Getting Windows privacy and security right is one of the simplest ways to reduce risk in a small business. If your company runs on Windows, the default setup is built for convenience rather than confidentiality. Whether you are running Windows 11 on a new laptop or keeping older hardware going after the Windows 10 era, the out-of-the-box settings can share more than many owners realise: location history, typing patterns, app usage and diagnostic data can all reach Microsoft’s servers unless you change them.
For women founders and women-led businesses, time and budget are often tight, so a preventable security incident can be especially disruptive. With the UK government’s Cyber Security Breaches Survey 2024 finding that 50% of businesses identified a cyber security breach or attack in the previous 12 months, locking down your devices is not optional. The same report puts the median cost of a cyber incident at £1,205 for businesses overall, rising to £10,830 for medium and large firms. For a small business, even the lower figure can hurt cash flow. The good news is that most of the protection you need is already built into Windows.
Start with the right account and setup
During setup, Windows encourages you to sign in with a personal Microsoft account. For a business device, this is rarely the best choice. A personal account can sync browsing history, passwords and settings across non-company devices, which creates a data-protection headache. If you do not need the consumer Windows Store or personal cloud features, set up a local account instead, or sign in with a work account that your business controls.
If you already use Microsoft 365 or Entra ID (formerly Azure Active Directory), use those business credentials. They let you apply security policies, enforce multi-factor authentication and manage devices centrally. Avoid the “Express” or “recommended” setup options that accept every default; choose the custom path and read each privacy prompt carefully. For more on building a complete security routine, see our guide to how to secure your remote work environment in 2026.
Windows privacy and security settings to review
Most of the controls you need live under Settings > Privacy & security in Windows 11, or Settings > Privacy if you are still on Windows 10. Work through the list methodically:
- Advertising ID: Turn off “Let apps show me personalised ads using my advertising ID.” This stops Microsoft building an advertising profile tied to your account.
- Location: Disable location services globally, then grant access only to apps that genuinely need it, such as mapping or delivery tools.
- Diagnostic data: Choose “Required diagnostic data” rather than “Optional diagnostic data” to limit what is sent to Microsoft.
- Activity history: Turn off storing activity history on the device and sending it to Microsoft. This prevents a detailed log of your files, apps and browsing being held in the cloud.
- Inking & typing and speech: Disable “Getting to know you” and cloud-based speech recognition unless you actively use dictation. These features upload samples of your handwriting, typing and voice to improve Microsoft’s prediction engines.
- App permissions: Audit access to the camera, microphone, contacts, calendar and files. Deny anything that is not essential, and remove permissions for apps you no longer use.
You can also manage your Microsoft account privacy from the Microsoft privacy dashboard and opt out of personalised ads wherever you use your account. For business devices, sign into Edge with a work profile rather than a personal account so browsing data stays separate.
Strengthen device security with built-in Windows tools
Privacy settings are only part of the picture. Make sure the device itself is hard to attack:
- Windows Hello: Use a PIN, fingerprint or facial recognition instead of a password. It is faster and far more resistant to phishing.
- Device encryption: Check that BitLocker (Windows Pro and Enterprise) or device encryption (Windows Home) is enabled. If a laptop is lost or stolen, encrypted data is extremely difficult to access.
- Secure Boot and TPM 2.0: These should be enabled in the firmware. They are required for Windows 11 and protect against low-level malware.
- Microsoft Defender Antivirus: The built-in antivirus and firewall are sufficient for most small businesses if kept up to date. Only replace them if you have a specific reason.
- Smart App Control: On Windows 11, this blocks untrusted or unsigned apps. It is a useful extra layer if your team downloads software from the web.
If you are reviewing your wider IT setup, see our practical guide to IT services for small businesses. A virtual private network adds another barrier when staff work away from the office; read our look at 4 reasons your small business should use a VPN in 2026.
Keep Windows updated and backed up
Modern Windows expects you to keep up to date: while Pro and Enterprise editions let you defer updates, refusing patches indefinitely is no longer realistic. Unpatched systems are one of the easiest ways attackers break in. Enable automatic updates and schedule restarts outside working hours.
Windows 10 support ended in October 2025. After that date, Microsoft stopped providing free security updates for most editions. If your hardware allows it, upgrade to Windows 11. Devices that cannot be upgraded should be replaced or covered by Microsoft’s paid Extended Security Updates programme, which now runs until October 2028 for eligible devices.
Backups matter just as much as updates. Ransomware can lock you out of your files in minutes. Use OneDrive for Business or another reputable cloud backup service, but keep an offline or separate copy as well. The National Cyber Security Centre (NCSC) recommends the 3-2-1 approach: three copies of important data, on two different media, with one stored off-site or offline.
Balance convenience with confidentiality
Microsoft will argue that data sharing lets it improve your experience, predict your preferences and protect your security. Some of that is true: cloud-based threat intelligence, for example, helps Defender respond quickly to new malware. But convenience should never override your data protection responsibilities under UK GDPR and the Data Protection Act 2018, where the maximum fine can reach £17.5 million or 4% of global annual turnover.
The simplest approach is to turn off everything you do not need, document the choices in a short IT policy, and train staff not to click “accept” on every setup screen. If you use Microsoft 365, review the admin privacy and security dashboards regularly; if you run standalone PCs, set aside an hour each quarter to revisit Settings > Privacy & security.
Taking control of Windows privacy and security is not about rejecting every modern feature. It is about making sure your business data is shared only when you have consciously decided the benefit is worth the risk.
Five practical action steps for your business
- Audit every business device and note whether it runs Windows 10 or Windows 11.
- Upgrade any Windows 10 hardware before the end of 2026, or purchase Extended Security Updates if replacement is not yet possible.
- Walk through Settings > Privacy & security on each device and disable unnecessary data sharing.
- Enable device encryption, Windows Hello and automatic updates.
- Put the NCSC 3-2-1 backup rule into practice and test that you can restore a file.






