Search

Cyber Security Checklist for Small Businesses in the UK

A cyber attack does not need to involve an international criminal group breaking through sophisticated defences. For a small business, it may begin with one convincing phishing email, a reused password, an unpatched laptop or an employee account that was never disabled after the person left.

That is why an effective cyber security checklist should concentrate first on ordinary weaknesses that attackers repeatedly exploit.

The latest UK government survey found that 46% of small businesses identified a cyber breach or attack in the previous 12 months. Phishing remained particularly common. Small businesses therefore need practical controls covering email, accounts, devices, software, backups, employees and incident response rather than assuming they are too small to attract criminals.

This guide provides a practical framework for SME security, including ransomware protection, GDPR security, employee responsibilities and wider business cyber safety.

What Is Cyber Security and Why Is It Important for Small Businesses?

Cyber security is the protection of devices, systems, accounts, networks and information against unauthorised access, disruption, theft, manipulation or destruction.

For a small business, that can involve everything from protecting a Microsoft 365 account to preventing an attacker from encrypting the files needed to invoice customers.

The risks are both technical and human.

An employee may accidentally send confidential information to the wrong person. A criminal could steal an email password and use the account to request fraudulent payments. Malware could compromise a laptop. Ransomware could make important operational information unavailable.

Cyber security therefore involves more than antivirus software.

It combines technology, policies, employee behaviour and preparation for when something goes wrong.

A well-protected small company should know which information and systems are essential, who can access them, how accounts are secured, when software is updated, where backups are kept and what employees should do if they suspect an attack.

The aim is not to make the organisation impossible to attack. No realistic security programme can promise that.

The aim is to reduce the likelihood of successful attacks and limit the damage if one occurs.

Why Cyber Security Is Important for UK Small Businesses

Small businesses can be attractive targets because they often handle valuable information and payments without having the specialist security teams found in large organisations.

The latest Cyber Security Breaches Survey estimates that 43% of businesses overall and 46% of small businesses identified a breach or attack during the previous year. Phishing was the most common category, while impersonation attacks also remained significant.

A cyber incident can affect more than computers.

Consider a small professional firm whose email account is compromised.

The attacker reads conversations with clients, understands how invoices are normally issued and then sends altered payment instructions from the genuine account.

The result could involve financial loss, confidential-data exposure and damage to client trust at the same time.

Another business may lose access to files after ransomware encrypts its systems.

Even if no ransom is paid, the company may face operational downtime, restoration costs and lost sales.

Security is therefore closely connected to business continuity.

Cyber security and data protection overlap

If a business holds personal information about customers, employees or suppliers, protecting that information is also part of its data-protection responsibilities.

The UK GDPR requires appropriate technical and organisational measures rather than prescribing one identical security system for every company.

The appropriate level depends on the information being processed and the risks involved.

A business storing health information, for example, may require stronger controls than one holding only basic public business-contact details.

Good GDPR security therefore starts with understanding the data rather than purchasing a product labelled “GDPR compliant”.

Essential Cyber Security Skills, Measures, and Requirements

Small-business cyber security checklist does not always require advanced technical expertise.

Many of the most important improvements are basic operational disciplines.

Understand what needs protecting

Make an inventory of important systems and information.

This might include:

  • business email;
  • accounting and banking systems;
  • CRM data;
  • employee records;
  • customer databases;
  • website and domain accounts;
  • cloud storage;
  • laptops and mobile phones.

A company cannot protect assets it does not know exist.

Understand who has access

Access should follow job requirements.

A marketing employee does not automatically need administrator access to accounting software. A former contractor should not retain access six months after the contract ends.

The principle is simple: give people what they need to work and remove access when they no longer need it.

Know how to recognise scams

Technical controls cannot prevent every fraudulent email, message or telephone call.

Employees should recognise suspicious payment requests, unexpected attachments, unusual login prompts and attempts to create urgency.

The NCSC specifically highlights phishing as a major route into business systems. Its 2026 small-organisation guidance advises businesses to ensure staff can identify suspicious activity and know where to report it.

Know when specialist help is required

A founder can enable MFA and automatic updates without being a cyber-security engineer.

Investigating malware across a network or responding to a significant data breach may require professional support.

Good security includes recognising that boundary.

Complete Cyber Security Checklist for Small Businesses in the UK

The following checklist covers a practical baseline for UK small organisations.

1. Secure the business email account

Email should normally receive the highest priority because compromise can help attackers reach many other systems.

Check that:

  • every employee uses their own account;
  • passwords are unique where passwords remain in use;
  • two-step verification is enabled;
  • passkeys are used where suitable and supported;
  • old employee accounts are disabled promptly;
  • mailbox forwarding rules are reviewed after suspicious activity.

The NCSC now recommends passkeys for important accounts where available. Where passwords remain, it recommends strong unique passwords supported by two-step verification.

A compromised email inbox can also allow an attacker to reset passwords for other services. That is why email should not share a password with any other system.

2. Turn on multi-factor authentication

Enable two-step or multi-factor authentication for important cloud services.

Priority accounts include:

email, banking, accounting, payroll, cloud storage, CRM, social media, website administration and domain management.

The latest UK survey found that only 47% of businesses reported using two-factor authentication, although adoption among microbusinesses increased to 43%.

MFA does not eliminate account takeover, but it creates another barrier when a password has been stolen.

3. Use a password manager or passkeys

Employees should not need to remember dozens of complex passwords.

A reputable password manager can generate and store unique credentials.

Passkeys can provide an even stronger option where supported because they are designed to resist common phishing attacks.

Avoid predictable password patterns such as changing one digit for each website.

4. Keep devices and software updated

Turn on automatic updates wherever practical.

This applies to:

operating systems, browsers, office software, accounting tools, mobile phones, routers, firewalls and other internet-connected devices.

Updates frequently contain security fixes for known vulnerabilities.

Unsupported software creates a different problem because security updates may no longer be available.

Businesses should plan to replace systems that have reached the end of security support rather than leaving them indefinitely connected to critical information.

5. Remove unnecessary applications and accounts

Every additional program, plugin and user account increases the number of things that need to be secured.

Remove software nobody uses.

Delete or disable unused accounts.

Review administrator access separately.

Employees should generally use standard accounts for everyday work rather than having unrestricted administrator privileges by default.

6. Protect laptops, phones and tablets

Require screen locks on every business device.

Use suitable device encryption where available.

Configure devices so that they lock automatically when left unattended.

Personal devices used for business should not escape the organisation’s security expectations simply because the company does not own them.

The NCSC specifically advises businesses to secure phones, laptops, tablets and shared workplace devices because they often contain or provide access to important business information.

7. Create reliable backups

Back up information the business could not operate without.

This might include accounting records, customer information, operational documents, website data and important communications.

Backups should be automatic where possible.

They should also be protected from the systems they are intended to recover.

If an external backup drive remains permanently connected to an infected computer, ransomware may be able to encrypt the backup too.

The NCSC advises organisations to keep recoverable copies and recommends considering both online and separate storage. Businesses should also test restoration rather than simply assuming backups work.

This is one of the most important forms of ransomware protection.

8. Test whether backups can actually be restored

A backup that cannot be restored is not a useful backup.

Periodically recover a small selection of files or test the restoration process in a controlled environment.

Document who knows how to recover systems.

Do not leave that knowledge with only one employee.

9. Configure routers and firewalls securely

Change default administrative credentials.

Install firmware updates.

Disable unnecessary remote-management features.

Use firewalls to restrict unwanted traffic between business devices and external networks.

Firewalls remain one of the five core cyber security checklist Essentials controls.

10. Protect against malware

Use built-in or commercial anti-malware controls appropriate to the organisation’s devices.

Keep them updated.

Restrict unapproved software installation where practical.

Employees should also know not to disable security tools simply because a download or website asks them to.

Malware protection is another cyber security checklist Essentials control, but software alone should never be treated as the entire security programme.

11. Train staff to recognise phishing

Employees should understand common warning signs:

unexpected login links, unusual payment instructions, attachment requests, fake invoice messages and attempts to create panic or urgency.

Encourage staff to verify unusual requests through another trusted channel.

If a director emails asking for an urgent bank transfer, for example, telephone them using a known number rather than replying to the suspicious email.

Training should make reporting easy.

Employees should not fear punishment for raising a concern that turns out to be harmless.

12. Protect financial transactions

Payment fraud deserves separate attention.

Create procedures for changing supplier bank details.

Do not accept a bank-detail change solely because it arrived from an apparently genuine email address.

Require independent verification for significant payments or unusual instructions.

For larger transfers, consider dual authorisation.

These are operational controls rather than complicated cyber security checklist technologies, but they can prevent serious losses.

13. Control cloud-service permissions

Many SMEs rely heavily on Microsoft 365, Google Workspace and other cloud platforms.

Cloud does not mean automatically secure.

Review who can access shared folders, whether public sharing links are necessary and which third-party applications have permission to connect.

cyber security checklist Essentials version 3.3 also makes clear that relevant cloud services cannot simply be excluded from certification scope because another company hosts them.

14. Protect the website and domain

The domain account is critical because control of the domain can affect the website and email.

Enable MFA for domain registrars and hosting providers.

Keep content-management systems, plugins and themes updated.

Remove unused plugins.

Limit administrator accounts.

Ensure important website data can be restored.

15. Create a joiner, mover and leaver process

Every employee lifecycle change should trigger an access review.

When someone joins, grant only required access.

When their role changes, remove permissions they no longer need.

When they leave, disable accounts promptly and recover company devices.

The NCSC specifically warns that accounts belonging to former staff, suppliers or contractors can remain active unnoticed and become easier targets.

16. Maintain a simple asset register

Record important devices, software, cloud services and owners.

The register does not need to be elaborate.

For a ten-person business, a controlled spreadsheet may be enough.

The purpose is to know what the business depends on and who is responsible for it.

17. Review supplier cyber risk

Small businesses increasingly depend on external accountants, payroll platforms, IT providers, software companies and cloud services.

Ask what information suppliers can access and how access will be removed when the relationship ends.

The latest government survey found that only 15% of businesses formally reviewed cyber security checklist risks associated with immediate suppliers.

Supply-chain security deserves more attention because an attacker may reach a business through a trusted third party.

18. Write an incident-response plan

Decide in advance what happens if:

an email account is compromised, a device is stolen, ransomware appears, money is transferred fraudulently or customer information is exposed.

The plan should identify who leads the response, which IT provider to contact, how essential services will continue and who decides whether regulators, insurers, customers or law enforcement need to be notified.

The NCSC recommends preparing for incidents in advance and identifying both critical information and critical business processes.

19. Keep a data-breach procedure

cyber security checklist incident and a personal-data breach are related but not identical.

If personal information is lost, destroyed, altered, disclosed or accessed unlawfully, assess the risk to affected people.

Keep a record of the breach and the response.

Where the statutory threshold for reporting is met, notify the ICO without undue delay and, where feasible, within 72 hours after becoming aware of it. High-risk breaches can also require communication with affected individuals.

20. Consider Cyber Essentials

cyber security checklist Essentials provides a structured benchmark against five technical-control areas.

The current requirements are:

firewalls, secure configuration, security update management, user access control and malware protection.

The certification process uses verified self-assessment, while cyber security checklistr Essentials Plus adds independent technical testing.

Basic certification currently starts from £320 plus VAT depending on organisation size.

Certification is not mandatory for every UK small business. However, some customers and supply chains require it, and it can provide a useful framework for improving basic controls.

Cyber Security Requirements, Policies, Costs, and Professional Development

There is no universal UK law requiring every business to spend a particular amount on cyber security checklist security.

The correct budget depends on systems, information, employees, regulatory obligations and potential business impact.

A microbusiness using cloud software may obtain much of its basic protection through existing subscription features such as MFA, device encryption, automatic updates and cloud backup.

A company handling highly sensitive information may require significantly more.

Cyber Essentials certification currently begins from £320 plus VAT. cyber security checklistr Essentials Plus costs depend on the organisation’s size and technical complexity.

Other possible costs include managed IT support, endpoint protection, backup systems, password management, employee training, penetration testing and cyber security checklist insurance.

The important point is to spend according to risk.

Useful policies for small businesses

Policies do not need to run to 100 pages.

A small organisation may benefit from concise policies covering:

  • acceptable technology use;
  • passwords and authentication;
  • access control;
  • remote working;
  • software updates;
  • backup and recovery;
  • personal devices;
  • incident reporting;
  • data breaches;
  • supplier access.

A policy should describe what actually happens.

Copying an enterprise template from the internet does not improve business cyber safety if employees never read it and the controls described do not exist.

Cyber Security Responsibilities, Procedures, and Best Practices

cyber security checklist requires clear ownership.

Someone in senior management should understand the major risks and make sure responsibilities are assigned.

The latest UK survey found that cyber security checklist security was considered a high priority by 72% of businesses, but only 31% reported board-level responsibility for it.

In a small company, responsibility may sit with the owner or operations director rather than a dedicated security officer.

That person does not need to perform every technical task.

They do need to ensure tasks are being performed.

Review access regularly

Set a periodic reminder to review administrator accounts, cloud-service users and external supplier access.

This can reveal forgotten accounts before attackers find them.

Practise incident response

A short scenario exercise can be valuable.

Ask the team:

“What would we do if tomorrow morning nobody could access our files?”

Then work through who would be contacted, how backups would be restored and how customers would be informed if operations were disrupted.

Weaknesses are much easier to fix during an exercise than during a real ransomware attack.

Train repeatedly

One annual presentation is unlikely to change behaviour permanently.

Short reminders and realistic examples throughout the year can be more useful.

Training should particularly cover phishing, password practices, payment fraud, secure sharing and reporting suspicious activity.

Business Risks and Opportunities From Effective Cyber Security

Good security is primarily about risk reduction, but it can also support commercial opportunities.

Some larger organisations require suppliers to holdcyber security checklist Essentials certification before bidding for particular work. The NCSC specifically identifies supply-chain requirements as one reason organisations obtain certification.

Security can also strengthen customer confidence.

A business that can explain how it protects information, controls access and prepares for incidents may be easier for a corporate customer to approve during supplier due diligence.

That does not mean certification guarantees contracts.

Nor does having cyber security checklist Essentials mean a business cannot experience an incident.

It shows that defined controls have been assessed against a recognised baseline.

Strong SME security can also reduce operational risk.

Reliable backups, controlled access and documented incident procedures help a business recover more effectively when something does go wrong.

How to Build a Successful Cyber Security Strategy for a UK Small Business

Start with the systems the business cannot afford to lose.

Identify the email environment, finance systems, customer information, important documents and operational software.

Then identify the most credible threats.

For many SMEs, phishing and account compromise deserve immediate attention.

Turn on MFA. Secure email. Remove old accounts. Apply software updates.

Next, establish backups.

Do not postpone this until the company becomes larger.

After the technical basics, work on employee behaviour and incident response.

Give employees a clear method for reporting suspicious messages and establish who coordinates an incident.

Then assess the organisation against Cyber Essentials.

Even if certification is not currently required, its five-control framework provides a useful baseline.

Finally, review rather than finish.

cyber security checklist is not a one-time installation project.

New employees join. New cloud services appear. Software reaches end of life. Suppliers change.

A quarterly security review is far more useful than creating one elaborate plan that nobody revisits.

Future Trends in Cyber Security, AI, Data Protection, and Business Technology

AI is changing cyber security checklist on both sides.

Businesses can use AI-assisted systems to identify unusual activity, classify suspicious messages and analyse security information.

Attackers can also use AI to produce convincing phishing messages and impersonation attempts at greater scale.

This makes identity verification increasingly important.

Employees should not trust instructions merely because the wording looks polished or appears to come from a senior colleague.

Passkeys will become more common

The NCSC’s 2026 guidance increasingly encourages passkeys for email and important online accounts where services support them.

Passkeys can reduce dependence on passwords and provide stronger resistance against common phishing attacks.

Businesses should expect passwordless authentication to become increasingly normal.

Cloud security will receive more attention

Small companies continue moving important information into cloud platforms.

That changes the security model rather than removing the security problem.

Businesses still need to configure access, MFA, sharing and administrator privileges correctly.

Cyber insurance will not replace controls

Insurance may help manage some financial consequences of an incident.

It should not become an alternative to preventive security.

Insurers can also expect organisations to maintain specified controls such as MFA, backups or endpoint security before cover applies.

Supply-chain scrutiny will grow

Customers increasingly want assurance that suppliers are not weak links in their information systems.

cyber security checklistr Essentials and other recognised controls may therefore become commercially relevant for more SMEs.

Security and AI governance will overlap

The government’s 2025/26 breaches survey found that among businesses and charities using, adopting or considering AI, only a minority reported cyber-security practices specifically addressing AI risk.

As employees use generative AI services, organisations will need rules about confidential information, customer data, approved systems and access permissions.

“Do not upload secrets to random AI tools” may become as basic a security rule as “do not reuse passwords”.

Key Takeaways

A useful cyber security checklist starts with the basics: secure email, use MFA or passkeys, maintain unique credentials, update software, control access and keep recoverable backups.

Phishing remains the most common identified cyber threat to UK businesses, so employee awareness is a core part of business cyber safety.

For effective ransomware protection, backups should be kept in a form that an attacker cannot easily destroy alongside the live systems, and restoration should be tested.

GDPR security does not come from purchasing one product or completing one checklist. UK businesses must implement technical and organisational measures appropriate to the personal information and risks involved.

Cyber Essentials provides a useful government-backed SME security baseline covering five technical-control areas, although certification does not guarantee immunity from attacks.

FAQ

What is cyber security?

Cyber security is the protection of digital devices, accounts, systems, networks and information against unauthorised access, theft, disruption or damage. For small businesses, it includes technical controls, employee practices, backups and incident preparation.

Why is cyber security important for small businesses in the UK?

Small businesses hold commercially valuable information and often depend heavily on digital systems. The latest government survey found that 46% of small businesses identified a cyber breach or attack during the previous 12 months. A successful incident can interrupt operations, expose customer information or create financial loss.

What should be included in a small business cyber security checklist?

A practical checklist should cover secure email, MFA or passkeys, unique passwords, updates, malware protection, backups, device security, access control, phishing training, supplier risk, payment procedures and an incident-response plan. Businesses handling personal information should also maintain an appropriate personal-data breach procedure.

What are the biggest cyber security risks for small businesses?

Phishing and account compromise are particularly significant. Other risks include impersonation fraud, malware, ransomware, weak passwords, unpatched software, insecure cloud configurations, lost devices and excessive account permissions.

How much does cyber security cost for a small business?

There is no universal budget. Some important protections, including MFA and automatic security updates, may already be included within existing software. Other costs can include backups, IT support, security software, training and certification. Cyber Essentials currently starts from £320 plus VAT, with the price dependent on organisation size.

What cyber security policies should a UK business have?

Useful policies can cover account access, passwords and authentication, remote working, personal devices, updates, backups, acceptable use, supplier access, incident response and personal-data breaches. Policies should reflect what the organisation actually does rather than being generic documents copied from another business.

What skills are needed to manage business cyber security?

Small organisations need risk awareness, account and device-management skills, basic understanding of backups and updates, phishing awareness and the ability to respond to incidents. More complex networks or serious incidents may require qualified IT or cyber-security specialists.

How can a small business protect itself from cyber attacks?

Secure the email system first, turn on MFA or passkeys, keep software updated, restrict administrator privileges, maintain recoverable backups and train employees to recognise suspicious activity. Use the NCSC’s free small-business guidance and consider Cyber Essentials as a structured security baseline.

Conclusion

A strong cyber security checklist for a UK small business does not need to begin with expensive technology.

Start with the accounts criminals are most likely to target. Protect business email, banking, cloud storage and other critical services using passkeys or strong unique credentials and multi-factor authentication. Keep devices and software updated and remove access when employees or contractors leave.

Next, build resilience.

Reliable backups provide essential ransomware protection, but only if the business knows how to restore them. An incident-response plan should also explain who takes charge, which systems are critical and how potential personal-data breaches will be assessed.

For GDPR security, remember that data protection is risk-based. The obligation is to protect personal information using appropriate technical and organisational measures, not simply to install antivirus software or display a compliance badge.

Skills Pack’s current Workplace Confidentiality course includes a cybersecurity module alongside data confidentiality and employee-record handling. It can provide supplementary awareness and awards a completion certificate. It is not a substitute for implementing real controls, obtaining Cyber Essentials where appropriate or using specialist cyber-security expertise when the organisation’s risks require it.

Effective SME security is ultimately built through routine habits: secure accounts, restricted access, current software, tested backups, trained employees and clear incident procedures.

Those measures may appear less exciting than sophisticated security technology, but for business cyber safety, consistently applying the fundamentals remains one of the strongest places a small organisation can start.

Cyber Security Checklist for Small Businesses in the UK