Business Cyber Security: 5 Essential Steps for SMEs

Business cyber security protects your people, systems and data from theft, disruption and unauthorised access. For most small and medium-sized businesses, the strongest defence is a set of simple controls applied consistently. Start with these five practical steps.

1. Use strong passwords and multi-factor authentication

Create a unique password for every important account. A strong password should be long, hard to guess and unrelated to personal information. Avoid predictable choices such as “Password1234” and never reuse a work password on another service.

A reputable password manager can generate and store secure passwords so your team does not need to remember them. Do not share passwords by email or leave them in documents that other people can access.

Turn on multi-factor authentication (MFA), sometimes called two-factor authentication, wherever it is available. MFA asks for a second form of verification, such as an authenticator-app code. It can prevent an intruder from signing in even if a password has been stolen.

2. Back up essential business data

Back up the information your organisation depends on, including customer records, financial documents, emails, contacts and operational files. A reliable backup helps you recover after ransomware, hardware failure, accidental deletion or another incident.

Keep backups separate from your everyday network so an attacker cannot encrypt or delete every copy. Use automated cloud backups or encrypted storage held in another secure location. Test restoration regularly: a backup is useful only if you can recover the data when you need it.

3. Recognise and report phishing

Phishing messages impersonate a trusted person or organisation to steal information, install malware or persuade someone to make a payment. They may arrive by email, text message, social media or collaboration tools.

Pause before opening an unexpected attachment, following a link or approving a payment. Check the sender’s full address and verify unusual requests through a known phone number or a separate communication channel.

Common warning signs include:

  • pressure to act immediately or keep a request secret;
  • a changed bank account or unexpected payment request;
  • a web address or sender domain that is slightly misspelt;
  • a request for a password, verification code or sensitive information; and
  • an offer or threat that seems unusual or too good to be true.

Good spelling is not proof that a message is genuine. If you are unsure, report it to your IT support team or designated security contact rather than taking the risk.

If you believe your organisation has experienced online fraud, a scam or extortion, report it through the Action Fraud website, the UK’s national reporting centre for fraud and cybercrime.

4. Keep devices and security software up to date

Install software and security updates promptly on computers, phones, routers and business applications. Updates often fix weaknesses that criminals could exploit. Where possible, enable automatic updates and replace devices or software that no longer receive security support.

Use the security protection built into reputable operating systems, including antivirus or endpoint protection, and make sure it remains active. Malware is a broad term for malicious software such as ransomware, spyware and adware. It can steal information, damage files or disrupt access to your systems.

Limit administrator access to people who genuinely need it. Give each person their own account, remove access promptly when someone leaves and use device encryption and screen locks. These controls reduce the effect of a compromised account or lost device.

5. Build cyber security awareness across your team

Business cyber security is a shared responsibility. Give everyone clear, practical training when they join and repeat it regularly. Training should explain how to identify phishing, handle sensitive information, use passwords safely, report concerns and respond to a suspected incident.

Create a simple reporting process and make it safe for people to raise a concern quickly. Early reporting gives your organisation more time to contain an attack. Run short exercises, review lessons from real incidents and keep an up-to-date response plan with named contacts and recovery priorities.

Business cyber security checklist

  • Use unique passwords and multi-factor authentication.
  • Automate backups, keep them separate and test recovery.
  • Verify unexpected links, attachments and payment requests.
  • Update supported devices, applications and security tools.
  • Restrict access and remove accounts that are no longer needed.
  • Train your team and provide a clear way to report concerns.

The right controls depend on your systems, data and level of risk, but these measures provide a practical foundation for most SMEs. Review them regularly as your organisation, suppliers and technology change.

Cyber security training resources

Use these existing resources to support team learning:

Cyber security for small organisations – National Cyber Security Centre

Cybersecurity Awareness Training – Bob’s Business

Cybersecurity Tutorial: A Step-by-Step Guide – Simplilearn

Cybersecurity training – ESET

Free Cybersecurity Certifications – Oxford Home Study Centre


Our Knowledge Hub For SME Insights

Cookies in use

We use cookies on our website to help improve your experience during your visit. Please read our Privacy Policy for more information.