
Small businesses do not need a large security team to make a meaningful reduction in cyber risk. Protecting email, turning on multi-factor authentication, keeping devices updated, backing up important data, controlling access and teaching staff how to verify unusual requests can prevent or reduce many common incidents.
The UK National Cyber Security Centre (NCSC) estimates that around half of small businesses experience a cyber incident each year. Its current guidance emphasises that useful improvements do not have to be highly technical and that cyber security should be treated as a shared business responsibility rather than left to one person.
Here are ten practical steps a small organisation can start taking now.
1. Secure your business email first
Email deserves priority because it often provides access to much more than messages. Password resets, invoices, customer conversations and security notifications all pass through the inbox.
If a criminal compromises a business email account, they may be able to:
- impersonate the employee
- request fraudulent payments
- reset other account passwords
- access sensitive customer or commercial information
- change bank details in invoice conversations
Use a strong unique password or passkey and turn on multi-factor authentication. Avoid sharing one mailbox password between several employees.
2. Turn on multi-factor authentication for important accounts
Multi-factor authentication, commonly called MFA, 2FA or two-step verification, adds another check beyond the password.
This is particularly important for:
- online banking
- Microsoft 365 or Google Workspace
- cloud storage
- social media
- website administration
- domain registration and hosting
- accounting and payroll systems
A stolen password is far less useful to an attacker if a second sign-in factor is also required.
3. Stop reusing passwords
Password reuse creates a chain reaction. If one supplier suffers a data breach and the same password is used elsewhere, criminals can try that login across other services.
A reputable password manager makes unique passwords practical. Many browsers, phones and operating systems now include password-management features, while dedicated password managers can synchronise credentials across different devices.
Protect the password manager itself carefully with a strong master login and MFA or a passkey.
4. Keep laptops, phones and software updated
Security updates fix weaknesses that attackers may be actively exploiting. Delaying updates leaves known vulnerabilities available for longer.
Small businesses should enable automatic updates where practical for:
- Windows and macOS
- iPhone, iPad and Android
- web browsers
- Microsoft Office and other productivity applications
- accounting and specialist business software
- routers, firewalls and other network devices where supported
Older hardware and software that no longer receives security updates should be replaced or isolated where appropriate.
5. Make reliable backups and test that you can restore them
A backup is only useful if it contains the data you need and can actually be restored.
Important business data can include:
- accounts and invoices
- customer records
- documents and contracts
- website content
- staff and payroll information
- business databases
Cloud backup can provide a convenient automated option. External storage can also be useful, but removable devices should not remain permanently connected because malware or ransomware may also affect attached storage.
Schedule periodic restore tests. Discovering after an incident that a backup has been incomplete for six months is too late.
6. Give people only the access they need
Not every employee needs administrator rights or access to every business system.
Use individual accounts and apply the principle of least privilege. People should have the minimum access needed for their role.
The NCSC also recommends using a normal standard user account for everyday computer use and reserving administrator accounts for tasks that genuinely require elevated permissions.
This reduces the damage that can occur if a normal account is compromised.
7. Remove access promptly when somebody leaves
Leavers and role changes are a common source of unnecessary access.
When an employee, contractor or agency relationship ends, review:
- email accounts
- Microsoft 365 or Google Workspace
- shared drives
- CRM and accounting systems
- social-media accounts
- website administration
- remote access and VPNs
- password-manager shared vaults
- physical access cards
Do not rely on somebody remembering every service they used. Maintain a basic access checklist so offboarding becomes a repeatable process.
8. Train staff to verify unusual messages and payment requests
Technology alone will not stop every attack. Cyber criminals deliberately target people because a believable message can bypass technical controls.
Teach staff to be particularly cautious when a message:
- creates urgency
- requests a password or verification code
- changes bank details
- asks for an unusual payment
- claims to be from a senior colleague
- contains an unexpected attachment
- asks them to sign in through an unfamiliar link
Payment changes should be verified through a separate trusted channel. For example, if a supplier emails new bank details, telephone a known contact using a number you already hold rather than one in the email.
Our article How to Stay Safe Online provides a broader guide to phishing, impersonation, QR-code scams, fake calls and other common techniques.
9. Create a simple cyber incident plan
You do not need a 100-page incident-response manual. A one-page plan is far better than improvising under pressure.
At minimum, define:
- who takes charge
- who contacts your IT provider
- who contacts the bank if payments are affected
- how staff communicate if email is unavailable
- where backups are located
- how key customers or suppliers will be informed if necessary
- who handles regulatory or insurance notifications
Keep a copy somewhere that remains accessible if your normal systems are unavailable.
10. Work towards Cyber Essentials
Cyber Essentials is the UK government-backed certification scheme designed to protect organisations against common cyber attacks.
It focuses on core technical controls and provides a useful framework for small organisations that want a clear standard to work towards.
The NCSC provides a free Cyber Essentials Readiness Tool, assessment questions and other resources. Cyber Essentials can also be commercially useful because some customers and supply chains expect or require it.
For eligible UK organisations with turnover below £20 million, the scheme currently also includes cyber liability insurance when certification covers the whole organisation, subject to the applicable terms.
Why small businesses are attractive targets
A common misconception is that criminals only want large corporations.
Small organisations may actually be attractive because they often hold useful customer, payment and commercial information while having fewer specialist security resources.
Attackers can also automate much of their activity. They do not need to know your company exists before scanning internet-connected systems or sending phishing messages to business addresses.
The right question is therefore not “Why would anybody target us?” but “How difficult have we made it for a common attack to succeed?”
What are the most common cyber risks for a small business?
Business email compromise
An attacker compromises or convincingly imitates an email account and uses the trust in an existing relationship to redirect payments or obtain information.
Phishing and credential theft
An employee is tricked into entering a username and password into a fake sign-in page.
Ransomware
Malware encrypts or otherwise disrupts access to business systems and data, sometimes accompanied by data theft and extortion.
Weak or reused passwords
Credentials obtained from another breach are used to access business accounts.
Unpatched software
Attackers exploit a known vulnerability that would have been fixed by an available update.
Supplier compromise
A trusted supplier, IT provider or software service is compromised and becomes a route into your organisation.
Do small businesses need antivirus?
Modern Windows devices include built-in security tools and firewalls, while Apple platforms also include integrated security protections. The important point is to keep these features enabled and updated.
Additional security software may be appropriate depending on the organisation, but buying a security product is not a substitute for basic controls such as MFA, updates, backups and access management.
Do small businesses need a firewall?
Yes, but most modern devices and business routers already include firewall functionality. It needs to be configured sensibly and should not be disabled without a clear reason.
Businesses with more complex networks, remote access or externally accessible services may require stronger firewall and network-security management.
How should you protect Microsoft 365?
For organisations using Microsoft 365, start with:
- MFA for all users
- individual rather than shared accounts
- removing unused users and permissions
- reviewing administrator roles
- keeping recovery details secure
- checking suspicious forwarding rules after an account compromise
- using appropriate Microsoft security features for the licence you hold
The same principles apply to Google Workspace and other cloud productivity suites.
How often should staff receive cyber awareness training?
Cyber awareness should not be a one-off annual exercise that everybody forgets.
A practical approach is to provide a structured introduction and then reinforce it with short reminders when risks are particularly relevant, for example:
- before Christmas shopping and delivery periods
- around tax deadlines
- when a major new scam is circulating
- when staff begin using a new system
- during Cyber Security Awareness Month in October
Real examples and clear verification procedures are often more useful than highly technical presentations.
What should a small business do after a suspected compromise?
The response depends on what happened, but the first priorities are usually to contain the problem and protect money, accounts and data.
Actions may include:
- contact your IT provider or internal technical lead
- change compromised passwords through the genuine service
- revoke sessions and reset MFA where necessary
- contact your bank immediately if payments or financial details may be affected
- preserve relevant evidence rather than deleting everything immediately
- identify which systems and people are affected
- restore from clean backups where appropriate
- consider regulatory, insurance, contractual and police reporting requirements
In England, Wales and Northern Ireland, fraud and cyber crime can be reported through Report Fraud. In Scotland, fraud should be reported to Police Scotland.
Cyber Essentials or Cyber Essentials Plus?
Cyber Essentials is based on an organisation completing the certification assessment against the scheme's requirements.
Cyber Essentials Plus uses the same technical controls but adds independent technical verification of the implementation.
For some organisations, standard Cyber Essentials is sufficient. Others choose Plus because a customer, framework or supply chain requires stronger independent assurance.
A 30-day cyber security improvement plan
Week 1: protect accounts
- enable MFA
- stop password reuse
- secure email and admin accounts
- remove unused accounts
Week 2: protect devices and data
- enable automatic updates
- check firewall and built-in security protections
- confirm backups
- perform a test restore
Week 3: protect payments and people
- introduce a payment-detail verification process
- brief staff on phishing and impersonation
- review social-media and website access
Week 4: prepare for an incident
- write a simple response plan
- confirm emergency contact details
- review Cyber Essentials readiness
- record the next review date
Frequently asked questions
Is my business too small to be targeted?
No. Automated attacks, phishing and credential theft affect organisations of every size. Small firms may also be targeted through invoices, supplier relationships and online accounts.
What is the single most important cyber security step?
There is no single control, but securing email and enabling MFA on important accounts are among the highest-value early actions.
How expensive is cyber security for a small business?
Many important improvements cost little or nothing, including MFA, updates, better password practices, access reviews and incident planning. More advanced controls should be added according to risk and business needs.
Do I need a dedicated cyber security employee?
Not necessarily. Many small organisations use an IT provider or external specialist. Someone inside the business should still own the responsibility for ensuring agreed controls and reviews actually happen.
Should all staff receive cyber security training?
Yes. Anyone who uses business email, systems or data can be targeted. Training should match the role, with additional guidance for people handling payments, sensitive data or administrator access.
Is Cyber Essentials worth it for a small business?
It can be. It provides a clear security framework, independent certification and can help when customers or procurement processes expect evidence of basic cyber security controls.
Make cyber security part of normal business practice
The most effective small-business security is not built from one expensive product. It comes from several sensible controls that are maintained consistently.
Protect the accounts that matter most, keep software current, back up your data, verify unusual payment requests, remove unnecessary access and make sure staff know what to do when something looks wrong.
ExperTrain's Cyber Security Glossary explains common terms, while How to Stay Safe Online provides practical guidance that can be shared with employees, friends and family.
Professionals who want to develop deeper skills can also explore ExperTrain's Cyber Security training and Which Cyber Security Certification Should I Take?.
Further reading
Found this article useful? Add ExperTrain as a Preferred Source on Google to help surface more of our training guides, articles and learning resources.




