Even the most expensive firewall cannot stop an employee from clicking a phishing link. According to the UK government’s Cyber Security Breaches Survey 2024, 50% of UK businesses identified at least one cyber security breach or attack in the previous 12 months. Among medium businesses the figure rose to 70%, and among large businesses it reached 74%. The same survey found that phishing accounted for 84% of identified breaches. For women running UK businesses, the lesson is clear: the weakest links in your business are rarely technical. They are human.
This matters because the cost of a breach is not abstract. The 2024 survey put the mean cost of a cyber incident at £1,205 for businesses of any size, and £10,830 for medium and large businesses combined. Yet only 31% of UK businesses have a cyber insurance policy in place. With the Information Commissioner’s Office able to fine organisations up to £17.5 million or 4% of total global annual turnover under UK GDPR, a single mistake can become a serious financial and reputational problem.
Why people remain the weakest links in your business
Cyber criminals target people because people have access. Employees hold passwords, handle customer data, use company devices, and make quick decisions under pressure. Sophisticated security software can filter malware and block suspicious traffic, but it cannot rewrite an urgent-looking email or stop someone from sharing a password over Slack.
The National Cyber Security Centre treats human error as a core risk. Common mistakes include:
- Using weak or reused passwords across work and personal accounts.
- Clicking links in unexpected emails, texts, or social media messages.
- Sharing sensitive data through unencrypted channels.
- Leaving devices unlocked in public spaces.
- Using public WiFi without a virtual private network.
Remote and hybrid working has made these risks harder to contain. Staff now work from home offices, coffee shops, and co-working spaces, often on personal routers and mobile phones. If you employ remote workers, our guide on how to secure your remote work environment in 2026 sets out the practical controls to put in place.
The most common human-triggered cyber risks
Understanding the specific risks helps you prioritise training and spending. The 2024 Cyber Security Breaches Survey breaks down the threat landscape for UK businesses:
| Threat type | Share of businesses affected |
|---|---|
| Phishing | 84% |
| Impersonation | 32% |
| Malware, ransomware, or hacking | 8% |
Phishing dominates because it exploits trust and urgency. A message that appears to come from HMRC, a supplier, or a senior colleague can prompt an employee to hand over credentials or approve a payment. Impersonation fraud, where attackers pose as a known contact, is the second most reported issue.
These figures underline why technical tools alone are not enough. A business can run endpoint protection, email filtering, and automatic updates and still suffer a breach because one person acted in a hurry.
Building a practical cyber security policy for 2026
A written policy turns good intentions into repeatable behaviour. It does not need to be long, but it must be specific and enforced. At minimum, your policy should cover:
- Password standards: require unique passphrases of at least 12 characters and mandate multi-factor authentication on all business accounts.
- Device rules: company devices must be encrypted, locked when unattended, and used only by approved people.
- Data handling: define which information can be shared by email, which needs encryption, and how customer records must be stored.
- Incident reporting: make it easy for staff to report suspicious emails or lost devices without blame.
- Remote working: set out approved networks, VPN use, and restrictions on working from public WiFi.
For a broader view of the systems and records a growing business needs, see our business admin guide for UK business owners.
How to build a security-aware team
Training should be regular, not a one-off induction. The National Cyber Security Centre recommends short, practical sessions that reflect real situations your team might face. Test phishing simulations, for example, show employees what to look for and measure whether training is working.
Consider backing up your policy with Cyber Essentials, the government-backed certification scheme administered by the National Cyber Security Centre. Cyber Essentials helps protect against the most common internet-based threats and is often required when bidding for public sector contracts. Certification is available through IASME, the NCSC’s Cyber Essentials partner, with pricing based on business size and assessment type.
Other practical steps include:
- Running automatic software updates on all devices.
- Restricting access so employees can only reach the data they need.
- Keeping offline backups of critical business data.
- Reviewing who has admin rights every quarter.
- Making cyber security part of performance conversations, not just IT conversations.
Five action steps to strengthen your business
- Audit your current human risks: review recent near-misses, password habits, and remote working arrangements.
- Write a one-page cyber security policy and share it with every employee and contractor.
- Turn on multi-factor authentication for email, banking, and cloud storage.
- Book a short phishing awareness session within the next month.
- Check whether Cyber Essentials certification would help you win public sector work and reduce your insurance premium.
Turn your weakest links into a defence
Recognising the weakest links in your business is the first step to protecting it. In most UK small businesses, the weakest link is not outdated software or missing hardware; it is the person who clicks, shares, or forgets. By combining clear policies, regular training, and recognised standards such as Cyber Essentials, you can turn your team from a vulnerability into a defence. For more context on the environment women-led businesses operate in, see our women in business key UK facts page.



