Cybersecurity is not just an IT issue for UK small businesses. It is a financial, legal and operational risk that sits with the business owner. The UK government’s Cyber Security Breaches Survey 2025 found that 43% of businesses experienced a cyber security breach or attack in the previous 12 months. For a woman running a small business, the cost of recovery, lost trading hours and reputational damage can be far harder to absorb than for a larger firm.
Here are five cybersecurity best practices for small businesses that will help you protect customer data, meet UK legal obligations and reduce the chance of a costly breach.
Cybersecurity Best Practices for Small Businesses: Five Core Controls
1. Write a Cyber Policy and Incident Response Plan
A cyber policy sets out who is responsible for security, what data you hold, how it is protected and what happens if something goes wrong. The 2024 Cyber Security Breaches Survey reported that micro and small businesses were far less likely than larger firms to have formal cyber security policies or documentation in place. Without one, you are relying on memory and goodwill when an attack happens.
Your policy should cover:
- The devices, software and cloud services the business uses
- Who can access sensitive data and on what basis
- Password and multi-factor authentication rules
- How to report suspicious emails or lost devices
- Steps to take in the first 24 hours of a breach
Pair this with an incident response plan. The National Cyber Security Centre (NCSC) provides a free Small Business Guide and Response and Recovery guidance that you can adapt to your firm.
2. Train Employees to Recognise Phishing and Social Engineering
Most cyberattacks on small businesses start with a human mistake. The Cyber Security Breaches Survey 2024 found that phishing remained the most common attack type, reported by 84% of businesses that identified any breach or attack. Training your team to spot suspicious links, unexpected attachments and requests for passwords is one of the highest-return investments you can make.
Make training practical and repeated. Cover:
- How to verify requests for payments or sensitive data
- Why public Wi-Fi is risky for business tasks
- What to do if they click a malicious link
- How to handle customer data safely under UK GDPR
If you employ staff, include cybersecurity in your induction and refresher training. For sole traders, the same discipline applies: treat your own inbox and devices with the same caution you would expect from an employee.
3. Install and Maintain Technical Security Measures
Basic technical controls stop most opportunistic attacks. At minimum, your business should:
- Turn on multi-factor authentication (MFA) for every account that offers it, especially email, banking and cloud storage
- Keep operating systems, apps and antivirus software updated automatically
- Use a firewall on your network and a reputable endpoint security product on every device
- Encrypt sensitive data and restrict access to authorised people
- Back up business-critical data regularly and store a copy offline or in a separate cloud account
The NCSC recommends these controls as the foundation of good cyber hygiene. If you use AI tools or cloud software to run your business, review their security settings too. Our guide to the best AI tools for UK small businesses explains what to check before adopting new platforms.
4. Get Cyber Essentials Certified
Cyber Essentials is a UK government-backed certification scheme. The NCSC sets the technical requirements and IASME, the NCSC’s Cyber Essentials partner, manages certification. It shows you have implemented five key technical controls and is often required by public-sector suppliers and larger corporate buyers.
The self-assessment option starts at around £300 plus VAT through an IASME-accredited certification body. For businesses that want a higher level of assurance, Cyber Essentials Plus includes a hands-on technical audit. Certification lasts for 12 months, so diarise renewal.
Beyond the badge, the process helps you identify gaps in your defences before an attacker does. If you are a woman-led business bidding for public contracts or corporate supply chains, Cyber Essentials can be a practical differentiator.
5. Understand Your Legal Obligations and Prepare for the Worst
UK businesses must comply with the UK GDPR and the Data Protection Act 2018. If you process personal data, you need lawful basis, clear privacy notices, data retention limits and a process for handling subject access requests. The Information Commissioner’s Office (ICO) can issue fines of up to £17.5 million or 4% of total annual worldwide turnover, whichever is higher, for serious breaches.
From 17 October 2024, the Network and Information Systems Regulations 2024 (NIS2) also placed new security and incident-reporting duties on essential and important entities in sectors such as energy, transport, health and digital services. Most micro and small businesses fall outside scope, but if you supply these sectors or provide managed IT services, check whether the rules apply to you.
If a breach occurs, act fast. Under UK GDPR, you may need to report a personal data breach to the ICO within 72 hours of becoming aware of it. Keep the ICO’s breach reporting helpline and your cyber insurer’s details to hand. You can read more about protecting your firm financially in our guide to what is cyber insurance for women-led SMEs.
What to Do If You Suffer a Breach
Speed matters. Disconnect affected devices from the internet, preserve evidence, change compromised passwords and notify your bank if financial details are involved. If personal data is at risk, report to the ICO within the 72-hour window. Document every decision, because regulators and insurers will ask for it.
Take Action This Week
- Audit the devices, accounts and data your business holds this week
- Write a one-page cyber policy and share it with anyone who accesses business systems
- Turn on multi-factor authentication and automatic updates across all devices
- Book Cyber Essentials self-assessment if you supply public-sector or corporate clients
- Check your privacy notice and data handling processes against ICO guidance
Cybersecurity best practices for small businesses do not require an enterprise budget. They require consistency, clear responsibilities and a plan for when things go wrong. Start with the basics, certify where it helps you win work, and treat security as part of running a resilient business. For women founders, this is about protecting the business you have built and the customers who trust you.






