Key takeaways
- Small businesses are attractive targets because attackers expect weaker defences.
- Multi-factor authentication, prompt updates and tested backups stop a large share of common attacks.
- Protect email with filtering and domain authentication (SPF, DKIM and DMARC) to reduce phishing and invoice fraud.
- Train staff to recognise and report suspicious messages, and have an incident response plan ready.
- In the UK, the government-backed Cyber Essentials scheme is a good baseline to work towards.
Cybersecurity for small businesses means putting practical, affordable controls in place to protect your devices, accounts, data and people from threats such as phishing, ransomware and fraud. You do not need an enterprise budget to be well protected. A handful of well-chosen measures, applied consistently, block most of the attacks small businesses face.
Why small businesses are targeted
Many cyber attacks are automated and opportunistic. Criminals scan the internet and send phishing emails at scale, looking for easy wins: unpatched systems, reused passwords and staff who have not been trained to spot scams. Smaller organisations often lack dedicated security staff, which makes them attractive targets, and a single incident can cause serious disruption, financial loss and reputational damage.
10 essential cybersecurity protections
1. Turn on multi-factor authentication (MFA)
MFA requires a second proof of identity, such as an app prompt, in addition to a password. Enable it on email, Microsoft 365 or Google Workspace, banking, cloud services and remote access. It is one of the most effective protections against stolen passwords.
2. Keep software and devices updated
Install security updates for operating systems, browsers and applications promptly, and replace devices that no longer receive updates. Many attacks exploit known vulnerabilities that already have fixes available.
3. Use endpoint protection on every device
Install reputable, centrally managed antivirus or endpoint detection and response (EDR) on laptops, desktops and servers, and make sure it is active and updating.
4. Back up your data and test restores
Follow the 3-2-1 rule: keep three copies of important data, on two different types of storage, with one copy off-site or offline. Test restores regularly, because a backup you cannot restore is not a backup.
5. Secure your email
Use email filtering to block malicious messages, and configure SPF, DKIM and DMARC on your domain so criminals find it harder to send emails pretending to be you.
Not sure how secure your business is?
Ignite System offers practical security audits and ongoing protection with 24/7 monitoring.
6. Use a password manager
Password managers make it easy to use long, unique passwords for every account. Combined with MFA, they dramatically reduce the risk of account takeover.
7. Limit admin access
Give people only the access they need to do their jobs. Staff should not use administrator accounts for everyday work, and accounts should be removed promptly when someone leaves.
8. Protect your network
Use a properly configured business firewall, change default passwords on routers and devices, separate guest Wi-Fi from your business network and use a secure VPN or modern zero-trust access for remote working.
9. Train your staff
People are your first line of defence. Short, regular training helps staff recognise phishing, fake invoices and suspicious requests, and makes it normal to report mistakes quickly.
10. Prepare an incident response plan
Decide in advance who to call, how to isolate affected systems, how to communicate with staff and customers and how to restore from backups. A simple, written plan saves vital time.
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification scheme, run with the National Cyber Security Centre (NCSC), that helps organisations protect themselves against common cyber attacks. It focuses on five technical controls:
- firewalls;
- secure configuration;
- user access control;
- malware protection;
- security update management.
Certification can also help you win contracts, as some customers and public sector buyers require it. The ten protections above will put you in a strong position to meet these controls.
What to do if you are attacked
- Disconnect affected devices from the network, but do not switch them off if you can avoid it.
- Contact your IT or security provider immediately.
- Reset passwords for affected accounts from a clean device and check MFA settings.
- Report the incident. In the UK, cybercrime can be reported to Action Fraud, or Police Scotland in Scotland.
- If personal data is affected and the breach is likely to pose a risk to people, you may need to report it to the Information Commissioner’s Office (ICO) within 72 hours.
- Restore systems from clean backups and fix the weakness that allowed the attack.
Want to see how security fits into a wider IT plan? Read what managed IT services include.
Frequently asked questions
There is no single fix, but multi-factor authentication on email and cloud accounts is one of the most effective and affordable steps, especially when combined with updates, backups and staff training.
It depends on your size, data and risk. Many essential protections, such as MFA, updates and password managers, cost little or nothing. A security audit helps you prioritise spending where it reduces the most risk.
No. Antivirus is important, but most attacks start with phishing or stolen passwords. You also need MFA, email security, updates, backups and trained staff.
It is not a legal requirement for most businesses, but it is a strong baseline for security and is required for some government contracts and by some customers.
Want a clear picture of your security? Request a free consultation with Ignite System.



