Cybersecurity Checklist for Qatar SMEs: 15-Point Risk Assessment
Why SMEs Are Targeted
- 60% of cyberattacks target companies under 250 employees
- SMEs often lack dedicated security staff
- Ransomware averages QAR 2.5M+ ransom demand in Middle East
- Average breach cost in Qatar region: QAR 8.5M (downtime, recovery, fines)
15-Point Cybersecurity Checklist
Tier 1: Critical (Implement First)
1. ☑ Firewall & Network Security
Requirement: Enterprise-grade firewall (Fortinet FortiGate, Cisco ASA, or Sophos)
Checklist:
- [ ] Firewall deployed at network edge
- [ ] DPI (Deep Packet Inspection) enabled
- [ ] IPS (Intrusion Prevention System) active
- [ ] Antivirus/malware filtering enabled
- [ ] VPN for remote workers configured
- [ ] Firewall firmware updated within last 30 days
Cost: QAR 15,000–40,000 (hardware + licensing) Implementation Time: 1–2 weeks
2. ☑ Multi-Factor Authentication (MFA)
Requirement: MFA on all critical accounts (email, VPN, admin)
Checklist:
- [ ] MFA enforced for email (Microsoft 365, Gmail)
- [ ] MFA enabled for VPN access
- [ ] MFA for financial systems (accounting software, banking)
- [ ] MFA for Active Directory/domain login
- [ ] Hardware keys OR authenticator apps (Microsoft Authenticator, Google Authenticator)
Cost: QAR 500–2,000 (apps are free, hardware keys ~QAR 200 each) Implementation Time: 1 week
3. ☑ Backup & Disaster Recovery
Requirement: 3-2-1 backup strategy
- 3 copies of data
- 2 different storage types
- 1 off-site copy
Checklist:
- [ ] Daily incremental backups (8 TB+ storage minimum)
- [ ] Weekly full backups
- [ ] Monthly off-site backup (cloud or external facility)
- [ ] Backup tested quarterly (actual recovery drill)
- [ ] RTO (Recovery Time Objective): < 4 hours
- [ ] RPO (Recovery Point Objective): < 1 hour data loss acceptable?
- [ ] Backup logs monitored weekly
Cost: QAR 20,000–50,000 (Veeam licensing + storage) Implementation Time: 2–3 weeks
4. ☑ Endpoint Detection & Response (EDR)
Requirement: Antivirus + behavioral threat detection on all devices
Checklist:
- [ ] EDR deployed on 100% of endpoints (Windows, Mac, Linux)
- [ ] Threat intelligence enabled (real-time updates)
- [ ] Quarantine rules configured
- [ ] Incident response automated (isolate infected device)
- [ ] Weekly patch management (OS + software updates)
- [ ] USB/external drive restrictions configured
Cost: QAR 3,000–8,000/year (50 users) Implementation Time: 1 week
Recommended: Microsoft Defender, CrowdStrike, or Sophos
5. ☑ Access Control & User Permissions
Requirement: Principle of Least Privilege (PoLP)
Checklist:
- [ ] Active Directory (AD) configured with security groups
- [ ] Admin accounts separated from daily-use accounts
- [ ] File share permissions audited (no "Everyone" access)
- [ ] Database access restricted by role
- [ ] Service accounts use strong, unique passwords
- [ ] Quarterly review of user access (remove leavers)
- [ ] Privileged Access Management (PAM) for critical systems
Cost: QAR 0 (if using Windows Server AD) Implementation Time: 3–4 weeks (audit + remediation)
Tier 2: Important (Implement Within 3 Months)
6. ☑ Email Security
Checklist:
- [ ] Email gateway filtering (Fortinet, Proofpoint, Mimecast)
- [ ] SPF, DKIM, DMARC records configured
- [ ] Phishing simulation training completed (staff training monthly)
- [ ] Advanced email encryption for sensitive data
- [ ] External email banner (warns of external emails)
- [ ] Attachment sandboxing enabled
Cost: QAR 2,000–5,000/year Implementation Time: 1 week
7. ☑ Password Policy & Management
Checklist:
- [ ] Passwords minimum 14 characters
- [ ] Complexity requirements (uppercase, lowercase, numbers, symbols)
- [ ] Password expiration: 90 days for sensitive accounts
- [ ] Password history: Last 12 passwords cannot be reused
- [ ] Shared passwords eliminated (use password manager)
- [ ] Password manager deployed (1Password, Bitwarden, LastPass)
- [ ] Default passwords changed on ALL systems
Cost: QAR 1,000–3,000/year (password manager) Implementation Time: 2 weeks
8. ☑ Network Segmentation
Checklist:
- [ ] Separate VLAN for guests/visitors (no access to internal network)
- [ ] DMZ for public-facing systems (web server, mail server)
- [ ] Financial systems on isolated VLAN with restricted access
- [ ] IoT devices (cameras, printers) segmented
- [ ] Inter-VLAN traffic monitored
- [ ] Firewall rules reviewed quarterly
Cost: QAR 5,000–15,000 (managed switch + configuration) Implementation Time: 3–4 weeks
9. ☑ Logging & Monitoring
Checklist:
- [ ] Firewall logs retained (minimum 90 days)
- [ ] Windows Event Logs centralized (Syslog or SIEM)
- [ ] File access logs enabled (audit trail)
- [ ] Failed login attempts monitored (alert on 5+ failures)
- [ ] Database audit trails enabled
- [ ] Suspicious activity reviewed daily
- [ ] SIEM (Security Information & Event Management) deployed for enterprises
Cost: QAR 1,000–5,000/year (ELK Stack is free, commercial SIEMs: QAR 10k+) Implementation Time: 2–3 weeks
10. ☑ Incident Response Plan
Checklist:
- [ ] Written incident response procedure (1–2 pages minimum)
- [ ] Defined roles (who is incident commander, who notifies, who communicates)
- [ ] Incident classification (low, medium, high, critical)
- [ ] Escalation matrix (when to notify management/customers)
- [ ] Communication template (what to say, what NOT to say)
- [ ] Evidence preservation (forensics chain of custody)
- [ ] Post-incident review process
- [ ] Annual tabletop drill conducted
Cost: QAR 0 (internal) + QAR 10k–20k if outsourcing IR consultant Implementation Time: 2 weeks
Tier 3: Important (Implement Within 6 Months)
11. ☑ Data Encryption
Checklist:
- [ ] Full-disk encryption (BitLocker for Windows, FileVault for Mac)
- [ ] Data in transit: TLS 1.2+ for all connections
- [ ] Database encryption at rest (EDB, MySQL TDE)
- [ ] Sensitive files encrypted (PII, financial data)
- [ ] Encryption key management documented
- [ ] Backup encryption enabled
Cost: QAR 1,000–3,000 (licensing + implementation) Implementation Time: 2–3 weeks
12. ☑ Vulnerability Management
Checklist:
- [ ] Quarterly vulnerability scans (Nessus, Qualys, OpenVAS)
- [ ] Penetration testing annually (external + internal)
- [ ] Patch management system deployed
- [ ] Critical patches applied within 48 hours
- [ ] Non-critical patches applied within 30 days
- [ ] CVSS risk scoring used to prioritize
- [ ] Remediation tracked and signed off
Cost: QAR 5,000–10,000/year (scanning tools) Implementation Time: 1–2 weeks to set up
13. ☑ Vendor Risk Management
Checklist:
- [ ] Vendor security questionnaire (SaaS providers)
- [ ] Third-party penetration test results reviewed
- [ ] SLA terms include security clauses
- [ ] Data handling agreement (DPA) in place
- [ ] Incident notification requirements defined
- [ ] Annual vendor audit scheduled
Cost: QAR 0 (review existing contracts) Implementation Time: 4 weeks
14. ☑ Compliance & Audit
Relevant for Qatar:
- Qatar Central Bank: Cybersecurity controls for banks
- QMRA (Qatar Ministry of Public Health): Healthcare data protection
- QNCC: Government security standards
- ISO 27001: International information security standard
- GDPR: If handling EU customer data
- Saudi Aramco SAFESQ: If supplying to Saudi energy sector
Checklist:
- [ ] Compliance requirements identified
- [ ] Internal audit conducted
- [ ] Gap analysis completed
- [ ] Remediation roadmap created
- [ ] External audit scheduled (annually)
- [ ] Certifications pursued (ISO 27001)
Cost: QAR 30,000–80,000/year (audit + remediation) Implementation Time: 3–6 months
15. ☑ Security Awareness Training
Checklist:
- [ ] Mandatory security training for all staff (quarterly)
- [ ] Phishing simulation training monthly
- [ ] Clean desk policy (no sensitive data visible)
- [ ] Acceptable use policy (internet, email, devices)
- [ ] Mobile device management (MDM) policy
- [ ] BYOD (Bring Your Own Device) policy
- [ ] Incident reporting mechanism (anonymous if possible)
- [ ] Board-level cybersecurity awareness
Cost: QAR 2,000–5,000/year (online training platform) Implementation Time: 1 month to implement
Priority Implementation Timeline
Month 1 (Critical)
- [ ] Firewall deployment
- [ ] MFA enablement
- [ ] EDR deployment
- [ ] Backup system setup
Months 2–3 (Important)
- [ ] Email security
- [ ] Network segmentation
- [ ] Logging & monitoring
- [ ] Access control audit
Months 4–6 (Ongoing)
- [ ] Vulnerability management
- [ ] Compliance audit
- [ ] Incident response plan
- [ ] Security training
Cost Summary (50-User SME)
| Tier | Controls | Estimated Cost | Timeline | |------|----------|---------------|-----------| | Critical | Firewall, MFA, Backup, EDR | QAR 40,000 | 4 weeks | | Important | Email, Segmentation, Logging | QAR 15,000 | 8 weeks | | Ongoing | Training, Compliance, Monitoring | QAR 5,000/year | 12 weeks | | Total Year 1 | — | QAR 60,000 | 12 weeks | | Ongoing Annual | — | QAR 8,000–12,000/year | — |
Recommended Tools by Category
Firewall: Fortinet FortiGate 100D (QAR 18k), Cisco ASA (QAR 25k), Sophos XGS (QAR 20k)
EDR: Microsoft Defender (free with M365), CrowdStrike (QAR 200/endpoint/year), Sophos XDR (QAR 150/endpoint/year)
Backup: Veeam Backup & Replication (QAR 30k), Acronis (QAR 15k), Commvault (QAR 40k+)
SIEM: ELK Stack (free), Splunk (QAR 50k+), Datadog (QAR 20k+)
Password Manager: Bitwarden (QAR 1k/year), 1Password (QAR 2k/year), LastPass (QAR 1.5k/year)
Star Tech's Cybersecurity Services
✓ Complete security assessment (15-point checklist) ✓ Firewall design & deployment (Fortinet NSE certified) ✓ Incident response planning & tabletop drills ✓ Compliance audit (ISO 27001, QCB, QNCC) ✓ 24/7 SOC (Security Operations Center) monitoring ✓ Annual penetration testing
Get Your Free Security Assessment → Identify gaps and create a roadmap.
