Journey

Cyber security fundamentals

A structured learning path for business owners new to cyber security. Understand the threat landscape, implement the five essential controls, prepare for incidents, and build ongoing resilience.

Running a Business Updated 15 September 2026
6 milestones references 5 guides

Why cyber security matters for every business

Cyber attacks are not just a problem for large companies. Criminals target small businesses because they often have weaker defences and valuable data. A single successful attack can mean weeks of downtime, lost customers, regulatory fines, and reputational damage.

This learning path takes you through the essentials: understanding the threats you face, implementing protective controls, and knowing what to do if something goes wrong.

  1. Understanding the current threat landscape

    Before implementing defences, understand what you are defending against. The National Cyber Security Centre (NCSC) tracks threats affecting UK businesses and publishes regular statistics.

  2. The five essential security controls

    The government-backed Cyber Essentials scheme identifies five technical controls that protect against approximately 80% of common cyber attacks. You do not need certification to implement these controls - start with the basics.

    Cyber security basics for small businesses

    Practical, low-cost steps to implement all five controls. Includes free tools, staff training guidance, and a prioritised checklist.

  3. Getting certified (optional but recommended)

    Once you have implemented the basic controls, formal certification provides independent verification. Cyber Essentials certification is required for some government contracts and increasingly requested by larger customers and insurers.

    Get Cyber Essentials certified

    Step-by-step guide to achieving basic or Plus certification. Covers costs, the assessment process, and what to expect.

  4. Preparing for cyber incidents

    Even with strong defences, incidents can occur. Knowing what to do before an attack happens reduces damage and recovery time. Have reporting contacts ready and a basic response plan documented.

    Report a cyber incident

    Who to contact, what information to provide, and the reporting timelines you must meet.

    Respond to a ransomware attack

    Immediate steps if your systems are encrypted. What to do, what not to do, and how to recover.

  5. The data protection connection

    Cyber security and data protection are closely linked. A cyber attack that exposes personal data triggers mandatory breach notification requirements under UK GDPR. You have just 72 hours to report to the ICO if individuals are at risk.

    Respond to a data breach

    Assess whether a breach is reportable, meet the 72-hour deadline, and notify affected individuals when required.

  6. Staying secure - ongoing vigilance

    Cyber security is not a one-time exercise. Threats evolve constantly, and yesterday's defences may not protect against tomorrow's attacks. Build security habits into your regular operations.

    Monthly habits

    • Review and apply updates - Check all devices have automatic updates enabled
    • Test backups - Verify you can actually restore from your backups
    • Staff reminders - Brief your team on current threats and phishing examples

    Quarterly habits

    • Access review - Remove accounts for departed staff, revoke unnecessary permissions
    • Test phishing awareness - Send test emails to identify training needs
    • Review incident response plan - Ensure contacts are current and staff know their roles

    Annual habits

    • Renew Cyber Essentials - Certification expires after 12 months
    • Review cyber insurance - Ensure coverage matches your current risk profile
    • Full security review - Consider an external assessment or penetration test