Some links here are affiliate links: we may earn a small fee if you buy, at no extra cost to you.

Most cyber attacks on small UK businesses are not sophisticated. They are phishing emails, reused passwords, unpatched software and out-of-date websites. The good news is that a handful of basic steps blocks the large majority of them, and most cost little or nothing.

1. Turn on two-step verification everywhere

Email, banking, your website login, social media and accounting software should all use two-step verification (2SV). If a password leaks, the attacker still can’t get in without the second step. Start with your email account, because it can be used to reset everything else.

2. Use a password manager

Reused passwords are one of the most common ways small businesses are breached. A password manager creates and remembers a unique password for every account, and makes it easy to share logins with staff without writing them down.

3. Keep devices and software updated

Switch on automatic updates for Windows, macOS, phones, browsers and apps. Replace devices that no longer get security updates.

4. Protect every computer with security software

Windows includes Microsoft Defender, which is a sensible baseline. If you want extra features such as safe-browsing protection, ransomware protection, a VPN or central management across several devices, a paid security suite like Kaspersky covers PCs, Macs and phones under one licence.

One thing to be aware of: if you supply the UK public sector or work with sensitive government information, the National Cyber Security Centre (NCSC) has advised such organisations to think carefully about using security software from Russian-based companies. For most small businesses this doesn’t apply, but check your contracts and clients’ requirements first.

5. Back up, and test your backups

Keep at least one backup that isn’t permanently connected to your computer or network, so ransomware can’t encrypt it too. Check now and then that you can actually restore files from it. Backup software such as AOMEI Backupper can run scheduled backups of whole PCs to an external drive or network storage.

6. Secure your website

An out-of-date WordPress site is a common target. Keep WordPress, the theme and plugins updated, remove plugins you don’t use, and use strong admin passwords with 2SV. A website firewall and malware scanning service such as Sucuri can block attacks and help clean up a hacked site. If your site is old and hard to update, see the right way to modernise an old WordPress site.

7. Train your team to spot phishing

Most breaches start with someone clicking a link or opening an attachment. Teach staff to check sender addresses, be suspicious of urgent payment requests, and confirm any change of bank details by phone using a number you already have.

8. Consider Cyber Essentials

Cyber Essentials is the UK government-backed scheme that certifies you have the basic controls above in place. Some public-sector and larger clients ask for it, and it’s a good checklist even if you don’t certify. The NCSC’s free Small Business Guide is a good place to start.

If something goes wrong

  • Disconnect affected devices from the network
  • Change passwords from a clean device, starting with email
  • Report fraud and cyber crime to Action Fraud
  • If personal data may have been exposed, you may need to report it to the ICO within 72 hours of becoming aware

Quick checklist

  • Two-step verification on email, banking and website logins
  • A password manager for the whole team
  • Automatic updates switched on
  • Security software on every device
  • An offline or separate backup, tested
  • Website updated, with a firewall or scanning service
  • Staff know how to spot phishing
Web Matter is an independent UK web studio and publisher · info@webmatter.co.uk · About · How we review · Affiliate disclosure · Partner with us · Privacy & cookie policy
Web Matter
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.