Cyber Security Checklist for UK Small Businesses (2026)

Cyber attacks on small businesses are rising every year. According to the UK government’s Cyber Security Breaches Survey, 50% of UK businesses experienced a cyber attack or breach in the past 12 months — and small businesses are increasingly the target precisely because they’re seen as easier to breach than large enterprises.

The good news: most attacks exploit basic security gaps that are straightforward to fix. This checklist covers the essentials every UK small business should have in place in 2026.

✅ 1. Enable Multi-Factor Authentication (MFA) on Everything

MFA adds a second layer of verification (usually a code sent to your phone) on top of your password. It blocks over 99% of automated account takeover attacks.

Enable it on:

  • Microsoft 365 / Google Workspace
  • Your banking and finance apps
  • Your website and hosting accounts
  • Any cloud storage (Dropbox, OneDrive, Google Drive)
  • Social media accounts

How to do it: Most services have MFA in their security settings. For Microsoft 365, go to the admin centre → Security defaults and turn it on.

✅ 2. Use Strong, Unique Passwords

Reusing passwords across accounts is one of the most common causes of breaches. If one account is compromised, attackers try the same password everywhere else.

Use a password manager to generate and store unique passwords for every account. Good options for small businesses:

  • Bitwarden — free, open source, excellent for teams
  • 1Password — great team features, around £4/user/month
  • Dashlane — user-friendly, good for less technical teams

✅ 3. Keep Software and Devices Updated

Outdated software is the most common entry point for ransomware and malware. Software updates patch known security vulnerabilities — delaying them leaves the door open.

Set up automatic updates for:

  • Windows / macOS
  • All business applications
  • Antivirus and endpoint protection software
  • Router and network device firmware

✅ 4. Back Up Your Data — Properly

A good backup strategy follows the 3-2-1 rule:

  • 3 copies of your data
  • 2 on different storage types (e.g. local drive + cloud)
  • 1 offsite or air-gapped (not connected to your main network)

Test your backups regularly. A backup you’ve never tested is a backup you can’t rely on.

Common mistake: assuming Microsoft 365 or Google Workspace backs up your data. They don’t — not in the way you think. Files deleted from OneDrive are only recoverable for 93 days. Use a dedicated backup tool like Veeam or Backupify.

✅ 5. Train Your Staff on Phishing

Over 80% of cyber attacks start with a phishing email — a message designed to trick someone into clicking a link or handing over credentials.

Your staff are your biggest vulnerability and your best defence. Even a short 30-minute awareness session can dramatically reduce your risk.

Key things to teach:

  • How to spot suspicious emails (urgency, unusual sender, unexpected attachments)
  • Never click links in unexpected emails — go directly to the website instead
  • How to report suspicious emails internally
  • What to do if they think they’ve been phished

✅ 6. Secure Your Wi-Fi Network

  • Change the default router admin password immediately
  • Use WPA3 encryption (or WPA2 at minimum)
  • Set up a separate guest Wi-Fi network for visitors — never give guests access to your main business network
  • Disable WPS (Wi-Fi Protected Setup) — it’s a known vulnerability
  • Keep router firmware updated

✅ 7. Control Who Has Access to What

Not everyone in your business needs access to everything. Apply the principle of least privilege — give people access only to what they need to do their job.

  • Remove access immediately when someone leaves the business
  • Limit admin rights to one or two trusted people
  • Review user permissions regularly
  • Use role-based access controls in Microsoft 365 or Google Workspace

✅ 8. Have an Incident Response Plan

If the worst happens, do you know what to do? Having a simple plan in place means you respond faster and limit the damage.

Your plan should cover:

  • Who to contact first (IT support, your bank, the ICO if personal data is involved)
  • How to isolate affected devices from the network
  • How to communicate with staff and clients
  • Where your backups are and how to restore from them

You don’t need a 50-page document — a one-page reference sheet is enough for most small businesses.

✅ 9. Register with the ICO

If your business handles personal data (which almost all businesses do), you’re legally required to register with the Information Commissioner’s Office (ICO) under UK GDPR. Registration costs £40–£60 per year depending on your organisation size.

Failure to register can result in fines. Check if you need to register at ico.org.uk.

✅ 10. Consider Cyber Essentials Certification

Cyber Essentials is a UK government-backed certification scheme that demonstrates your business has basic cyber security controls in place. It covers five key areas: firewalls, secure configuration, access control, malware protection, and patch management.

Benefits:

  • Demonstrates security credentials to clients and partners
  • Required for some government contracts
  • Includes £25,000 cyber insurance for eligible businesses
  • Costs from around £300 for self-assessment

Need Help Implementing Any of This?

If your business isn’t sure where to start, we offer a cyber security assessment that reviews your current setup against this checklist and gives you a clear, prioritised action plan.

Get a quote or browse our cyber security services to find out more.