Take it with you
8 chapters · about 20 minutes · 1,550 words. Free, no sign-up.
Most cyber attacks on small businesses are not clever or targeted. They are ordinary, automated, and opportunistic, and they succeed because a basic step was missing. That is genuinely good news, because it means a handful of straightforward habits will put you ahead of the risk that most small firms carry every day.
You do not need to be technical to follow this guide, and you do not need a big budget. What you need is a short list of the right things done consistently. This guide walks through them in the order we would tackle them ourselves.
Chapter 1
Phishing and scam emails

Phishing is a scam email that pretends to be someone you trust, such as Microsoft, your bank, or a supplier you deal with every week. The goal is simple: get you to click a link, open an attachment, or type your password into a fake page. It is the most common way a business gets breached.
The design is rarely the giveaway, because logos and layouts are easy to copy. The clues are usually in the sender address and the link. On a computer, hover over a link to see where it really goes before you click. On a phone, press and hold to preview it.
Urgency is a tactic, not a coincidence. That pressure is there to stop you checking. A real provider will not close your account because you took an hour to think.
Quick checklist
- Hover over or long-press links to check the real destination before clicking
- Treat urgency and threats as a warning sign, not a reason to hurry
- Reach login pages by typing the address yourself, never through an emailed link
- Confirm unexpected attachments with the sender using a contact you already hold
Chapter 2
Passwords and a password manager

The two biggest problems are passwords that are simple to guess and the same password reused across many sites. When one website is breached, attackers try those leaked passwords everywhere else, so one small leak becomes a big problem.
Length beats complexity. A long passphrase made of a few random words is stronger and easier to remember than a short jumble of symbols. The NCSC advice of three random words is a good, human way to build one.
The honest reason people reuse passwords is that nobody can remember dozens of unique ones. A password manager solves exactly that, and you only need to recall one master password.
Quick checklist
- Give your email, banking and main business logins their own unique passwords
- Build strong passwords from three random words rather than short symbol jumbles
- Set up a reputable password manager and let it generate and store your logins
- Change a password promptly if you suspect it has leaked, rather than on a timer
Chapter 3
Multi-factor authentication

Multi-factor authentication adds a second proof of who you are, usually a code or a tap on your phone, on top of your password. Even if a scammer steals your password, they are stopped at that second step, which blocks the large majority of account takeovers.
Not all methods are equal. An authenticator app or a physical security key is stronger than a code sent by text, because text messages can be intercepted or redirected. A text code is still far better than no second factor.
Start with email, banking, your Microsoft 365 or Google account, and any tool holding customer or payment data. Save the backup codes somewhere safe so a lost phone does not lock you out.
Quick checklist
- Turn it on for email, banking and key business accounts first
- Prefer an authenticator app or security key over text-message codes
- Save your recovery codes somewhere safe and separate from your phone
- Never approve a prompt you did not trigger, and change that password if one appears
Chapter 4
Backups that actually restore

If a fire, a theft, a failed drive or a ransomware attack wiped your systems this afternoon, a good backup is the difference between a bad day and a closed business. For most small firms the real damage is the days of downtime, not the ransom.
A simple, trusted approach is the 3-2-1 rule. Keep three copies of important data, on two different types of storage, with one kept off site or offline. Never let a single event destroy every copy at once.
The step almost everyone skips is testing. A backup you have never restored from is only a hope. Every so often, actually retrieve a file and check it opens.
Quick checklist
- Keep three copies, on two types of storage, one off site or offline
- Make sure at least one backup cannot be reached and altered from your main systems
- Include email, accounts and customer records, not just documents
- Test a real restore regularly, so you know it works before you need it
Chapter 5
Keeping software updated

Many attacks rely on known weaknesses that the maker has already fixed. When you install an update you are usually closing a door that attackers already know how to walk through.
This applies to everything: operating systems, browsers, phones, business software, and the firmware on your router and other network kit. Automatic updates are the most reliable approach, because they do not depend on anyone remembering.
It is also worth knowing when a product stops receiving updates altogether. Once something reaches the end of its supported life, new weaknesses are found but never fixed.
Quick checklist
- Turn on automatic updates on computers, phones, browsers and business software
- Include your router, firewall and other network devices
- Restart devices when asked, so pending fixes actually finish installing
- Replace software and hardware that no longer receives security updates
Chapter 6
Staff awareness and a simple rule for money

Your team is not the weak link, they are your best early-warning system once they know what to look for. A short, blame-free conversation about the scams in this guide does more than any single piece of software.
Build a culture where checking is normal and encouraged. Staff should feel safe to pause, ask a colleague, or call a number back to verify, and to report a mistake quickly without fear of being told off.
The costliest scam a small business faces is payment redirection. The defence is a simple, firm rule: any change of bank details, or any payment over a set amount, needs a second person to approve and a verbal confirmation on a number you already hold.
Quick checklist
- Talk through common scams with your team, without blame, and repeat it now and then
- Make it safe and quick to report a suspected mistake, so problems surface early
- Require a second approver and a call-back on a known number for bank-detail changes
- Verify any urgent or unusual payment request by trusted phone before paying
Chapter 7
What to do if the worst happens

Even careful businesses have incidents, so it helps to decide in advance roughly what you will do. The aim in the first hour is to contain the problem and start recovery, not to assign blame.
If an account may be compromised, change its password from a device you trust and turn on multi-factor authentication. If a computer looks infected, disconnect it from the network to stop the problem spreading, then restore from backups once you are confident the threat is cleared.
On ransomware, UK guidance from the NCSC and Action Fraud is not to pay, because paying does not guarantee your files back and marks you as someone who will pay again. Report the incident, and keep a note of what happened and when.
Quick checklist
- Contain first: change passwords from a trusted device and disconnect affected machines
- Restore from a known-good backup once you are confident the threat is gone
- Do not pay a ransom, and seek help rather than negotiating alone
- Report to Action Fraud and check NCSC guidance, and forward scam texts to 7726
- Write down what happened and when, in case data protection duties apply
Chapter 8
Your first week action plan

You do not have to do everything at once. This plan spreads the essentials across a week so it stays manageable alongside running the business.
Day 1: multi-factor authentication on your email, then banking and main business accounts. Day 2: set up a password manager and give your email a new, unique passphrase. Day 3: check your backups and prove a restore works.
Day 4: switch on automatic updates everywhere, including the router. Day 5: agree your money rule and share it. Then, when you can, have a short blame-free chat with staff about phishing.
Quick checklist
- Multi-factor authentication on your most important accounts (Day 1)
- Password manager set up and your email password made unique (Day 2)
- Backups checked and a test restore proven (Day 3)
- Automatic updates switched on everywhere (Day 4)
- Payment rule agreed and shared, and staff briefed (Day 5 onward)
Talk to us when you are ready
If you have worked through this guide, you are already ahead of most small businesses, and that is worth feeling good about.
If you would rather have someone check it over, set it up properly, or simply take it off your plate, that is where we come in. There is no pressure and no jargon, just a calm conversation about what your business actually needs.
This guide is general information to help small businesses improve their security. It is not specific advice for your particular circumstances. For guidance tailored to your business, please speak to us or another qualified professional.
