The small business cyber security checklist

Most cyber attacks on small businesses are not sophisticated. They rely on a guessable password, an out-of-date laptop, or someone clicking a convincing email. The good news is that the same basics that stop the majority of attacks are mostly low or no cost — they just need doing, and keeping done. Here is a practical, ordered checklist you can work through. None of it requires you to be technical.

The ten-step checklist

Start at the top and work down. The earlier items give you the most protection for the least effort, and most can be put in place this week.

1. Use strong, unique passwords with a password manager

Reusing one password everywhere means that a single leak exposes everything. A password manager creates and remembers a long, unique password for every account, so your team only has to remember one master password. Good ones are free or very cheap, and they remove the temptation to keep passwords on sticky notes or in a spreadsheet.

2. Turn on multi-factor authentication (MFA)

MFA asks for a second proof of identity — usually a code from an app on your phone — on top of the password. It is the single most effective step on this list, because even if a password is stolen, the attacker still cannot get in. Switch it on for email, banking, accounting and any cloud systems first.

3. Train staff to spot phishing

Phishing emails and texts trick people into handing over passwords or paying fake invoices. A short, honest conversation with your team about what to look for — unexpected urgency, mismatched sender addresses, links that do not go where they claim — prevents a large share of incidents. Make it clear that reporting a suspicious message is always the right call, never something to be embarrassed about.

4. Keep software and devices updated

Updates are not just new features; they patch the security holes attackers exploit. Turn on automatic updates for operating systems, browsers, phones and apps wherever you can, so the fixes arrive without anyone having to remember. Retire devices that are too old to receive updates.

5. Back up your data — and test the restore

Reliable backups are your safety net against ransomware, hardware failure and simple mistakes. Follow the principle of keeping more than one copy, with at least one held separately from your main systems. Crucially, test that you can actually restore from a backup — an untested backup is only a hope, not a plan.

Not sure your backups would actually work if you needed them? A managed IT partner can check and monitor them for you.

Get Started

6. Protect every device with endpoint and antivirus software

Modern antivirus and endpoint protection quietly watches for malicious software and blocks it before it can do harm. Make sure it is installed and switched on across all business laptops, desktops and, where relevant, phones — not just the office server.

7. Give people only the access they need

This is the principle of least privilege: each person should have access to the systems and data their role requires, and no more. It limits the damage if an account is compromised, and it means a departing employee cannot walk away with the keys to everything. Review who has access to what from time to time, and remove accounts promptly when people leave.

8. Secure your email and Microsoft 365

Email is the front door to most businesses, so it deserves particular attention. Beyond MFA, that means enabling the security features already built into platforms like Microsoft 365, being alert to mailbox rules you did not set up, and locking down who can send on behalf of the business. Getting this right also helps protect you from invoice fraud.

9. Have a simple incident plan

Decide in advance what you would do if something went wrong: who to call, how to isolate an affected device, where the backups are, and who needs to be told. It does not need to be a thick document — a single page that everyone can find under pressure is far more useful than a detailed plan nobody can locate on a bad day.

10. Consider Cyber Essentials certification

Cyber Essentials is a UK government-backed scheme that sets out a baseline of sensible controls — many of which are already on this list. Working towards it gives you a clear framework, and the certification can reassure customers and is sometimes required to win certain contracts. It is a natural next step once the basics are in place.

You do not have to tackle all ten at once. Working through them in order, starting with passwords and MFA, meaningfully reduces your risk within days. If you would rather have this set up, monitored and kept current for you, that is exactly what a good managed IT partner does — and you can get in touch for an introduction to one. Do the basics well, keep doing them, and you close the door on the great majority of attacks small businesses actually face.

FAQs

Common questions

Turn on multi-factor authentication and start using a password manager. Together they protect you against the most common way accounts are compromised — stolen or guessed passwords — and both are quick and low cost to set up.

Most cost little or nothing. Password managers, MFA, automatic updates, least-privilege access and a written incident plan are largely free or already built into tools you own. The main investment is a bit of time and the discipline to keep things maintained.

Cyber Essentials is a UK government-backed certification that confirms you have a baseline of sensible security controls in place. It is not compulsory for most businesses, but it provides a clear framework, reassures customers, and is sometimes required to win certain contracts — especially in the public sector.

Yes. A managed IT partner can put these controls in place, monitor updates and backups, run phishing awareness for staff and support you through Cyber Essentials — so security is looked after in the background rather than left to chance.

Ready when you are

Want the basics handled for you?

Tell us about your setup and we'll introduce a managed IT specialist who can secure and monitor it — free, independent and with no obligation.

Get Started