UK IT & website support · plans from £25/month · £45/hour ad-hoc01623 650333 · Client login
Get help

Small Business Cyber Security Checklist (UK)

A small business cyber security checklist covers MFA on every account, automatic updates, tested backups, email authentication, staff phishing awareness and prompt removal of leavers. dijitul support works through it with you and keeps it maintained: ad-hoc at £45 an hour + VAT, or ongoing on our £99 a month + VAT Complete plan.

Updated 2026-10-10 · by the dijitul support team, Mansfield, UK

Key facts

  • The UK Government's Cyber Security Breaches Survey 2025 found 43% of businesses reported a breach or attack in the previous 12 months.
  • The same survey found phishing was the most common attack, affecting 38% of businesses.
  • MFA on email and cloud accounts blocks most password-based attacks.
  • Backups need to be separate from your main systems and tested, or ransomware can encrypt them too.
  • SPF, DKIM and DMARC records stop criminals sending email that looks like it came from your domain.
  • Every leaver's account should be disabled on their last day.

Why small businesses are targets

Criminals do not need to target you personally. Most attacks are automated: phishing emails sent to thousands of addresses, bots trying leaked passwords against Microsoft 365, scanners looking for old WordPress plugins. According to the UK Government's Cyber Security Breaches Survey 2025, 43% of UK businesses reported a cyber breach or attack in the previous 12 months, rising to 65% of medium and 69% of large businesses. Phishing was by far the most common type, affecting 38% of businesses.

The good news is that a short list of basics stops most of it. Work through the checklist below and tick off what you have.

None of these steps needs expensive software. Most are settings in tools you already pay for, such as Microsoft 365 and Windows.

Accounts and passwords

  • Turn on MFA for Microsoft 365 or Google Workspace, banking, your website admin, domain registrar, accounting software and social media. Use an authenticator app rather than text messages where possible.
  • Use a password manager so every account has a long, unique password.
  • Separate admin accounts. Nobody should browse the web or read email while signed in as a global admin.
  • Remove leavers on their last day: disable the account, revoke sessions, and reset any shared passwords they knew.
  • Block legacy authentication in Microsoft 365, which bypasses MFA. Security Defaults or Conditional Access does this.

Devices and software

  • Automatic updates on for Windows, macOS, phones, browsers and Office. Critical updates should be installed within 14 days, which is also a Cyber Essentials requirement.
  • No unsupported systems. Windows 10 without Extended Security Updates is out of support; see Windows 10 end of support.
  • Antivirus active on every device. Microsoft Defender is fine if it is turned on and reporting.
  • Disk encryption on laptops: BitLocker on Windows, FileVault on Mac, so a lost laptop is not a data breach.
  • Staff are not local admins on their own PCs.
  • Router secured: default password changed, firmware updated, remote admin off.

Email, website and backups

  • SPF, DKIM and DMARC are set up on your domain so others cannot easily spoof it. Start DMARC at p=none, check the reports, then move to quarantine or reject. See email security.
  • External email warning banners on messages from outside the business.
  • Website updated: CMS core, plugins and themes, with unused plugins removed and an SSL certificate in place.
  • Backups follow 3-2-1: three copies, two different types of storage, one offsite or offline. Include Microsoft 365 mail and OneDrive, which Microsoft does not back up for you in the way most people assume.
  • Test a restore at least every quarter.

People and plans

  • Short phishing training for everyone, repeated yearly. Teach staff to check sender addresses and to report, not delete, suspicious emails. See staff security training.
  • A payment verification rule: any change of bank details is confirmed by phone on a number you already have.
  • A one-page incident plan: who to call, how to disconnect, where backups are. Our ransomware guide is a good starting point.
  • Consider Cyber Essentials once the basics are in place; see Cyber Essentials explained.

Finally, write down who is responsible for each item on this list. In many small businesses, security slips not because anyone disagrees with it, but because everyone assumes someone else is checking the backups or removing old accounts.

When to call dijitul support

If you could not tick most of the list, we can do a remote review of Microsoft 365, devices, email records, website and backups, then fix the gaps. One-off work is £45 an hour + VAT. To keep it maintained, the £99 a month + VAT Complete plan covers website updates, backups, monitoring, 3 hours of work a month and helpdesk support for your team. See cyber security support and security audit.

Frequently asked questions

What is the most important cyber security step for a small business?

Turning on multi-factor authentication for email and cloud accounts. Most small-business compromises start with a stolen or guessed password, and MFA stops that password alone being enough to get in.

How common are cyber attacks on UK small businesses?

The UK Government's Cyber Security Breaches Survey 2025 found 43% of businesses reported a breach or attack in the previous year, including 42% of micro and 46% of small businesses. Phishing was the most common type.

Does Microsoft back up my Microsoft 365 email?

Microsoft keeps the service running and holds deleted items for a limited time, but it is not a full backup you control. A separate Microsoft 365 backup protects you against accidental deletion, malicious deletion and ransomware.

What are SPF, DKIM and DMARC?

They are DNS records that prove which servers may send email for your domain, sign your messages, and tell receiving servers what to do with fakes. Together they make it much harder for criminals to impersonate your business by email.

Can dijitul check our cyber security?

Yes. dijitul reviews Microsoft 365 settings, MFA, devices, email records, website and backups remotely, then fixes the gaps. One-off work is £45 an hour + VAT, or ongoing on the £99 a month + VAT Complete plan.

Related

Hand it over and stop worrying

Updates, backups, monitoring and fixes from £25 a month + VAT. Real UK people on the phone.

Call usGet help now