Cyber security a small business can actually keep up with
A practical UK guide for small offices, businesses with staff and home users. What changed in 2026, what matters most, and the exact order to do it in. Written by the engineers at Verge Tech.
Source: UK Government Cyber Security Breaches Survey 2025/2026.
If you only do five things
- 1Turn on multi-factor sign-in, or passkeys, for every email and cloud account. Email is the master key to everything else.
- 2Put a password manager in place so every account has its own long password and nobody reuses one.
- 3Let devices update themselves. Operating system, browser, apps and your router. Most attacks use a hole a patch already fixed.
- 4Get one backup you can restore from that an attacker cannot reach or encrypt, and test a restore.
- 5No payment or bank detail changes on an email alone. Always confirm by phone on a number you already had.
Where the risk is now
The UK government's Cyber Security Breaches Survey 2025/2026 found 43% of businesses and 28% of charities had a breach or attack in the previous 12 months, about 612,000 businesses. The NCSC is consistent that smaller organisations are targeted often, usually by automated attacks that do not care how big you are. Phishing is still the most common route in. What changed is speed and polish, because attackers now use AI to write convincing messages and clone voices.
What changed in 2026
Four updates worth knowing about, with dates so you can check them yourself.
Cyber Essentials updated to v3.3
The NCSC's Requirements for IT Infrastructure v3.3 (April 2026) formally includes FIDO2 and passkeys in the passwordless definition, states that eligible cloud services cannot be left out of scope, and puts more weight on patching timelines and backups. The current question set is named "Danzell" for assessment accounts created from 27 April 2026.
NCSC now recommends passkeys first
In April 2026 the NCSC said plainly that people should choose passkeys where a service supports them, and fall back to a password manager plus two-step verification where they do not. A passkey cannot be phished, because there is no code to read out or type into a fake page.
The regulator has raised the alarm on AI-assisted attacks
ICO guidance from May 2026 highlights AI-enhanced phishing, deepfake social engineering and faster exploitation of weaknesses. The ICO is clear this is a present duty under UK GDPR Article 32, not a future one.
Smart devices must meet a UK security baseline
Since 29 April 2024 the Product Security regime has required consumer connected products to ship without universal default passwords and to state how long they will get security updates. Check that support window before you buy.
Know your risk profile
The controls are similar across all three groups. The order of priority is not.
Small office and home office
Little or no dedicated IT help, heavy reliance on cloud email and file sharing, and one compromised account can stop the business. The classic hits are phishing, reused passwords across web apps, unpatched laptops and routers, and fake supplier invoices.
Businesses with staff
A mix of cloud and on-site systems, several teams, and more personal data. The added risks are a stolen login being used to move between systems, ransomware through remote access, misconfigured cloud settings, and problems arriving through a supplier.
Home users
Many online accounts, mostly used from a phone, plus shared family devices and smart-home kit. The main risks are reused passwords being tried automatically, scam calls and texts, and takeover of a main email account, which is the recovery route for everything else.
The baseline everyone needs
Nine controls that apply whether you are one person or fifty.
| Control | What good looks like |
|---|---|
| Phishing-resistant sign-in | Passkeys or FIDO2 keys where supported. Multi-factor or two-step verification on every important account otherwise. |
| Password hygiene | A password manager, a unique password per service, no shared logins where you can avoid them. |
| Patching discipline | Automatic updates on for operating systems, browsers, apps and firmware. High-risk fixes applied quickly. |
| Endpoint hardening | Disk encryption on, modern endpoint protection, no everyday admin rights, screen lock enforced. |
| Tested backups | At least one copy an attacker cannot reach or encrypt. Restores tested on a schedule, not assumed. |
| Least privilege | People get only the access they need. Admin rights are time-limited and reviewed. |
| Secure cloud settings | Sign-in enforcement, conditional access, sharing limits and logging checked in your Microsoft 365 or Google Workspace tenant. |
| An anti-phishing process | A one-click way to report a suspicious email, mailbox protection on, and the odd practice run. |
| Response readiness | Named contacts, agreed priorities and first-hour actions, with a printed copy kept offline. |
Our Cyber Essentials checklist maps these onto the certification if you plan to get certified.
If you run a small or one-person business
Sole traders, micro businesses and partnerships. Keep the setup simple, and keep it locked down.
The 14-day quick start
- Days 1–2List every account, device and cloud service. Turn on multi-factor everywhere. Reset weak or reused passwords in the password manager.
- Days 3–5Force automatic updates on all devices. Turn on endpoint and ransomware protection. Review sharing and public links.
- Days 6–8Set backup policies and retention. Restore three real files and one full device image. Write down how long it took.
- Days 9–11Write your invoice-fraud and phishing procedure. Train everyone on the payment verification rule.
- Days 12–14Talk through a "phishing leads to account takeover" scenario out loud. Note the gaps and fix them.
Track these each month
- Share of accounts with multi-factor or a passkey, and share of devices fully patched.
- Whether the last restore test worked, and how long it took.
- Number of suspicious emails reported, and open high-severity issues with their age.
If you have employees and IT systems
More people and more data means the plan needs owners, a routine, and detection, not just controls.
Who owns what
- Senior leadership: cyber risk overall, how much risk is acceptable, and the budget.
- IT or security lead: putting controls in place, monitoring, and leading an incident.
- Data protection lead: personal-data safeguards, impact assessments, breach reporting.
- Team managers: risk in their own process: finance, operations, HR, customer service.
Run a monthly risk review, a quarterly recovery test, and an annual strategic review with an outside check.
Technical baseline
- Multi-factor for all users, all admins and all remote access. Extra protection on privileged accounts.
- Central endpoint policy. Separate network zones for staff, servers, management and guest or smart devices.
- SPF, DKIM and DMARC set up and monitored. Safe-link and attachment checks on.
- Collect logs from sign-in, devices, email, firewall and cloud in one place. Alert on impossible travel, mass downloads and privilege changes.
- An asset list with an owner for each item. A patch deadline based on risk. Regular authenticated scans.
- Recovery targets per business service. Backup logins kept separate from normal logins. Restore drills for whole systems, not only files.
A 90-day hardening plan
- Phase 1See what you have. Confirm the asset list, the identity baseline, and whether you can actually recover from backup today.
- Phase 2Cut the biggest risks. Clear the critical patch backlog, tighten remote access and least privilege, strengthen anti-phishing controls.
- Phase 3Build resilience. Centralise the key logs, run a tabletop and a real recovery drill, put a readiness report to the board.
NCSC guidance is clear that you should check your backups are clean before you restore from them. Keep a short playbook for each of: phishing-led account compromise, ransomware, payment fraud, suspected data theft, and a supplier being compromised.
If you want to protect your home
Protect the email account first, then the devices, then the network.
- Use passkeys where a service offers them. Where they are not available, use a password manager plus two-step verification.
- Lock down your main email account first. It is the reset route for everything else. Remove old recovery numbers and devices you do not recognise.
- Keep phones, tablets, laptops, smart TVs and consoles updated. Use a screen lock and device encryption. Install apps only from official stores.
- Change the router admin password straight away. Use WPA2 or WPA3 with a unique passphrase. Turn off remote management you do not use. Replace a router that no longer gets updates.
- Put smart-home devices on a separate guest network. Avoid devices close to the end of their update support.
- Teach the scam red flags: urgency, pressure to pay, secrecy, odd links. Agree that any unexpected bank or support call gets ended and called back on a known number.
Ransomware and recovery
Plain-English glossary
| Term | What it means |
|---|---|
| Passkey | A sign-in method tied to your phone or laptop that replaces the password. It cannot be phished because there is no code to steal. |
| FIDO2 | The open standard behind passkeys and physical security keys. |
| MFA / 2SV | Multi-factor authentication, or two-step verification. A second proof of identity on top of the password. |
| Password manager | An app that creates and stores a unique strong password for every account, so you only remember one. |
| Endpoint protection / EDR | Security software on a device that blocks and reports attacks. EDR adds detection and investigation tools. |
| Immutable backup | A backup that cannot be changed or deleted for a set period, so ransomware cannot destroy it. |
| Cyber Essentials | A UK government-backed certification covering five basic security controls. Plus adds a hands-on technical check. |
| SPF, DKIM, DMARC | Email settings that prove a message really came from your domain and make it harder to impersonate you. |
| Lateral movement | An attacker using one compromised account or device to reach others inside the same organisation. |
| Business email compromise | Fraud where an attacker uses a real or spoofed email account to redirect a payment or invoice. |
Frequently Asked Questions
What is the single most important thing a small business can do?
Are passkeys really better than a password with two-step verification?
What is Cyber Essentials and do I need it?
How often should backups be tested?
What should you do first in a ransomware attack?
Does the guide cost anything?
Take the whole thing with you
The full guide as a PDF, with the checklists, the 14-day and 90-day plans and the response steps. No email needed.
Download the guide (PDF)How Verge Tech helps
We are a team of senior engineers based near Slough, working across London, Berkshire and Surrey. Verge Tech Solutions has run since 2018. Our engineers are Microsoft and CompTIA certified, and one named engineer owns your account from start to finish. Most small businesses do not need a full-time IT person. They need this done once, properly, then kept running.
Written by
Noman Maqsood (Nomi)
Senior IT Engineer, Verge Tech Solutions
Sources: UK Government Cyber Security Breaches Survey 2025/2026; NCSC Cyber Essentials Requirements v3.3; NCSC guidance on passkeys and on recovering from cyber attacks; ICO guidance on AI-powered cyber threats (May 2026); GOV.UK Product Security regime; NIST and CISA small business guidance. Full links in the PDF. This is practical guidance, not legal advice. Checked 28 August 2026.
Get help today
Want us to set this up and keep it running?
We cover London, Berkshire and Surrey, remote or on-site.