Field guide · 2026 edition

Cyber security a small business can actually keep up with

A practical UK guide for small offices, businesses with staff and home users. What changed in 2026, what matters most, and the exact order to do it in. Written by the engineers at Verge Tech.

No email needed 15 min read UK sources, checked Aug 2026
43%
of UK businesses hit by a breach or attack in the last year
~612k
UK businesses affected over the year
28%
of UK charities hit in the same period
#1
Phishing is still the most common way in

Source: UK Government Cyber Security Breaches Survey 2025/2026.

If you only do five things

  1. 1Turn on multi-factor sign-in, or passkeys, for every email and cloud account. Email is the master key to everything else.
  2. 2Put a password manager in place so every account has its own long password and nobody reuses one.
  3. 3Let devices update themselves. Operating system, browser, apps and your router. Most attacks use a hole a patch already fixed.
  4. 4Get one backup you can restore from that an attacker cannot reach or encrypt, and test a restore.
  5. 5No payment or bank detail changes on an email alone. Always confirm by phone on a number you already had.

Where the risk is now

The short version: most attacks are not clever. Someone is tricked into handing over a password, the attacker signs in, and the damage follows. Everything here aims at breaking that chain.

The UK government's Cyber Security Breaches Survey 2025/2026 found 43% of businesses and 28% of charities had a breach or attack in the previous 12 months, about 612,000 businesses. The NCSC is consistent that smaller organisations are targeted often, usually by automated attacks that do not care how big you are. Phishing is still the most common route in. What changed is speed and polish, because attackers now use AI to write convincing messages and clone voices.

A TYPICAL ATTACK, LEFT TO RIGHTPhishingemailPasswordhanded overAttackersigns inSpreads tomore accountsRansomwareor fraudPassword manager:no reuse, spots fake sitesMFA / passkeys:sign-in fails without the deviceTested backups:recover without paying
Most incidents follow this path. Each control below the line breaks a different link, which is why layering them matters more than perfecting any single one.

What changed in 2026

Four updates worth knowing about, with dates so you can check them yourself.

Cyber Essentials updated to v3.3

The NCSC's Requirements for IT Infrastructure v3.3 (April 2026) formally includes FIDO2 and passkeys in the passwordless definition, states that eligible cloud services cannot be left out of scope, and puts more weight on patching timelines and backups. The current question set is named "Danzell" for assessment accounts created from 27 April 2026.

NCSC now recommends passkeys first

In April 2026 the NCSC said plainly that people should choose passkeys where a service supports them, and fall back to a password manager plus two-step verification where they do not. A passkey cannot be phished, because there is no code to read out or type into a fake page.

The regulator has raised the alarm on AI-assisted attacks

ICO guidance from May 2026 highlights AI-enhanced phishing, deepfake social engineering and faster exploitation of weaknesses. The ICO is clear this is a present duty under UK GDPR Article 32, not a future one.

Smart devices must meet a UK security baseline

Since 29 April 2024 the Product Security regime has required consumer connected products to ship without universal default passwords and to state how long they will get security updates. Check that support window before you buy.

Know your risk profile

The controls are similar across all three groups. The order of priority is not.

SMALL OFFICEWITH STAFFHOMEPhishing & fake invoicesReused / weak passwordsUnpatched laptops & routersRansomware via remote accessStolen login used across systemsSupplier / third-party compromiseScam calls, texts & fake support
Filled dot = high exposure, ring = worth planning for, faint dot = lower. Green marks the risks that grow sharply once you have staff and shared systems.

Small office and home office

Little or no dedicated IT help, heavy reliance on cloud email and file sharing, and one compromised account can stop the business. The classic hits are phishing, reused passwords across web apps, unpatched laptops and routers, and fake supplier invoices.

Businesses with staff

A mix of cloud and on-site systems, several teams, and more personal data. The added risks are a stolen login being used to move between systems, ransomware through remote access, misconfigured cloud settings, and problems arriving through a supplier.

Home users

Many online accounts, mostly used from a phone, plus shared family devices and smart-home kit. The main risks are reused passwords being tried automatically, scam calls and texts, and takeover of a main email account, which is the recovery route for everything else.

The baseline everyone needs

Nine controls that apply whether you are one person or fifty.

YOUR DATATested offline / immutable backupsPatched & encrypted devices, least privilegeIdentity: passkeys / MFA, password managerTrained people + a way to report a suspicious messageA written response plan, kept offline
Each layer buys time when the one outside it fails. Backups are the layer that still works even if an attacker gets all the way in, which is why they have to be genuinely out of reach.
ControlWhat good looks like
Phishing-resistant sign-inPasskeys or FIDO2 keys where supported. Multi-factor or two-step verification on every important account otherwise.
Password hygieneA password manager, a unique password per service, no shared logins where you can avoid them.
Patching disciplineAutomatic updates on for operating systems, browsers, apps and firmware. High-risk fixes applied quickly.
Endpoint hardeningDisk encryption on, modern endpoint protection, no everyday admin rights, screen lock enforced.
Tested backupsAt least one copy an attacker cannot reach or encrypt. Restores tested on a schedule, not assumed.
Least privilegePeople get only the access they need. Admin rights are time-limited and reviewed.
Secure cloud settingsSign-in enforcement, conditional access, sharing limits and logging checked in your Microsoft 365 or Google Workspace tenant.
An anti-phishing processA one-click way to report a suspicious email, mailbox protection on, and the odd practice run.
Response readinessNamed contacts, agreed priorities and first-hour actions, with a printed copy kept offline.

Our Cyber Essentials checklist maps these onto the certification if you plan to get certified.

If you run a small or one-person business

Sole traders, micro businesses and partnerships. Keep the setup simple, and keep it locked down.

Target setup: a cloud productivity suite, a cloud backup with version history, managed security on every work device, a password manager, and a firm rule that payments need a second check.

The 14-day quick start

  1. Days 1–2List every account, device and cloud service. Turn on multi-factor everywhere. Reset weak or reused passwords in the password manager.
  2. Days 3–5Force automatic updates on all devices. Turn on endpoint and ransomware protection. Review sharing and public links.
  3. Days 6–8Set backup policies and retention. Restore three real files and one full device image. Write down how long it took.
  4. Days 9–11Write your invoice-fraud and phishing procedure. Train everyone on the payment verification rule.
  5. Days 12–14Talk through a "phishing leads to account takeover" scenario out loud. Note the gaps and fix them.

Track these each month

  • Share of accounts with multi-factor or a passkey, and share of devices fully patched.
  • Whether the last restore test worked, and how long it took.
  • Number of suspicious emails reported, and open high-severity issues with their age.

If you have employees and IT systems

More people and more data means the plan needs owners, a routine, and detection, not just controls.

Who owns what

  • Senior leadership: cyber risk overall, how much risk is acceptable, and the budget.
  • IT or security lead: putting controls in place, monitoring, and leading an incident.
  • Data protection lead: personal-data safeguards, impact assessments, breach reporting.
  • Team managers: risk in their own process: finance, operations, HR, customer service.

Run a monthly risk review, a quarterly recovery test, and an annual strategic review with an outside check.

Technical baseline

  • Multi-factor for all users, all admins and all remote access. Extra protection on privileged accounts.
  • Central endpoint policy. Separate network zones for staff, servers, management and guest or smart devices.
  • SPF, DKIM and DMARC set up and monitored. Safe-link and attachment checks on.
  • Collect logs from sign-in, devices, email, firewall and cloud in one place. Alert on impossible travel, mass downloads and privilege changes.
  • An asset list with an owner for each item. A patch deadline based on risk. Regular authenticated scans.
  • Recovery targets per business service. Backup logins kept separate from normal logins. Restore drills for whole systems, not only files.

A 90-day hardening plan

  1. Phase 1See what you have. Confirm the asset list, the identity baseline, and whether you can actually recover from backup today.
  2. Phase 2Cut the biggest risks. Clear the critical patch backlog, tighten remote access and least privilege, strengthen anti-phishing controls.
  3. Phase 3Build resilience. Centralise the key logs, run a tabletop and a real recovery drill, put a readiness report to the board.

NCSC guidance is clear that you should check your backups are clean before you restore from them. Keep a short playbook for each of: phishing-led account compromise, ransomware, payment fraud, suspected data theft, and a supplier being compromised.

If you want to protect your home

Protect the email account first, then the devices, then the network.

  • Use passkeys where a service offers them. Where they are not available, use a password manager plus two-step verification.
  • Lock down your main email account first. It is the reset route for everything else. Remove old recovery numbers and devices you do not recognise.
  • Keep phones, tablets, laptops, smart TVs and consoles updated. Use a screen lock and device encryption. Install apps only from official stores.
  • Change the router admin password straight away. Use WPA2 or WPA3 with a unique passphrase. Turn off remote management you do not use. Replace a router that no longer gets updates.
  • Put smart-home devices on a separate guest network. Avoid devices close to the end of their update support.
  • Teach the scam red flags: urgency, pressure to pay, secrecy, odd links. Agree that any unexpected bank or support call gets ended and called back on a known number.

Ransomware and recovery

The rule that matters: do not rush the restore. Rebuilding from a backup that is still infected, or before you understand how they got in, is how businesses get hit twice.
FIRST 60 MINUTES1 · Isolatedevices off network2 · Preservekeep evidence3 · Escalateroles + contacts4 · Check backupsare actually clean5 · Rebuildonly nowThen: reset credentials widely, watch for the attacker returning, and hold a lessons-learned review.
Steps 1 to 4 come before any restore. Validating the backup is the checkpoint that stops a second, worse incident.

Plain-English glossary

TermWhat it means
PasskeyA sign-in method tied to your phone or laptop that replaces the password. It cannot be phished because there is no code to steal.
FIDO2The open standard behind passkeys and physical security keys.
MFA / 2SVMulti-factor authentication, or two-step verification. A second proof of identity on top of the password.
Password managerAn app that creates and stores a unique strong password for every account, so you only remember one.
Endpoint protection / EDRSecurity software on a device that blocks and reports attacks. EDR adds detection and investigation tools.
Immutable backupA backup that cannot be changed or deleted for a set period, so ransomware cannot destroy it.
Cyber EssentialsA UK government-backed certification covering five basic security controls. Plus adds a hands-on technical check.
SPF, DKIM, DMARCEmail settings that prove a message really came from your domain and make it harder to impersonate you.
Lateral movementAn attacker using one compromised account or device to reach others inside the same organisation.
Business email compromiseFraud where an attacker uses a real or spoofed email account to redirect a payment or invoice.

Frequently Asked Questions

What is the single most important thing a small business can do?
Turn on multi-factor sign-in, or passkeys, for every email and cloud account. Email is the reset route for everything else, so protecting it first stops one stolen password turning into a full compromise.
Are passkeys really better than a password with two-step verification?
Yes. In April 2026 the NCSC recommended passkeys as the first choice wherever a service supports them. A passkey cannot be phished because there is no code to read out or type into a fake page. Where passkeys are not available, use a password manager plus two-step verification.
What is Cyber Essentials and do I need it?
Cyber Essentials is a UK government-backed certification covering five basic security controls. Cyber Essentials Plus adds a hands-on technical check. It is a sensible baseline and a clear signal to customers and insurers. The technical requirements were updated to v3.3 in April 2026.
How often should backups be tested?
Test a restore of a few real files every month, and a full system or device recovery at least once a quarter. A backup you have never restored from is an assumption, not a safety net.
What should you do first in a ransomware attack?
Isolate affected devices from the network, preserve evidence, and trigger your response contacts. Then check that your backups are clean before you restore anything. NCSC guidance is clear that rushing the restore risks a second, worse incident.
Does the guide cost anything?
No. The full guide is a free PDF with no email signup. Read it online or download it and share it with your team.

Take the whole thing with you

The full guide as a PDF, with the checklists, the 14-day and 90-day plans and the response steps. No email needed.

Download the guide (PDF)

How Verge Tech helps

We are a team of senior engineers based near Slough, working across London, Berkshire and Surrey. Verge Tech Solutions has run since 2018. Our engineers are Microsoft and CompTIA certified, and one named engineer owns your account from start to finish. Most small businesses do not need a full-time IT person. They need this done once, properly, then kept running.

Written by

Noman Maqsood (Nomi)

Senior IT Engineer, Verge Tech Solutions

Sources: UK Government Cyber Security Breaches Survey 2025/2026; NCSC Cyber Essentials Requirements v3.3; NCSC guidance on passkeys and on recovering from cyber attacks; ICO guidance on AI-powered cyber threats (May 2026); GOV.UK Product Security regime; NIST and CISA small business guidance. Full links in the PDF. This is practical guidance, not legal advice. Checked 28 August 2026.

Get help today

Want us to set this up and keep it running?

We cover London, Berkshire and Surrey, remote or on-site.

Microsoft & CompTIA Certified
4.9★ Google Rated
020 3376 1140

We use analytics cookies to see which pages help visitors, so we know what to improve. We only set them if you accept. Read our privacy policy.

WhatsApp

Message an engineer

Start with a common issue

Open WhatsApp chat