The UK Small Business Cyber Security Starter Guide
If you run a small UK business and cyber security feels overwhelming, start here. This guide explains the threats that actually target small firms, the handful of controls that stop most of them, what Cyber Essentials is and why it helps you win work, and where to turn for trustworthy help. No jargon, no scare tactics, just what to do.
Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.
Cyber security without the fear
If you run a small business, cyber security can feel like a subject designed to make you feel behind. It is full of jargon, the headlines are frightening, and every provider seems to be selling something. This guide strips all of that away. By the end you will understand the threats that genuinely affect small UK firms, the controls that stop most of them, and where to get help you can trust.
Here is the reassuring truth up front. You do not need to understand how attacks work to defend against them. You need a small set of good habits and controls, done consistently. That is entirely within reach for a business of any size.
The threats that actually target small businesses
Forget the image of a hooded hacker singling out your firm. The reality is more mundane and more common. Most attacks are automated: software scans the internet non-stop looking for any business with a gap to exploit. Small firms get caught because they assume they are too small to bother with.
The threats you are most likely to meet are:
- Phishing. Fake emails or texts that trick someone into handing over a password or clicking a harmful link. This is the number one way businesses are breached.
- Invoice and payment fraud. Criminals pose as a supplier or your boss and ask for a payment or a change of bank details. This costs UK businesses in the hundreds of millions of pounds a year (per UK Finance’s Annual Fraud Report).
- Ransomware. Malicious software locks up your files and demands payment. Without a good backup, you may lose everything.
- Account takeover. A stolen or reused password lets a criminal into your email, from where they can reset everything else.
- Lost or stolen devices. A laptop left on a train is a data breach if it is not encrypted and protected.
Notice a pattern: almost all of these come down to email, passwords and people, not exotic technology.
The controls that stop most attacks
The encouraging part is that a short list of measures blocks the overwhelming majority of these threats. If you do nothing else, do these.
1. Turn on multi-factor authentication (MFA)
MFA means a stolen password alone is not enough to get into an account; a criminal also needs a code from your phone. Switch it on for email first, then banking, accounting software and anything holding customer data. It is free and it is the single most effective step you can take.
2. Use a password manager
Reused passwords are one of the biggest risks in any business. A password manager creates and remembers a strong, unique password for every account, so your team never has to. Proton Pass is a simple, privacy-focused choice, and Proton is the provider we use for our own email at Dacros, so we are recommending something we actually rely on.
3. Keep everything updated
Most breaches exploit flaws that have already been fixed, in updates people never installed. Turn on automatic updates for laptops, phones and key software, and the problem largely looks after itself.
4. Back up your data, and test it
Follow the 3-2-1 rule: three copies of your important data, on two types of storage, with one copy off-site or in the cloud. Crucially, test that you can actually restore a file. A backup you have never checked is only a hope. Note that cloud services like Microsoft 365 hold your live data but are not a full backup on their own.
5. Protect your email domain
Settings called SPF, DKIM and DMARC stop criminals from sending emails that appear to come from your business. They are technical to set up, so this is a sensible job for an IT provider, but they protect both your reputation and your customers.
6. Train your team
Your people are your best defence. A fifteen-minute briefing on spotting phishing, plus one firm rule that any change to payment details must be verified by phone, prevents most fraud.
A quick word on phones and communication
Security is not only about computers. If staff use personal mobiles for work, make sure those phones have a screen lock and can be wiped if lost. And if you are still juggling personal mobile numbers for business calls, a proper business phone system keeps work and personal life separate and gives you more control. A UK VoIP service such as AirLandline lets you run a professional business number across your devices without new hardware, which also makes it easier to verify callers and manage who speaks for your business.
Cyber Essentials: proving you have the basics
Once the controls above are in place, you are close to meeting Cyber Essentials, the UK government-backed certification run by IASME on behalf of the National Cyber Security Centre (NCSC). It certifies that you have five basic controls in place.
Why bother getting certified?
- It gives you a clear checklist and confirms you have not missed anything.
- It reassures clients that you take their data seriously.
- It is increasingly required to win contracts, especially in the public sector.
- It can reduce your cyber insurance premiums.
For a small business it is affordable and genuinely achievable, and it is one of the best-value things you can do to stand out to cautious clients.
Where to get help you can trust
You do not have to do this alone, and you should be wary of anyone who tries to frighten you into a big purchase. Trustworthy sources include:
- The NCSC, which publishes free, plain-English guidance for small businesses.
- The ICO, for anything about protecting personal data and your legal duties.
- Action Fraud, to report fraud and cyber crime in the UK.
- A good managed IT provider, to put the controls in place and keep them working so you can get on with running your business.
If you would like a hand, that is exactly what we do. Our cyber-security services and managed IT support are built for small businesses that want to be secure without becoming experts. If you are local, we also offer IT support in Leeds and Bradford.
The best first step is simply to know where you stand. Book a free IT and security review and we will look at your setup, tell you honestly what is strong and what needs work, and give you a clear, jargon-free plan. There is no obligation and no scare tactics, just straight advice.
Frequently asked questions
Are small businesses really a target for cyber criminals?
Yes. Most attacks are automated and untargeted; they look for any business with weak defences, regardless of size. Small firms are often hit precisely because they assume they are too small to bother with and so leave gaps that larger organisations have closed.
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification, run by IASME on behalf of the NCSC, that shows you have five basic security controls in place. It is affordable, achievable for small businesses, and increasingly required to win contracts, especially public-sector work.
How much should a small business spend on cyber security?
Less than most people fear. The highest-impact steps, like MFA and updates, are free. A password manager and cloud backup cost a few pounds per user per month. Managed IT support is a predictable monthly fee that usually costs far less than a single serious incident.
What should I do first if I think we have been hacked?
Disconnect the affected device from the internet, change passwords from a different, clean device, turn on MFA, and contact your IT provider. Report fraud to Action Fraud, and report a personal-data breach to the ICO within 72 hours if one has occurred.
Do I need antivirus if I use Microsoft 365?
You still need protection on every device, but for many small businesses the built-in tools such as Microsoft Defender are sufficient, provided they are switched on and kept updated. The bigger risks are usually weak passwords and phishing, not viruses.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.