Journey
Cyber security fundamentals
A structured learning path for business owners new to cyber security. Understand the threat landscape, implement the five essential controls, prepare for incidents, and build ongoing resilience.
Why cyber security matters for every business
Cyber attacks are not just a problem for large companies. Criminals target small businesses because they often have weaker defences and valuable data. A single successful attack can mean weeks of downtime, lost customers, regulatory fines, and reputational damage.
This learning path takes you through the essentials: understanding the threats you face, implementing protective controls, and knowing what to do if something goes wrong.
-
Understanding the current threat landscape
Before implementing defences, understand what you are defending against. The National Cyber Security Centre (NCSC) tracks threats affecting UK businesses and publishes regular statistics.
-
The five essential security controls
The government-backed Cyber Essentials scheme identifies five technical controls that protect against approximately 80% of common cyber attacks. You do not need certification to implement these controls - start with the basics.
Cyber security basics for small businesses
Practical, low-cost steps to implement all five controls. Includes free tools, staff training guidance, and a prioritised checklist.
-
Getting certified (optional but recommended)
Once you have implemented the basic controls, formal certification provides independent verification. Cyber Essentials certification is required for some government contracts and increasingly requested by larger customers and insurers.
Get Cyber Essentials certified
Step-by-step guide to achieving basic or Plus certification. Covers costs, the assessment process, and what to expect.
-
Preparing for cyber incidents
Even with strong defences, incidents can occur. Knowing what to do before an attack happens reduces damage and recovery time. Have reporting contacts ready and a basic response plan documented.
Report a cyber incident
Who to contact, what information to provide, and the reporting timelines you must meet.
Respond to a ransomware attack
Immediate steps if your systems are encrypted. What to do, what not to do, and how to recover.
-
The data protection connection
Cyber security and data protection are closely linked. A cyber attack that exposes personal data triggers mandatory breach notification requirements under UK GDPR. You have just 72 hours to report to the ICO if individuals are at risk.
Respond to a data breach
Assess whether a breach is reportable, meet the 72-hour deadline, and notify affected individuals when required.
-
Staying secure - ongoing vigilance
Cyber security is not a one-time exercise. Threats evolve constantly, and yesterday's defences may not protect against tomorrow's attacks. Build security habits into your regular operations.
Monthly habits
- Review and apply updates - Check all devices have automatic updates enabled
- Test backups - Verify you can actually restore from your backups
- Staff reminders - Brief your team on current threats and phishing examples
Quarterly habits
- Access review - Remove accounts for departed staff, revoke unnecessary permissions
- Test phishing awareness - Send test emails to identify training needs
- Review incident response plan - Ensure contacts are current and staff know their roles
Annual habits
- Renew Cyber Essentials - Certification expires after 12 months
- Review cyber insurance - Ensure coverage matches your current risk profile
- Full security review - Consider an external assessment or penetration test