1. Multi-factor authentication on everything
If you do one thing this week, do this. Turn on MFA for email, your accounting software, your banking, your CRM, your website admin and your domain registrar. An authenticator app or hardware key is stronger than SMS codes, which can be intercepted through SIM-swap fraud. Stolen passwords are worthless to an attacker if a second factor is required.
2. A password manager instead of reused passwords
Reused passwords are how one breach at an unrelated website becomes a breach of your business email. Give every member of staff a password manager, generate unique passwords per service, and stop rotating passwords on a schedule — the National Cyber Security Centre advises long unique passwords over frequent forced changes.
3. Backups you have actually tested
Ransomware is survivable if your backups are good. Follow the 3-2-1 rule: three copies of your data, on two different types of media, with one copy offline or immutable so attackers cannot encrypt it. Then restore something once a quarter. An untested backup is a hope, not a control. Remember that Microsoft 365 and Google Workspace do not back up your mailboxes for you in the way most owners assume.
4. Patch and update automatically
Enable automatic updates for operating systems, browsers, phones, and any website platform or plugins you run. Replace hardware and software that no longer receives security updates. The majority of successful automated attacks exploit vulnerabilities that were patched months earlier.
5. Control who has access to what
Nobody should use an administrator account for day-to-day work. Give people the minimum access their role needs, review it when someone changes role, and remove it the day they leave — including shared logins, VPN access and anything on a personal phone. Keep a short list of who holds the keys to your domain, hosting and bank.
6. Train staff on phishing and invoice fraud
The most expensive incidents at small firms are usually not technical. They are a convincing email asking finance to change a supplier's bank details, or a "supplier" emailing a fake invoice. Put a rule in place: any change to payment details is verified by phoning a known number, never a number in the email. Run a short phishing awareness session twice a year and make it safe to report mistakes quickly.
7. Protect your email domain
SPF, DKIM and DMARC records stop criminals sending email that appears to come from your domain. They also improve deliverability of your genuine email. Your IT provider can set these up in an afternoon; ask them to move DMARC to an enforcing policy once monitoring looks clean.
8. Know what you will do when something happens
Write a one-page incident plan: who to call, where the backups are, how to isolate a machine, which customers and insurers need telling, and the fact that a personal data breach may need reporting to the ICO within 72 hours. Keep a printed copy — if your systems are encrypted, a plan stored only on the server is no plan at all.
Get certified: Cyber Essentials
Cyber Essentials is the UK government-backed scheme covering five basic technical controls. It is inexpensive for a small business, takes a few weeks, and is increasingly required to win public sector and larger corporate contracts. Cyber Essentials Plus adds an independent technical audit. Many insurers also look for it when quoting cyber cover.
A realistic quarterly checklist
- MFA still enabled on every critical account, including new tools
- Test-restore one file and one mailbox from backup
- Review user accounts and remove leavers
- Confirm devices are patched and encrypted
- Check DMARC reports
- Remind the team about payment-detail verification
Next step
If you do not have in-house IT, an outsourced provider can implement all of the above and take you through Cyber Essentials. Browse vetted UK providers in the cyber security category, or read how to compare supplier quotes before you appoint one.
