Journey
Cyber security quick wins
Five practical security improvements any business can implement today without technical expertise. Covers passwords, updates, backups, phishing awareness, and access control.
Quick security wins for your business
You do not need technical expertise to protect your business from most cyber attacks. These five actions take minutes to implement and block the majority of common threats.
-
Use strong passwords and turn on two-step verification
Weak passwords are the easiest way into your business. 19% of people still use easy-to-guess credentials.
Do now: Enable two-step verification (2FA) on email, banking, and cloud storage. Use a password manager to create unique passwords for every account.
Full password and 2FA guidance
Step-by-step instructions for setting up strong passwords and two-factor authentication across your accounts
-
Turn on automatic updates
Security updates fix vulnerabilities that criminals actively exploit. Delaying updates leaves your door open.
Do now: Enable automatic updates on Windows, Mac, phones, tablets, and your router. This single action blocks many common attacks at no cost.
Security update guidance
How to configure automatic updates on all your devices and why the 14-day patching rule matters
-
Back up your data
Ransomware encrypts your files and demands payment. If you have backups, you can recover without paying. Average ransomware downtime is 21 days.
Do now: Use the 3-2-1 rule - three copies of important data, on two different types of storage, with one copy offline or in the cloud. Test that you can actually restore from backup.
-
Learn to spot phishing
Over 90% of successful attacks begin with a phishing email. Knowing the warning signs protects your entire business.
Red flags: Urgency ("act now"), unexpected requests for money or passwords, sender addresses that do not match the display name, suspicious links. When in doubt, verify by phone using a known number.
Report suspicious emails: Forward to report@phishing.gov.uk
-
Review who has access to what
Only 14% of businesses reviewed supplier cyber risk in the last 12 months. Former employees and unnecessary admin accounts create risk.
Do now: Remove access for anyone who has left. Review who has admin rights - most staff should not. Check which third parties can access your systems and whether they still need to.
Next steps: get certified
Once you have implemented these basics, consider formal Cyber Essentials certification. It demonstrates your security to customers and is required for many government contracts. Basic certification costs around 320 pounds for micro businesses.
Get Cyber Essentials certified
How to achieve certification, what it costs, and when you need it for contracts
If you have been attacked
Despite precautions, attacks can still happen. If you experience a cyber incident, you may need to report to multiple authorities within strict deadlines.
Report a cyber incident
Who to contact, what to report, and the 72-hour deadline for data breaches
NCSC Cyber Action Plan (opens in a new tab)
Free online tool that creates a personalised security action plan for your business