SMEs remain a prime target for cyber criminals, and a single attack can cause serious financial and reputational damage to a small business. Yet many owners still do not treat cyber crime as a business risk, especially if they do not sell online or believe they have nothing worth stealing. In reality, cyber crime is not only about cash. Criminals can profit from stealing your intellectual property, customer data, supplier details and even email addresses from your address book. Here is how to make your small business cyber secure without hiring an in-house security team.
According to the UK government’s Cyber Security Breaches Survey 2025, 43% of businesses and 30% of charities identified a cyber security breach or attack in the last 12 months. For medium businesses the figure rises to 66%, and for large businesses it reaches 72%. Phishing remains the most common threat, accounting for 84% of breaches, while impersonation, malware and ransomware also cause serious damage. Among businesses that identified a breach, the median estimated cost was £1,205, but the true cost is often far higher once downtime, recovery and lost business are included.
The good news is that small adjustments can deliver major improvements to your online security. For women founders and women-led businesses, this is particularly valuable: strong cyber security helps you protect your reputation, improve customer trust, become more productive and compete for larger contracts. The National Cyber Security Centre (NCSC) reports that customers are more likely to engage with businesses that can demonstrate they take cyber security seriously.
If you do not know where to start, here are practical steps to boost your cyber security.
Understand the risk to make your small business cyber secure
Small businesses are attractive to attackers because they often lack dedicated IT security teams but still hold valuable data. A customer database, invoice records or login credentials can be sold on or used to launch further attacks. Many criminals use automated tools to scan thousands of businesses at once, so you do not need to be a high-profile target to be hit.
The UK Cyber Security and Resilience Bill, introduced in 2025, is expected to expand reporting requirements and strengthen standards for businesses that provide critical digital services. Even if your firm is not directly in scope, the direction of travel is clear: basic cyber hygiene is becoming a minimum expectation for trading in the UK.
Keep software and devices up to date
Do not ignore messages asking you to update your software or operating system. Updates exist to fix security weaknesses that hackers could exploit. Where possible, turn on automatic updates for your computers, phones, tablets and apps. This simple habit closes the holes criminals use to gain access to your systems.
If you have staff working from home, make sure their personal routers and devices are also updated. Our guide on how to secure your remote work environment in 2026 covers the extra checks that matter for hybrid teams.
Use strong passwords and a password manager
Weak passwords leave your business open to fraud, theft and extortion. Avoid common choices such as pet names, dates of birth or simple sequences. The NCSC recommends using three random words to create memorable but strong passwords, combined with upper and lower case letters, symbols and numbers where the system allows.
Because most small businesses use dozens of online accounts, a password manager is one of the best investments you can make. It generates and stores unique, complex passwords for every account, so you only need to remember one strong master password. Never reuse passwords across business and personal accounts.
Turn on multi-factor authentication
Multi-factor authentication (MFA), sometimes called two-factor authentication or 2FA, adds an extra layer of protection by asking for a second piece of evidence before you can log in. Even if a criminal guesses or steals your password, they cannot access the account without the second factor, which is usually a code sent to your phone or generated by an authenticator app. Turn on MFA for email, banking, cloud storage, accounting software and any other service that holds sensitive business data.
Install and maintain endpoint protection
Installing reputable anti-virus or endpoint protection software and keeping it up to date is another layer of your cyber security defences. Make sure you are using the software correctly and to its full potential, and that it covers all devices that connect to your business network, including laptops used by remote workers.
For businesses that handle data on the move, a virtual private network (VPN) can add protection when staff use public Wi-Fi. Read our article on 4 reasons your small business should use a VPN in 2026 to decide whether it fits your setup.
Train your staff on cyber security awareness
Your staff are both your strongest defence and your biggest vulnerability. The most common problems faced by businesses include employees exposing IT systems to malware by plugging in unknown USB sticks, opening phishing emails, clicking malicious links or using unsafe websites. Make your team aware of the dos and don’ts, and help them understand how a cyber attack could affect them, your customers and the business. A clear, simple cyber security policy and regular reminders are more effective than one-off training sessions.
Back up your data and test it
Ransomware attacks can lock you out of your own files until you pay a fee. The best protection is to keep regular, secure backups of your important data, stored separately from your main network or in the cloud with a reputable provider. Test your backups periodically to make sure you can restore them quickly if the worst happens.
Check your readiness with free NCSC tools
The NCSC offers free tools to help small businesses assess and improve their cyber security. The NCSC Small Business Guide covers the essential steps in plain English, while the Exercise in a Box toolkit lets you practise your response to cyber incidents in a safe environment. You can also use the NCSC’s Cyber Action Plan to answer simple questions and receive a tailored list of actions.
Get certified with Cyber Essentials
Cyber Essentials is an easy-to-use, cost-effective way to help businesses protect themselves against the most common online risks. The government-backed and industry-supported scheme, administered by the IASME Consortium, sets out five key technical controls and provides clarity on good basic cyber security practice. Certification demonstrates that you have taken steps to be cyber safe, reassuring customers while boosting confidence in your firm. For women-led businesses, the credential can also help you meet procurement requirements and compete for public sector contracts. Certification costs vary by provider and organisation size, but self-assessment packages typically start from around £300 plus VAT.
Action steps to take this week
- Run automatic updates on every business device this week.
- Switch on multi-factor authentication for email, banking and cloud accounts.
- Sign up for a password manager and replace reused passwords.
- Complete the NCSC Cyber Action Plan and review the results with your team.
- Get a quote for Cyber Essentials certification if you supply the public sector or handle sensitive client data.
Do not make the mistake of assuming that only big corporations and governments are at risk from cyber criminals. Following these steps will help make your small business cyber secure and let you get on with running your company, knowing that you and your customers are better protected against hackers.
Emma Philpott is the CEO of the IASME Consortium, which promotes cyber security within small companies and assesses them against the government’s Cyber Essentials scheme and IASME’s own governance standard. Emma is also Founder and Manager of the Malvern Cyber Security Cluster and the UK Cyber Security Forum, a network of more than 250 small companies working in cyber security.






