Cyber Security Checklist for Small Businesses: 12 Essential Measures

Good cyber security does not require a small business to implement every security product available. It requires a sensible set of controls that protect important accounts, devices and data while helping employees recognise and report suspicious activity.

This 12-point checklist covers the practical measures that every small business should review. Some can be implemented internally, while others may require support from an IT or cyber security provider.

Small business cyber security checklist

  1. Identify your important systems, accounts and data
  2. Keep devices and software updated
  3. Use multi-factor authentication
  4. Use strong, unique passwords
  5. Protect business email from phishing
  6. Control user access and administrator privileges
  7. Protect and monitor business devices
  8. Back up important data and test recovery
  9. Secure networks, Wi-Fi and remote access
  10. Train employees and make reporting easy
  11. Create a cyber incident response plan
  12. Work towards Cyber Essentials and review security regularly

1. Identify your important systems, accounts and data

You cannot protect systems effectively if nobody knows what the business owns, where its data is stored or who has access to it.

Start by creating a straightforward record of:

  • Computers, laptops and mobile devices
  • Servers, networking equipment and business applications
  • Microsoft 365 and other cloud accounts
  • Important suppliers and online services
  • Where customer, financial and operational data is stored
  • Which employees and third parties have access
  • Who is responsible for each system

This does not need to become an enormous technical document. Its purpose is to identify what would cause the greatest disruption if it became unavailable, corrupted or accessed by an unauthorised person.

2. Keep devices and software updated

Software updates frequently contain security fixes for known vulnerabilities. Delaying them can leave computers and applications exposed to weaknesses that attackers already understand.

Where possible, enable automatic updates for:

  • Windows, macOS and mobile operating systems
  • Web browsers
  • Microsoft Office and other business applications
  • Firewalls, routers and network equipment
  • Security software

Replace devices and applications that are no longer supported by their manufacturer. Unsupported software may stop receiving security updates even if it continues to operate normally.

For centrally managed computers, use monitoring and patch-management tools to identify failed updates and devices that have fallen behind.

3. Use multi-factor authentication

Multi-factor authentication, also known as MFA or two-step verification, requires an additional method of verification alongside a password.

It should be enabled at a minimum for:

  • Email and Microsoft 365 accounts
  • Administrator accounts
  • Banking and financial services
  • Cloud storage and backup systems
  • Remote access and VPN accounts
  • Customer relationship management and accounting platforms

The National Cyber Security Centre describes two-step verification as one of the most effective ways to protect email and important online accounts. Where available, phishing-resistant methods such as passkeys, security keys or properly configured authentication applications offer stronger protection than relying only on text messages.

Read the NCSC guidance on securing business email.

4. Use strong, unique passwords

Employees should not reuse the same password across several business and personal accounts. If one service is compromised, reused credentials may give an attacker access elsewhere.

A practical password policy should encourage:

  • A different password for each important account
  • Long passwords or passphrases that are difficult to guess
  • Use of an approved password manager
  • MFA wherever it is available
  • Immediate password changes when compromise is suspected

Avoid forcing people to make minor password changes so frequently that they resort to predictable patterns. Strong access controls, unique passwords and MFA are more useful than passwords that merely become “PasswordJune” and “PasswordJuly”.

5. Protect business email from phishing

Email is frequently used to deliver fake invoices, malicious links, fraudulent payment requests and attempts to steal passwords.

Protect business email by combining technical controls with clear internal procedures:

  • Enable MFA for every mailbox
  • Use spam, malware and phishing filtering
  • Configure SPF, DKIM and DMARC for the company domain
  • Display warnings on messages arriving from outside the organisation
  • Verify unusual payment and bank-detail changes through another communication channel
  • Give employees a simple way to report suspicious messages

No email filter will identify every malicious message. Employees therefore need to know that an urgent tone, familiar branding or a senior colleague’s display name does not automatically make a request genuine.

6. Control user access and administrator privileges

Employees should have access only to the systems and information required for their role.

Review access when somebody joins, changes role or leaves the business. Former employees, unused accounts and forgotten third-party access can create unnecessary risk.

Administrator accounts should be kept separate from ordinary day-to-day accounts. A user who needs elevated permissions occasionally should not browse the web and read email while permanently signed in as an administrator.

Regularly review:

  • Microsoft 365 administrators
  • Access to shared files and mailboxes
  • Remote-access accounts
  • Third-party suppliers with system access
  • Inactive and unlicensed user accounts

7. Protect and monitor business devices

Every computer, laptop and mobile device connected to business systems should have an appropriate level of protection.

This normally includes:

  • Endpoint security or endpoint detection and response
  • Automatic security updates
  • Device encryption
  • Automatic screen locking
  • Restrictions on unapproved software
  • Central monitoring for security alerts and device health
  • The ability to lock or wipe lost mobile devices where appropriate

Traditional anti-virus remains useful, but businesses should also consider how suspicious behaviour is detected, investigated and contained. A security alert provides little value if nobody is responsible for responding to it.

8. Back up important data and test recovery

Backups help a business recover from accidental deletion, hardware failure, ransomware and other disruptive incidents.

Identify which information the business could not operate without, then confirm:

  • Which systems and data are backed up
  • How frequently backups run
  • How long backup copies are retained
  • Who receives and investigates failed-backup alerts
  • Whether backup administration uses separate credentials
  • Whether a compromised administrator can delete every backup copy
  • How frequently restoration is tested

Do not assume that information held in Microsoft 365 or another cloud service automatically meets your backup and retention requirements. Confirm what the platform retains, what your separate backup service protects and how information would actually be restored.

9. Secure networks, Wi-Fi and remote access

Internet connections and internal networks should be protected by properly configured firewalls and supported networking equipment.

Practical measures include:

  • Change default router and firewall passwords
  • Keep network equipment updated
  • Use modern Wi-Fi encryption
  • Separate guest Wi-Fi from the main business network
  • Disable services and ports that are not required
  • Protect remote access with MFA
  • Avoid exposing remote-management services directly to the internet
  • Review access when remote workers or contractors leave

Businesses with several locations or remote sites should also consider connection resilience. A secondary connection or failover service can reduce operational disruption if the primary connection fails.

10. Train employees and make reporting easy

Employees should receive practical guidance that reflects the risks they encounter in their actual work.

Training should cover:

  • How to recognise suspicious emails and login pages
  • How payment and bank-detail fraud works
  • How to report a suspicious message
  • What to do after clicking a suspicious link
  • How business information should be stored and shared
  • How to handle lost or stolen devices
  • Why MFA prompts should not be approved automatically

Create a culture in which employees report mistakes quickly rather than hiding them. Early reporting can give the IT or security team time to reset credentials, isolate a device or investigate suspicious activity before more damage occurs.

11. Create a cyber incident response plan

A cyber incident is much harder to manage when roles and contact details are being decided during the emergency.

A basic response plan should identify:

  • Who has authority to make urgent decisions
  • Who will contact the IT or cyber security provider
  • How affected accounts or devices will be isolated
  • How the business will operate if systems are unavailable
  • Where insurer, legal adviser and supplier details are stored
  • How customers, employees or regulators may need to be informed
  • Who will preserve evidence and record decisions

Keep a copy of the plan somewhere accessible even if normal business systems are unavailable. Test it with a realistic scenario, such as a compromised Microsoft 365 account, ransomware infection or complete loss of internet connectivity.

The NCSC provides a dedicated small business response and recovery guide.

12. Work towards Cyber Essentials and review security regularly

Cyber Essentials is a UK Government-backed scheme designed to help organisations protect themselves against common cyber attacks.

Its core technical controls cover:

  • Firewalls
  • Secure configuration
  • Security update management
  • User access control
  • Malware protection

Certification can provide a useful baseline, demonstrate that the business takes security seriously and may be required for certain contracts or supply-chain relationships.

Learn more through the official Cyber Essentials overview.

Cyber security should not be treated as a one-off project. Review controls following major technology changes, new suppliers, office moves, security incidents and changes in the way employees work.

What should a small business prioritise first?

If the whole checklist cannot be completed immediately, begin with the controls that reduce the most common risks:

  1. Enable MFA for email, administrators and important cloud services
  2. Install outstanding security updates
  3. Confirm important data is backed up and can be restored
  4. Remove unused accounts and unnecessary administrator access
  5. Protect business devices with centrally monitored security software
  6. Give employees a clear way to report suspicious activity

These steps provide a practical foundation while the business works through the remaining controls.

How Secure IT can help

Secure IT helps businesses manage day-to-day IT support, device security, patching, monitoring, Microsoft 365, email protection, backups and wider cyber security requirements.

The right approach depends on the size of your business, the information you hold, the systems you depend on and the controls already in place.

Contact the Secure IT team to discuss your current setup, the areas you are concerned about and the practical improvements that should be prioritised.

Frequently asked questions

Do small businesses really need cyber security?

Yes. Small businesses depend on email, cloud accounts, payment systems and customer information just as larger organisations do. Even a relatively simple account compromise can disrupt operations, expose information or enable fraudulent payments.

What is the most important cyber security measure?

No single control removes every risk. However, enabling MFA, installing security updates, maintaining recoverable backups and controlling administrator access provide a strong starting point.

Is anti-virus enough for a small business?

No. Endpoint protection is important, but it should form part of a wider approach that includes updates, MFA, email security, backups, access control, employee awareness and incident response.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials uses a verified self-assessment covering the scheme’s technical controls. Cyber Essentials Plus assesses the same controls but includes independent technical testing of the organisation’s systems.

How often should cyber security be reviewed?

Core controls should be monitored continuously, with a structured review at least annually and whenever the business makes a significant change to its systems, suppliers, workforce or locations.

Cyber security works best as an ongoing business process

The purpose of cyber security is not to make ordinary work unnecessarily difficult. It is to reduce avoidable risks, detect suspicious activity earlier and give the business a realistic route to recovery when something goes wrong.

Start with the essentials, assign clear responsibility and improve the controls over time. A well-managed set of practical measures is more valuable than a collection of security products that nobody monitors or understands.

Share this guide

Looking for a better way to manage your IT?

Whether you need day-to-day IT support, stronger cyber security or help with a specific project, tell us what you’re looking to improve. We’ll arrange a straightforward conversation with the right person.