Cyber Security Checklist for UK Small Businesses
Small businesses do not need enterprise-sized IT departments to take cyber security seriously.
They do need secure email accounts, protected devices, reliable backups, sensible access controls and employees who know what to do when a suspicious message arrives.
That matters because cyber attacks are not restricted to large companies. The latest UK government survey found that 43% of businesses identified at least one cyber breach or attack during the previous year, with phishing remaining the most common threat.
A practical cyber security checklist for UK small businesses therefore needs to cover people and processes as well as technology.
Strong SME cyber security includes account protection, software updates, backups, employee awareness, supplier controls and incident planning. Businesses processing personal information also need to consider GDPR security requirements, while reliable backups and controlled access are particularly important for ransomware protection.
The objective is not to make attacks impossible. No security programme can promise that.
It is to make attacks harder to succeed, limit the damage if they do and help the organisation recover quickly enough to maintain business safety and customer trust.
What Is Cyber Security and Why Is It Important for Small Businesses?
cyber security checklist for UK small businesses is the combination of technology, policies and human behaviour used to protect devices, accounts, networks, information and digital services.
For a small business, those assets might include:
- business email;
- online banking;
- payroll;
- customer databases;
- cloud storage;
- accounting software;
- websites and domains;
- social-media accounts;
- laptops and smartphones.
A cyber attack does not have to involve sophisticated hacking.
A criminal might simply persuade an employee to enter their Microsoft 365 password into a fake login page.
That one mistake could expose email conversations.
The attacker might then reset other passwords, impersonate the company, redirect supplier payments or access customer information.
cyber security checklist for UK small businesses therefore begins with understanding what the company depends on.
If losing access to one account could stop the business operating, that account deserves strong protection.
Why Cyber Security Matters for UK Small Businesses
Small businesses sometimes assume that criminals prefer multinational organisations because larger companies hold more money and data.
Scale is not the only factor.
Attackers also look for accessible opportunities.
A small company may have fewer security specialists, weaker account controls and one employee responsible for several sensitive systems.
The latest Cyber Security Breaches Survey found that phishing affected 38% of all businesses surveyed, impersonation attacks affected 12%, and malware affected 7%.
Cyber incidents can create several kinds of damage at once.
A compromised email account may allow fraudulent payment requests.
Ransomware may stop access to operational data.
A stolen laptop could expose personal information.
A hacked social account could be used to scam customers.
Businesses can also face lost working time, restoration costs and reputational damage long after the original attack.
Cyber protection should therefore be treated as normal operational risk management rather than an occasional IT project.
Essential Cyber Security Skills, Measures, and Requirements
Good security starts with a small number of principles.
Protect identity first
Most modern business systems are reached through online accounts.
That makes identity security fundamental.
The NCSC now recommends passkeys where supported because they are resistant to common phishing attacks. Where they are not available, businesses should use strong unique passwords plus two-step verification.
Restrict access
Employees should have access to what they need for their work rather than every system the company operates.
Someone managing social media probably does not require payroll-administrator privileges.
Similarly, former employees and contractors should not retain active accounts after access is no longer required.
Keep technology updated
Security updates fix vulnerabilities that attackers may exploit.
Businesses should use supported operating systems and applications and enable automatic updates where practical.
Assume people will occasionally make mistakes
Training matters, but security cannot depend on every employee identifying every malicious email.
Build controls so that one mistake does not automatically compromise the whole organisation.
MFA, restricted permissions, backups and payment-verification procedures all help.
Prepare for recoveryransomware protection
Businesses often concentrate entirely on prevention.
Recovery matters too.
If a device is stolen, an account is compromised or ransomware blocks files, the organisation needs a plan for restoring operations.
Complete Cyber Security Checklist for UK Small Businesses
The following checklist provides a practical baseline for most small organisations. Specific industries or high-risk processing may require stronger controls.
1. Identify Your Critical Systems and Data
Start by listing the technology the business could not operate without.
This may include:
email;
banking;
accounting;
CRM;
payroll;
website;
cloud storage;
customer records.
For each one, identify who owns it and who has access.
You cannot protect assets you have forgotten exist.
2. Secure Business Email First
Email deserves priority.
The NCSC warns that compromising a business inbox can expose private information, allow criminals to impersonate the organisation and provide routes into other accounts through password resets.
Use passkeys where supported.
Otherwise require strong, unique passwords and 2-step verification.
Avoid shared inbox passwords where named user access can be provided instead.
3. Protect Every Important Account With Strong Authentication
Move beyond email.
Review:
online banking;
payroll;
accounting;
cloud storage;
website administration;
domain registrar;
social media;
CRM;
payment platforms.
Enable passkeys where available or MFA/2SV.
A password alone should not be the only protection for a system capable of moving money or exposing sensitive information.
4. Use a Password Manager
Password reuse creates unnecessary risk.
If the same password protects email, social media and a cloud-storage service, one stolen credential may compromise all three.
The NCSC recommends password managers or built-in password-management tools to create and store unique credentials.
Employees should not maintain company passwords in unencrypted spreadsheets or shared documents.
5. Remove Unused Accounts
Every inactive account creates another potential route into the business.
When an employee or contractor leaves:
disable email;
remove cloud access;
remove social-media permissions;
revoke VPN access;
recover company devices;
transfer ownership of important files;
review shared credentials.
The NCSC recommends reviewing account access every few months, not only when somebody leaves.
6. Separate Administrator and Everyday Accounts
Administrator privileges allow users to install software and make significant changes.
That makes administrator accounts especially valuable to attackers.
The NCSC recommends using standard accounts for day-to-day work and reserving administrator access for tasks that genuinely require it.
Not every employee needs local administrator rights on their laptop.
7. Keep Operating Systems and Applications Updated
Updates should cover:
Windows or macOS;
mobile operating systems;
browsers;
Microsoft 365 or other productivity apps;
accounting software;
plugins;
website platforms;
routers and other supported network equipment.
Enable automatic security updates where possible.
Unsupported software should be replaced because security fixes may no longer be available.
8. Check Built-In Antivirus and Firewalls
Modern Windows and Apple systems already contain significant built-in security functionality.
The NCSC advises checking that antivirus and firewall protections are enabled rather than assuming they are active.
Businesses with more complex environments may require managed endpoint-security products, but installing several overlapping antivirus applications is not necessarily better.
9. Back Up Business-Critical Data
Backups are fundamental to ransomware protection.
The NCSC recommends backing up the information required to operate, which might include:
customer records;
invoices;
emails;
documents;
contacts;
website data.
It also suggests considering both online and separate storage-based backups where appropriate. External backup devices should not remain permanently connected because malware may reach connected storage.
Most importantly, test restoration.
A backup that cannot be restored is not a reliable backup.
10. Protect the Backups Themselves
Sophisticated ransomware attackers may deliberately target backups before encrypting operational systems.
The NCSC’s ransomware guidance notes that attackers may try to delete or destroy backups to increase pressure on victims to pay.
For important systems, consider protected or independent backup arrangements that cannot simply be deleted using an ordinary compromised account.
Secure cloud backup accounts with MFA as well.
11. Train Employees to Recognise Phishing

Technology cannot filter every malicious message.
Employees should recognise warning signs such as:
unexpected login links;
requests for passwords or verification codes;
urgent payment instructions;
new supplier bank details;
unusual attachments;
messages asking for secrecy.
The latest government survey found phishing in 38% of business safety overall and in 93% of businesses that experienced a cyber crime.
Training should therefore be practical and repeated rather than a one-time induction slide.
12. Verify Financial Changes Through a Separate Channel
Business email compromise can turn a cyber incident directly into financial fraud.
If a supplier emails saying its bank account has changed, verify the instruction through contact information already held by the business.
Do not simply telephone the number included in the suspicious message.
Apply similar controls to:
salary-account changes;
large payments;
unusual executive requests.
Where appropriate, significant payments should require approval from a second person.
13. Secure Your Business Domain and Website
The company domain can control both website and email identity.
Protect the registrar account with strong authentication.
Know which employee or provider controls:
the domain;
DNS;
website hosting;
SSL certificates;
administrative access.
Make sure the business—not a former developer’s private account—ultimately controls these assets.
Website platforms and plugins should also remain patched.
14. Protect Remote and Hybrid Working
Remote work changes where company information is accessed.
business safety should consider:
device encryption;
screen locking;
secure home routers;
approved cloud services;
remote-access security;
lost-device procedures.
Employees should avoid conducting sensitive work through untrusted shared devices.
If personal devices are permitted for work, define minimum security requirements rather than leaving arrangements informal.
15. Encrypt Portable Devices
Laptops and smartphones can be lost or stolen.
Device encryption reduces the risk that someone can read locally stored information simply by obtaining the hardware.
Modern operating systems frequently include built-in encryption capabilities.
business safety should check whether encryption is actually enabled, particularly on devices containing personal or commercially sensitive information.
16. Limit the Data You Keep
One effective way to reduce cyber impact is not to retain information the company no longer needs.
GDPR security is connected to broader data-protection principles such as data minimisation and storage limitation.
Do not retain unnecessary copies of customer databases, identity documents or former employee information indefinitely.
Less unnecessary sensitive information means less information available to be exposed.
17. Review Third-Party Suppliers
A company’s cyber risk extends into its supply chain.
Cloud software providers, accountants, IT contractors, payment processors and marketing systems may all process or access company information.
Before giving a supplier sensitive access, consider:
what it can access;
whether MFA is available;
how access is removed;
security commitments;
backup arrangements;
incident notification;
data-processing terms.
Small business safety remain responsible for their own data-protection decisions even when another company provides the technology.
18. Create a Cyber Incident Response Plan
Do not wait until an attack happens to decide who should respond.
The NCSC recommends having a cyber-attack plan defining who does what and when.
A simple plan should identify:
who coordinates the response;
who contacts the IT provider;
how compromised accounts are disabled;
who contacts the bank;
where backups are located;
who communicates with customers;
who assesses data-protection reporting;
how senior management is informed.
Keep essential contact details somewhere accessible even when normal systems are unavailable.
19. Know How to Report Incidents
If money has been stolen or fraud is ongoing, contact the relevant bank or payment provider immediately.
The national reporting system changed in December 2025.
Report Fraud replaced Action Fraud as the national service for cyber crime and fraud in England, Wales and Northern Ireland.
Scotland uses different police reporting arrangements, including Police Scotland.
A cyber incident involving personal information may also require assessment under UK data-protection rules.
20. Assess Whether the ICO Must Be Notified
Not every security incident is a reportable personal-data breach.
But every relevant personal-data breach should be assessed.
Where the legal reporting threshold is met, the organisation must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Higher-risk breaches can also require communication with affected individuals.
Document decisions even where notification is not required.
21. Consider Cyber Essentials
Cyber Essentials offers a recognised security baseline based on five controls:
firewalls;
secure configuration;
security updates;
user access control;
malware protection.
It can be useful for SMEs wanting a structured security benchmark.
Certification may also be required by particular customers or government contracts.
It should not, however, be treated as a guarantee against every attack or automatic proof of UK GDPR compliance.
22. Review Security Regularly
Security deteriorates when nobody checks it.
People leave.
New apps are installed.
Permissions accumulate.
Old devices remain active.
Schedule regular reviews of:
users;
administrators;
devices;
software;
backups;
suppliers;
incidents;
policies.
A quarterly basic review is far better than waiting several years between major security exercises.
Cyber Security Requirements, Policies, Costs, and Compliance Considerations
There is no single law saying every small UK company must buy a specific antivirus package or hold Cyber Essentials certification.
Responsibilities depend on what the organisation does and the information it processes.
UK GDPR security
Where personal data is processed, UK GDPR requires appropriate technical and organisational security measures.
The ICO explains that security should be based on risk.
That can involve:
risk analysis;
technical controls;
physical security;
staff procedures;
policies;
supplier management.
cyber security checklist for UK small businesses and data protection overlap, but they are not identical.
A company can have excellent antivirus and still misuse customer information.
Likewise, a strong privacy policy does not compensate for an unprotected administrator account.
Cyber Essentials costs
Current basic certification prices are:
| Organisation size | Employees | Cyber Essentials assessment |
| Micro | 0–9 | £320 + VAT |
| Small | 10–49 | £440 + VAT |
| Medium | 50–249 | £500 + VAT |
| Large | 250+ | £600 + VAT |
Cyber Essentials Plus requires the basic certification first and adds a technical audit, so pricing varies according to the environment.
Certification is only one potential cyber-security cost.
Businesses may also spend on:
managed IT;
backup services;
password management;
endpoint security;
security training;
cyber insurance;
specialist consultancy.
Many important improvements, however, cost little or nothing.
Enabling MFA, removing a former employee’s account and turning on automatic updates are examples.
Cyber Security Tasks, Responsibilities, and Best Practices

One of the weakest security models is:
“IT handles cyber security.”
IT has an important role, but employees, managers and business safety owners also make security decisions.
Owners and directors
Leadership should decide the organisation’s risk appetite, fund appropriate controls and make sure responsibility has been assigned.
IT providers
Internal or outsourced IT teams may manage:
devices;
accounts;
updates;
backups;
networks;
technical monitoring.
Their responsibilities should be documented rather than assumed.
Managers
Managers should control staff access and make sure employees leaving or changing roles do not retain unnecessary permissions.
Employees
Every employee should know how to:
recognise suspicious messages;
protect accounts;
handle confidential information;
report mistakes quickly.
Finance staff
Employees handling payments should follow verification procedures regardless of how senior or urgent the request appears.
The objective is shared responsibility without confusion about ownership.
Common Cyber Security Risks Facing Small Businesses
Several threats deserve particular attention.
Phishing
This remains the dominant threat in current UK statistics.
Criminals use fake emails, messages and login pages to steal credentials or money.
AI is making polished phishing messages easier to produce, so poor spelling is no longer a reliable warning sign.
Business email compromise
Attackers may access a real business safety inbox and monitor communications before changing invoice information or impersonating management.
Strong email authentication and financial verification controls are both important.
Ransomware
Ransomware can encrypt or destroy information and disrupt operations.
Although only 1% of all businesses in the latest survey reported ransomware attacks, the potential consequence can be severe.
Strong ransomware protection combines patching, restricted privileges, malware controls, account security and recoverable backups.
Credential theft
Passwords can be captured through phishing, malware or breaches at unrelated services.
Unique credentials, passkeys and MFA reduce the consequences.
Malware
Malicious software can steal data, provide remote access or disrupt a device.
Software updates, built-in protection and restricted installation permissions help reduce exposure.
Insider and accidental mistakes
Not every security breach is caused by an external criminal.
Employees can accidentally send information to the wrong recipient, share files too broadly or lose devices.
Policies and access restrictions should account for ordinary human error.
Supply-chain compromise
A trusted provider with access to the company’s systems can itself be compromised.
Businesses should therefore evaluate important suppliers rather than assuming outsourced systems eliminate risk.
How to Build a Strong Cyber Security Strategy for a UK Small Business
Do not begin by buying security products randomly.
Build the programme around risk.
Step 1: Identify what matters most
List critical systems, information and business safety processes.
Ask what would happen if each became unavailable for a day or a week.
Step 2: Prioritise email and identity
Secure email first.
Then banking, finance, payroll, cloud storage, domains and administrator accounts.
Step 3: Establish a minimum device standard
Require supported software, automatic security updates, screen locks, encryption where appropriate, antivirus and firewalls.
Step 4: Restrict privileges
Give employees only the access required for their work.
Review access regularly.
Step 5: Establish reliable backups
Back up important information automatically where practical.
Keep important backup copies protected from compromise.
Test restoration.
Step 6: Train people
Explain the actual attacks employees are likely to see.
Include phishing, payment diversion, suspicious login requests and handling of confidential information.
Step 7: Write basic policies
A small organisation does not need hundreds of pages.
It does need clear rules for:
acceptable IT use;
passwords and authentication;
remote working;
personal devices where permitted;
access control;
data handling;
incident reporting;
backup responsibilities.
Step 8: Test an incident
Run a tabletop exercise.
For example:
The managing director’s Microsoft 365 account has been compromised and fraudulent payment requests have been sent to customers. What happens during the next hour?
If nobody knows, the test has identified a weakness without the business safety having to suffer a real attack.
Step 9: Consider an external benchmark
Cyber Essentials provides a useful structured baseline.
Some organisations may require more extensive assessment because of their sector, customer requirements or data sensitivity.
Step 10: Review after every meaningful change
New office?
New cloud supplier?
New remote-working system?
Acquisition?
Major recruitment?
Each change can alter cyber risk.
Security should evolve with the business.
Future Trends in Cyber Security, AI, Data Protection, and Business Technology
Security risks are changing alongside technology.
AI will make phishing more convincing
Employees can no longer rely on obvious grammar mistakes.
Generative AI can produce professional-looking messages that imitate normal business safety language.
Verification of unusual actions therefore becomes more important than judging writing quality.
AI will also strengthen defence
Security providers increasingly use AI for:
anomaly detection;
email filtering;
threat prioritisation;
behaviour monitoring;
incident analysis.
These capabilities can support small organisations through managed products without requiring an internal security operations centre.
Human review still matters.
Passkeys will become more common
The NCSC’s 2026 guidance now explicitly recommends passkeys for email and other critical business safety accounts where supported.
Businesses should expect passwordless or phishing-resistant authentication to become increasingly normal.
Cloud security will receive more attention
Small business safety increasingly depend on cloud platforms rather than local servers.
That shifts security rather than removing it.
Misconfigured sharing permissions, weak administrator accounts and compromised cloud identities can all expose information without malware ever touching an office computer.
Security and data governance will become more closely connected
AI tools and automation make it easier for employees to move information between systems.
Businesses need to know what personal and confidential data is being uploaded, shared or connected.
That makes GDPR security increasingly a governance issue as well as a technical one.
Recovery capability will become a competitive strength
Cyber resilience is not only about stopping every intrusion.
Customers and suppliers increasingly want reassurance that a company can continue operating if technology fails.
Backups, incident plans and tested recovery procedures therefore become part of wider business safety and resilience.
Key Takeaways
A practical cyber security checklist for UK small businesses should begin with email, accounts, devices, backups and employee awareness.
Use passkeys where available or strong unique passwords with two-step verification.
Remove accounts and permissions that are no longer needed.
Keep operating systems, applications and website software updated.
Maintain tested backups as part of ransomware protection.
Train employees to identify phishing and independently verify unusual payment instructions.
Build GDPR security around appropriate technical and organisational controls where personal information is processed.
Consider Cyber Essentials as a recognised SME cyber security baseline, but do not confuse certification with immunity from attacks or automatic data-protection compliance.
Prepare an incident-response plan before something goes wrong.
Strong cyber controls support wider business safety, resilience and customer confidence.
FAQ
What is cyber security?
cyber security checklist for UK small businesses is the protection of digital systems, accounts, devices, networks and information against unauthorised access, disruption, theft and other threats. It involves both technical controls and organisational behaviour.
Why is cyber security important for UK small businesses?
Small businesses rely heavily on digital systems but may have limited security resources. A compromised email account, ransomware infection or payment scam can cause financial loss, operational disruption and reputational damage. Current government figures show that 43% of businesses identified a breach or attack during the previous year.
What should be included in a small business cyber security checklist?
A useful checklist should cover secure email, passkeys or MFA, unique credentials, password management, access controls, software updates, antivirus/firewalls, device security, backups, staff training, supplier risk, incident response and data-breach procedures.
What are the biggest cyber security risks for small businesses?
Phishing is the most commonly identified attack among UK businesses. Other important risks include impersonation, business safety email compromise, credential theft, malware, ransomware, account takeover, supplier compromise and accidental disclosure by employees.
How can a small business protect itself from cyber attacks?
Start with the NCSC fundamentals: secure email, secure important accounts, protect devices, maintain backups and train staff to recognise attacks. Restrict permissions, update software, use strong authentication and maintain a tested incident-response plan.
What cyber security policies should a UK business have?
Useful policies can cover access control, authentication, acceptable use, remote working, personal devices, data handling, backups and incident reporting. The exact requirements should be proportionate to the organisation’s size, systems, sector and information risks.
How much does cyber security cost for a small business?
There is no universal figure. Many basic improvements—such as enabling MFA and automatic updates—can cost little or nothing. Current basic Cyber Essentials certification costs £320 + VAT for micro-organisations and £440 + VAT for organisations with 10–49 employees. Managed IT, backups, specialist products, insurance and consultancy can add further costs according to risk and complexity.
What are the basic cyber security requirements for UK businesses?
There is no single technical checklist legally required of every UK business safety. Organisations processing personal information must apply appropriate security under UK data-protection law. Good baseline controls include secure authentication, access management, supported and updated devices, malware protection, backups and incident planning. Cyber Essentials provides a recognised five-control framework that many small businesses can use as a starting point.

Conclusion
The most effective cyber security checklist for UK small businesses is not a shopping list of expensive security products.
It is a set of habits and controls that reduce predictable weaknesses.
Secure business email.
Protect important accounts with passkeys or two-step verification.
Remove unnecessary access.
Update software.
Back up important information and test whether it can actually be restored.
Train employees to recognise suspicious messages and payment requests.
Those basic controls provide a strong foundation for SME cyber security checklist for UK small businesses because many attacks still depend on compromised accounts, human deception or unpatched technology.
Backups deserve particular attention for ransomware protection. They should cover the data required to keep the business safety operating and be protected so an attacker cannot easily destroy the recovery copy alongside the live systems.
Data protection needs to be integrated into the same strategy. GDPR security requires appropriate technical and organisational measures based on risk rather than one universal piece of software or certificate.
Skills Pack’s current Workplace Confidentiality course includes a dedicated cybersecurity module alongside data protection, employee records and sensitive-information management. It may help employees develop broader awareness of digital confidentiality risks, but its completion certificate should not be confused with Cyber Essentials certification or specialist cybersecurity competence.
For organisations seeking a more formal baseline, Cyber Essentials provides a practical framework covering firewalls, secure configuration, updates, user access and malware protection.
Whatever framework is used,cyber security checklist for UK small businesses should remain a business responsibility.
Owners need to understand the risk.
Managers need to control access.
Employees need to report suspicious activity.
IT providers need clearly defined responsibilities.
And the company needs a plan for what happens when prevention is not enough.
That combination is what turns cyber security checklist for UK small business safety from an IT checklist into genuine business safety and resilience.