissions need review. The plan includes a maintenance protocol — implement it or the security posture erodes within months.
Insurance brokerage (Financial Services): 30 days from zero to documented security posture. Followed the 30-day plan exactly. Starting from basic antivirus as their only security measure, they implemented all five controls within the timeline. Their first client security questionnaire after implementation was passed completely — something they had been deflecting for two years.
Architecture and engineering firm (Professional Services): $0 additional tools required beyond existing Microsoft 365 licensing. Discovered that their existing Microsoft 365 Business Premium licensing included MFA, email security, endpoint management, and conditional access. The 30-day plan primarily required configuration of existing capabilities rather than purchasing new tools.
| Metric | Before | After |
|---|---|---|
| Security Posture | Basic antivirus only | 5-control defense in depth |
| Implementation Timeline | Indefinite (no plan) | 30 days (structured) |
| Weekly Time Commitment | N/A | 8-12 hours per week |
| Client Audit Readiness | Deflected | Passed |
This plan converts security from a project you have been postponing into a structured four-week implementation with specific weekly deliverables.
Week 1: Identity and Access (Days 1-7)
Day 1-2: Conduct an access audit. List every user account across all business systems. Identify which accounts have administrative access. Document which accounts have MFA enabled and which do not.
Day 3-4: Deploy MFA on all accounts that do not have it. Start with administrative accounts, then user accounts. Use your identity platform's built-in MFA — Azure AD, Google Workspace, or equivalent.
Day 5-6: Review administrative access. Identify accounts with admin rights that do not require them for their current role. Revoke unnecessary admin access. Separate admin and daily-use accounts for people who need both.
Day 7: Verify. Confirm 100% MFA enrollment. Confirm admin access is limited to justified accounts. Document the baseline.
Week 2: Email Security (Days 8-14)
Day 8-9: Enable email security with attachment sandboxing. If your platform includes it (Microsoft Defender for Office 365, Google Workspace security), configure it. If not, deploy a third-party email security service.
Day 10-11: Configure DMARC. Start with a monitoring policy (p=none) to identify all legitimate email sources. Configure SPF and DKIM for all sources.
Day 12-13: Review quarantine and configure notifications. Ensure that quarantined emails are reviewed daily. Configure user notifications for quarantined messages.
Day 14: Verify. Send test phishing emails to confirm sandboxing is working. Verify DMARC is reporting correctly.
Week 3: Patching and Endpoint Protection (Days 15-21)
Day 15-16: Deploy endpoint management. Use Intune, Jamf, or equivalent to manage all company devices. Create a device inventory.
Day 17-18: Configure automated patching. Set policies for operating system and application updates. Define a maximum patch delay of 14 days for critical updates.
Day 19-20: Deploy endpoint detection if not already present. Configure alerting for suspicious endpoint activity.
Day 21: Verify. Confirm all endpoints are enrolled and receiving patches. Run a vulnerability scan to establish baseline.
Week 4: Network and Backup (Days 22-30)
Day 22-24: Implement network segmentation. Separate your network into zones: administrative systems, production systems, and guest access. Configure firewall rules between zones.
Day 25-27: Deploy immutable backup architecture. Configure backup targets that cannot be modified or deleted by production system administrators. Set backup frequency appropriate to your data change rate.
Day 28-29: Test backup restoration. Restore your most critical system from backup to a test environment. Verify data integrity and application functionality.
Day 30: Document and establish maintenance. Document all deployed controls. Create a monthly maintenance checklist. Assign ownership for ongoing security monitoring.
You now have five independent security controls that address the primary attack vectors for companies your size. Maintain them through the monthly checklist, verify them through quarterly testing, and improve them incrementally as your risk profile evolves.
Part of the Security Hardening insights cluster at JubilantWeb. Reviewed by Nelson Penagos, Founder & Systems Architect. Contact: hello@jubilantweb.com | (407) 630-8771
Yes, because the controls that address 90% of your risk are not complex to deploy. MFA is a configuration change in your identity platform. Email security is a service activation and DNS update. Automated patching is a policy configuration in your endpoint management tool. Network segmentation is a router and firewall configuration. Immutable backup is a backup target configuration change. None of these require custom development or extensive infrastructure changes. They are configurations of tools you likely already own or that are available as affordable services. The 30-day timeline is realistic because each control is a configuration task, not a construction project.
Three prerequisites. First, administrative access to your identity platform, either Azure Active Directory, Google Workspace admin, or equivalent. Second, administrative access to your email platform and DNS records for DMARC configuration. Third, a current inventory of your endpoints — how many workstations, laptops, and servers your company operates. If you do not have an endpoint inventory, creating one becomes the first task of Week 1. You do not need specialized security tools before starting. The plan identifies what to deploy at each stage. Starting with what you have and adding what you need as the plan progresses prevents the common paralysis of trying to select and purchase everything before beginning.
For companies already on Microsoft 365 Business Premium or equivalent, most controls are included in existing licensing and require only configuration. Additional costs typically include: call tracking or DNS configuration for DMARC setup which is minimal, and immutable backup storage which ranges from $50-200 per month depending on data volume. If you need to add email sandboxing beyond what your current platform provides, expect $3-5 per user per month. Total incremental cost for most companies is $200-800 per month. If you engage external help for implementation, a focused 30-day engagement typically costs $3,000-8,000 depending on environment complexity. Many companies find they can implement the plan internally with occasional vendor support.
After the initial implementation, security becomes a maintenance practice rather than a project. The monthly maintenance routine takes approximately 2-4 hours and includes: verifying that MFA enrollment is complete for any new accounts, reviewing email security quarantine reports for false positives or missed threats, confirming that automated patching is current with no failed updates, reviewing access permissions for any changes since the last review, and verifying that backup jobs are completing successfully. Quarterly, you should run a backup restoration test and conduct a full access review. Annually, consider a security assessment or penetration test to validate that your controls are performing as expected.
If you can only do one control immediately, deploy universal MFA. It blocks the highest-probability attack vector and costs nothing beyond configuration effort. If you can do two, add email security with sandboxing — this catches the second most common vector. If you can do three, add automated patching. The five controls are listed in priority order within the plan. Each one provides standalone value even if you pause before implementing the remaining controls. However, the full five-control implementation provides defense in depth that no subset achieves alone. A single control can be bypassed. Five independent controls make bypass exponentially more difficult.