Cybersecurity can feel like a job for large companies with dedicated IT teams. For a small business owner, it is more likely to compete with payroll, customer work and the thousand other decisions that need attention today. That is exactly why the best starting point is not a complex security programme. It is a short list of practical controls that reduce the chance that one misleading email, stolen password or missed update becomes a business-stopping problem.
The risk is not theoretical. The UK government’s Cyber Security Breaches Survey 2025/2026, published in April 2026, found that 43% of UK businesses identified a cyber breach or attack during the previous 12 months. Small businesses, defined in the survey as firms with 10 to 49 employees, were more likely than micro businesses to report an incident, at 46%. Phishing remains a dominant problem, while impersonation attacks can be particularly damaging where staff approve invoices, change supplier records or release payments.
No control offers a guarantee. But five actions taken this week can make a disproportionate difference: make recoverable backups, turn on multi-factor authentication, update software, clean up account access and build payment checks that do not depend on trusting an email. Alongside them, write and test a simple response plan. The aim is resilience: stopping common attacks where possible and recovering quickly when something still goes wrong.
Start with the priorities, not the panic
Small businesses do not need to copy an enterprise security department. They need to protect the systems that keep money moving and customers served. For most firms, that means email, cloud storage, accounting software, payroll, banking, customer records, website administration, point-of-sale systems and the devices staff use to access them.
Put one owner in charge of this week’s work. That might be a director, operations manager, office manager or external IT provider. Their task is not to do every technical job personally; it is to make sure each action has an owner, a deadline and evidence that it was completed. A basic spreadsheet is enough.
Work through the following order. Fix the issues that could create the most immediate and expensive disruption first: recovery, account protection and payment controls. Then make patching and access reviews part of normal business operations.
Fix one: Make backups that you can actually restore
A backup is not simply a folder copied to a drive or a cloud service that says it synchronises files. It is a separate, usable copy of the information needed to run the business after files are deleted, encrypted by ransomware, overwritten or made unavailable.
Begin by listing your “must-have-by-Monday” information. This normally includes customer and supplier contacts, quotes and invoices, accounting records, payroll exports, key contracts, project files, booking data, stock records, website content, email contacts and any configuration details needed to operate essential systems. Do not overlook cloud-based data. A business can lose access to a cloud account, accidentally delete a shared folder or sync corrupted files across every device.
Use a simple backup standard
The National Cyber Security Centre recommends the widely used 3-2-1 approach: keep at least three copies of important data, on two different devices or media, with one copy held off-site. Its data security guidance also stresses that backups should include business and configuration data, not just documents.
For a typical small firm, that might mean the live cloud service, an automated backup service with version history, and an encrypted external drive or separate protected storage location. The exact technology matters less than separation. If a staff member’s account is compromised, an attacker should not be able to delete both the live files and every backup with the same login.
Test a restore this week
The critical word is “restore”. Ask someone who did not create the backup to retrieve three items: a recent invoice, an older customer document and a file from a shared folder. Check that the files open, that the correct version is available and that the person knows how long recovery takes. Record the result and any gaps.
The NCSC’s Response and Recovery: Small Business Guide specifically advises organisations to identify essential information, back it up regularly and test that it can be restored. A backup that has never been tested is an assumption, not a recovery capability.
Set the frequency according to the harm of lost work. An online retailer may need frequent backups of orders and stock. A consultancy might accept a nightly backup but should save active project work continuously through a managed cloud platform. Assign a named person to check backup alerts each week. If the system says a backup has failed, treat it as an operational problem rather than an IT nicety.
Fix two: Turn on multi-factor authentication for the accounts that matter most
Passwords are routinely stolen through phishing pages, reused from unrelated breaches, guessed or harvested from infected devices. Multi-factor authentication, often called MFA, 2FA or two-step verification, adds another check after the password. That makes a stolen password far less useful on its own.
Do not wait to enable it everywhere before beginning. This week, prioritise email, banking, accounting, payroll, cloud storage, domain and website hosting, remote-access tools, customer relationship management systems and any administrator accounts. Email comes first because control of an inbox can let a criminal reset passwords for many other services and convincingly impersonate the account holder.
Choose stronger methods where the impact is highest
An authenticator app, passkey or physical security key is generally preferable to codes sent by text message, particularly for high-value accounts. Text messages are better than no MFA, but can be vulnerable to social engineering and phone-number attacks. The NCSC’s guidance on MFA for corporate online services recommends stronger techniques that provide better protection against phishing, and its updated advice highlights the growing role of phishing-resistant authentication.
For the business owner, finance lead and system administrator, use passkeys or security keys where the service supports them. Store recovery codes safely: not in the same email inbox being protected and not only on one employee’s phone. Have a documented process for replacing a lost device without allowing an attacker to talk their way through an account reset.
Beware of “MFA fatigue”. A criminal may repeatedly trigger approval prompts and then phone or message a staff member claiming to be from IT. Train people never to approve a login they did not initiate. A legitimate support provider should be able to verify itself through an agreed contact route, not demand a code or approval during an unexpected call.
Fix three: Update software and devices before criminals exploit known flaws
Software updates are often postponed because they interrupt work. Yet updates frequently fix security weaknesses that are already known publicly. Once a vulnerability is documented, criminals can scan widely for unpatched devices and services. Delaying an update turns a manageable maintenance task into an avoidable exposure.
Create a list of the hardware and software your company relies on: laptops, desktops, mobiles, Wi-Fi routers, firewalls, servers, printers, point-of-sale equipment and any remote-access product. Include operating systems, browsers, office software, antivirus or endpoint protection, accounting tools, website plugins and cloud applications.
Automate what can be automated
Turn on automatic updates for operating systems, browsers, mobile devices and core business applications. For products that cannot update automatically, set a regular patching slot and assign responsibility. A small firm may choose a weekly maintenance window outside opening hours, while installing urgent security updates sooner where the supplier advises it.
Do not forget routers and other network equipment. These are easy to ignore because they sit in a cupboard and appear to work, but they are part of the business’s internet boundary. Change default administrator passwords, install current firmware and replace equipment that is no longer supported by its manufacturer. Unsupported software is a business risk because it may no longer receive security fixes.
Before updating a critical system, ensure there is a current backup and that a rollback or support route exists. This is not an excuse to defer every update; it is a sensible way to update with confidence. If you use an IT supplier, require a simple monthly report showing which devices are supported, which updates are outstanding and why.
Fix four: Remove unnecessary account access and protect privileged users
Many small businesses accumulate accounts as they grow: former employees, temporary contractors, old agencies, shared logins and “just in case” administrator rights. Every unused or over-privileged account increases the number of ways someone could get in.
Start with a quick access review. Make a list of every user who can access email administration, banking, accounting, payroll, cloud storage, website hosting, social media, customer data and remote systems. For each person, ask three questions: do they still need access, do they need this level of access, and is the account clearly tied to an individual?
Eliminate shared credentials
Each worker should have their own account. Shared logins make it difficult to see who changed a payment detail, deleted data or published content. They also create awkward security problems when someone leaves. Where a shared mailbox is needed, grant individual access to it rather than circulating one password.
Remove former staff and contractors promptly. Make this part of the joiner-mover-leaver process: when someone changes role or leaves, disable access to business systems, revoke app connections, recover company devices and transfer ownership of files, pages and subscriptions. Do not rely on the departing person to remember every system they used.
Give people only the access needed for their role. The NCSC’s identity and access management guidance recommends reviewing unnecessary privileges regularly and revoking them when no longer required. It also advises separate accounts for administrators’ everyday work and higher-risk administrative tasks. In practice, that means the person who manages Microsoft 365, Google Workspace, the website or company devices should not browse email and the web all day from their all-powerful administrator account.
Run this review quarterly after the initial clean-up, and immediately after staffing or supplier changes. It will take less time than trying to establish who had access after an incident.
Fix five: Make payment approvals resistant to phishing and impersonation
Payment fraud is not always a crude scam. Criminals can impersonate a director, supplier, solicitor or regular customer using a lookalike email address, a compromised mailbox or a convincing message timed around a real transaction. They may request a bank-detail change, pressure staff to settle an “urgent” invoice or ask for payroll details. The message may contain accurate names, logos and invoice references.
The answer is not simply “be more careful”. Build a payment process that requires independent verification when money or bank details are involved. The NCSC describes these attacks as business payment fraud, also known as business email compromise, and warns that criminals may impersonate contacts to redirect payments.
Adopt a mandatory call-back rule
Any new supplier bank details, changed bank details, unusual payment request or request to bypass a normal approval route must be checked using a trusted contact method. Call the supplier or colleague using a number already held in your records, contract, official website or known directory. Do not use the phone number, link or reply address contained in the suspicious email.
For larger payments, require two people: one prepares the payment and another checks the beneficiary details and approves it. A second person should also confirm the information against the original supplier record, not merely compare it with an email that could be fraudulent. If the business is very small, an owner can act as the second approver, but the independent call-back remains essential.
Make this rule explicit: urgency is a reason to slow down, not a reason to skip checks. No legitimate supplier relationship should collapse because an employee took five minutes to verify a bank-account change.
Write a one-page response plan and rehearse it
Basic controls matter because incidents still happen. The latest government survey found that only 25% of businesses overall had a formal incident response plan. Among small businesses, the survey reported that 50% had written guidance on who to notify, 24% had an external communications plan and 44% had guidance on external reporting. Those figures show why a concise plan is a useful practical advantage, not bureaucracy.
Create one page with: the person who leads the response; the external IT or security contact; bank fraud and insurance contact details; the location of backup instructions; the process for isolating a suspected infected device; who can approve customer communications; and when to seek legal, regulatory or data-protection advice. Keep an offline or printed copy available in case email is unavailable.
Then run a 20-minute scenario. Imagine an employee has entered their Microsoft 365 password into a fake login page, or a supplier says they have not received a payment. Who does the employee call? Who contacts the bank? Can you identify the affected accounts? Can you restore a file? The exercise will reveal missing phone numbers, unclear authority and assumptions about backups before a real incident does.
If money has been sent to a fraudster, contact the bank immediately using an independently sourced number. If an account may be compromised, change passwords from a clean device, revoke active sessions where possible and follow the NCSC’s small and medium-sized organisation guidance for recovery and reporting routes.
Make cyber resilience part of ordinary business management
The strongest small-business cybersecurity plan is not the longest policy document. It is a routine: backups checked, MFA enabled, updates applied, access reviewed, and payments independently verified. These are manageable controls, and they reduce exposure to the attacks most likely to affect a busy firm.
Set aside time this week to complete the five fixes, assign owners and record the evidence. Next month, review what changed and test one part of the response plan again. Cybersecurity is not a one-off project, but a small amount of regular attention can protect cash flow, customer trust and the ability to keep trading when an attack lands.
Call to action: Schedule a 60-minute leadership meeting today. Open your account list, backup dashboard and payment process, then leave the meeting with five named owners and five completion dates. The best time to prepare for a cyber incident is before a convincing email reaches the inbox.





















