Business cyber security protects your people, systems and data from theft, disruption and unauthorised access. For most small and medium-sized businesses, the strongest defence is a set of simple controls applied consistently. Start with these five practical steps.
1. Use strong passwords and multi-factor authentication
Create a unique password for every important account. A strong password should be long, hard to guess and unrelated to personal information. Avoid predictable choices such as “Password1234” and never reuse a work password on another service.
A reputable password manager can generate and store secure passwords so your team does not need to remember them. Do not share passwords by email or leave them in documents that other people can access.
Turn on multi-factor authentication (MFA), sometimes called two-factor authentication, wherever it is available. MFA asks for a second form of verification, such as an authenticator-app code. It can prevent an intruder from signing in even if a password has been stolen.
2. Back up essential business data
Back up the information your organisation depends on, including customer records, financial documents, emails, contacts and operational files. A reliable backup helps you recover after ransomware, hardware failure, accidental deletion or another incident.
Keep backups separate from your everyday network so an attacker cannot encrypt or delete every copy. Use automated cloud backups or encrypted storage held in another secure location. Test restoration regularly: a backup is useful only if you can recover the data when you need it.
3. Recognise and report phishing
Phishing messages impersonate a trusted person or organisation to steal information, install malware or persuade someone to make a payment. They may arrive by email, text message, social media or collaboration tools.
Pause before opening an unexpected attachment, following a link or approving a payment. Check the sender’s full address and verify unusual requests through a known phone number or a separate communication channel.
Common warning signs include:
- pressure to act immediately or keep a request secret;
- a changed bank account or unexpected payment request;
- a web address or sender domain that is slightly misspelt;
- a request for a password, verification code or sensitive information; and
- an offer or threat that seems unusual or too good to be true.
Good spelling is not proof that a message is genuine. If you are unsure, report it to your IT support team or designated security contact rather than taking the risk.
If you believe your organisation has experienced online fraud, a scam or extortion, report it through the Action Fraud website, the UK’s national reporting centre for fraud and cybercrime.
4. Keep devices and security software up to date
Install software and security updates promptly on computers, phones, routers and business applications. Updates often fix weaknesses that criminals could exploit. Where possible, enable automatic updates and replace devices or software that no longer receive security support.
Use the security protection built into reputable operating systems, including antivirus or endpoint protection, and make sure it remains active. Malware is a broad term for malicious software such as ransomware, spyware and adware. It can steal information, damage files or disrupt access to your systems.
Limit administrator access to people who genuinely need it. Give each person their own account, remove access promptly when someone leaves and use device encryption and screen locks. These controls reduce the effect of a compromised account or lost device.
5. Build cyber security awareness across your team
Business cyber security is a shared responsibility. Give everyone clear, practical training when they join and repeat it regularly. Training should explain how to identify phishing, handle sensitive information, use passwords safely, report concerns and respond to a suspected incident.
Create a simple reporting process and make it safe for people to raise a concern quickly. Early reporting gives your organisation more time to contain an attack. Run short exercises, review lessons from real incidents and keep an up-to-date response plan with named contacts and recovery priorities.
Business cyber security checklist
- Use unique passwords and multi-factor authentication.
- Automate backups, keep them separate and test recovery.
- Verify unexpected links, attachments and payment requests.
- Update supported devices, applications and security tools.
- Restrict access and remove accounts that are no longer needed.
- Train your team and provide a clear way to report concerns.
The right controls depend on your systems, data and level of risk, but these measures provide a practical foundation for most SMEs. Review them regularly as your organisation, suppliers and technology change.
Cyber security training resources
Use these existing resources to support team learning:
Cyber security for small organisations – National Cyber Security Centre
Cybersecurity Awareness Training – Bob’s Business
Cybersecurity Tutorial: A Step-by-Step Guide – Simplilearn
Cybersecurity training – ESET
Free Cybersecurity Certifications – Oxford Home Study Centre
Our Knowledge Hub For SME Insights
How to Switch Business Broadband Without Losing Connection or Downtime
Switching business broadband doesn’t have to mean any loss of service. With the right planning, the changeover happens in the background, and your team stays online throughout.
Wayv Highly Commended at Chamber Business Awards 2025
Wayv was Highly Commended for Excellence in Customer Service at the 2025 Barnsley and Rotherham Business Awards at Magna, Rotherham.
Corporate Volunteering in Sheffield: Wayv at Norton Nurseries
See how Wayv’s corporate volunteering day helped Food Works restore Norton Nurseries and support community food-growing projects across Sheffield.
How to Connect a DSL Router: Step-by-Step Guide
Connect a DSL router to a master socket, use the correct microfilter, join Wi-Fi and troubleshoot common ADSL or FTTC connection problems.
The Big Switch Off: Business Guide to the 2027 PSTN Deadline
Prepare for the UK PSTN switch off on 31 January 2027. Audit phone lines and connected devices, compare VoIP options and plan power and connectivity resilience.
Business Phone Systems: More Value for Modern Teams
Modern business phone systems connect calls, tools and teams. See how cloud calling, integrations and AI improve flexibility, service and follow-up.
Wayv Shortlisted for unLTD Business Awards 2024
Wayv was shortlisted for Best Small Business at the unLTD Business Awards 2024, recognising growth, innovation and customer care in South Yorkshire.
Wayv Shortlisted for Celebration of Business Awards 2024
Wayv was shortlisted for the Growth Award at the Barnsley and Rotherham Chamber Celebration of Business Awards 2024, recognising sustained local growth.