Five cybersecurity basics every UK business should have in place
The majority of incidents affecting smaller organisations exploit gaps that cost little to close.
Security advice can feel endless. For most UK businesses, five controls cover the large majority of realistic risk, and they line up closely with the government-backed Cyber Essentials scheme. If you do nothing else this quarter, do these.
1. Multi-factor authentication everywhere
Passwords leak. Multi-factor authentication (MFA) means a leaked password alone is not enough to get in. Turn it on for email, cloud platforms, remote access and any admin account, with no exceptions for senior staff.
2. Patch on a schedule
Operating systems, browsers, office software and network equipment all need updates. Automate what you can, and have a monthly check for what you cannot. Unsupported software should be replaced, not tolerated.
3. Least-privilege access
Nobody should use an administrator account for daily work. Shared logins should be eliminated. When someone leaves, access is removed the same day. This is as much about process as technology.
4. Backups you have actually restored
A backup that has never been tested is a hope, not a plan. Keep at least one copy that is offline or immutable, so ransomware cannot encrypt it too, and restore something from it every quarter.
5. Staff who know what to do
Most attacks start with a message. Short, regular awareness sessions and a clear "report it, don't guess" policy turn your team into a detection layer rather than the weakest link.
A useful next step
Cyber Essentials certification takes these controls and gives you an independent tick against them. It is increasingly asked for in supplier questionnaires and tenders, and it is a sensible target for any business handling customer data.
Our security risk assessment maps your current position against these five areas and produces a prioritised plan.