Small Business IT Security: 7 Essentials Every UK Small Business Should Have

By Muhammad Amir, Founder & Lead Technician · · 3 min read

QUICK ANSWER

The most important IT security basics for a small business are: turn on multi-factor authentication for email and key accounts, keep devices and software updated, use a password manager, back up data with at least one copy offsite, protect every device with security software, limit who has admin access, and train staff to spot phishing.

Most cyber attacks on small businesses aren't sophisticated. They're automated, and they succeed because of weak passwords, missing updates or a convincing email. These seven essentials, drawn from more than 12 years of working in IT, close the most common gaps.

1. Turn on multi-factor authentication (MFA)

MFA means a stolen password alone isn't enough to get into an account. Turn it on for email first (Microsoft 365 or Google Workspace), then banking, accounting software and anything with customer data. In Microsoft 365, the simplest starting point is enabling security defaults, which require MFA for every user.

2. Keep everything updated

Updates fix security holes that attackers actively exploit. Turn on automatic updates for Windows, macOS, browsers and Microsoft 365 apps, and don't forget routers, printers and phones. Devices that no longer get updates, such as unsupported Windows 10 PCs, should be upgraded or replaced.

3. Use a password manager

A password manager creates and remembers a unique, strong password for every account, so one leaked password doesn't unlock everything. A business password manager also lets you share logins safely and remove access when someone leaves.

4. Back up your data: the 3-2-1 rule

Keep 3 copies of important data, on 2 different types of storage, with 1 copy offsite or in the cloud. Just as important: test that you can actually restore from your backups. Ransomware often targets connected backups, so keep at least one copy separate.

5. Protect every device

Every laptop and PC needs up-to-date security software (Microsoft Defender is built into Windows), disk encryption such as BitLocker, and a lock screen. For more than a handful of devices, central device management lets you enforce these settings and wipe a lost laptop remotely.

6. Limit admin access

Staff should use standard accounts day to day, with admin rights kept for the few people who really need them. This stops most malware from installing itself. Remove accounts promptly when people leave.

7. Train your team to spot phishing

Most attacks start with an email. Teach staff to check sender addresses, to be suspicious of urgent requests to pay invoices or change bank details, and to confirm unusual requests by phone. Suspicious emails can be forwarded to the National Cyber Security Centre at report@phishing.gov.uk.

Worth considering: Cyber Essentials

Cyber Essentials is a UK government-backed certification that covers these basics. It shows customers you take security seriously, and it's required for some government contracts. Working through the seven steps above puts you most of the way there.

Need a Hand With This?

Bring it to us for a free diagnostic. You get a fixed quote before any work starts, repairs from £65, no fix — no fee, and a 6-month warranty.

Common Questions

Yes. Many attacks are automated and aren't aimed at a particular company. They simply look for weak passwords, unpatched devices and staff who might click a malicious link, which is why the basics matter so much.

Keep three copies of important data, on two different types of storage, with one copy kept offsite or in the cloud, and regularly test that you can restore from them.

Yes. We help Birmingham and West Midlands businesses with Microsoft 365 security, backups, device set-up and ongoing support. One-off support starts from £65, with a free consultation for ongoing packages.