Journey

Cyber security quick wins

Five practical security improvements any business can implement today without technical expertise. Covers passwords, updates, backups, phishing awareness, and access control.

Running a Business Updated 15 September 2026
5 milestones references 3 guides

Quick security wins for your business

You do not need technical expertise to protect your business from most cyber attacks. These five actions take minutes to implement and block the majority of common threats.

  1. Use strong passwords and turn on two-step verification

    Weak passwords are the easiest way into your business. 19% of people still use easy-to-guess credentials.

    Do now: Enable two-step verification (2FA) on email, banking, and cloud storage. Use a password manager to create unique passwords for every account.

    Full password and 2FA guidance

    Step-by-step instructions for setting up strong passwords and two-factor authentication across your accounts

  2. Turn on automatic updates

    Security updates fix vulnerabilities that criminals actively exploit. Delaying updates leaves your door open.

    Do now: Enable automatic updates on Windows, Mac, phones, tablets, and your router. This single action blocks many common attacks at no cost.

    Security update guidance

    How to configure automatic updates on all your devices and why the 14-day patching rule matters

  3. Back up your data

    Ransomware encrypts your files and demands payment. If you have backups, you can recover without paying. Average ransomware downtime is 21 days.

    Do now: Use the 3-2-1 rule - three copies of important data, on two different types of storage, with one copy offline or in the cloud. Test that you can actually restore from backup.

  4. Learn to spot phishing

    Over 90% of successful attacks begin with a phishing email. Knowing the warning signs protects your entire business.

    Red flags: Urgency ("act now"), unexpected requests for money or passwords, sender addresses that do not match the display name, suspicious links. When in doubt, verify by phone using a known number.

    Report suspicious emails: Forward to report@phishing.gov.uk

  5. Review who has access to what

    Only 14% of businesses reviewed supplier cyber risk in the last 12 months. Former employees and unnecessary admin accounts create risk.

    Do now: Remove access for anyone who has left. Review who has admin rights - most staff should not. Check which third parties can access your systems and whether they still need to.

Next steps: get certified

Once you have implemented these basics, consider formal Cyber Essentials certification. It demonstrates your security to customers and is required for many government contracts. Basic certification costs around 320 pounds for micro businesses.

Get Cyber Essentials certified

How to achieve certification, what it costs, and when you need it for contracts

If you have been attacked

Despite precautions, attacks can still happen. If you experience a cyber incident, you may need to report to multiple authorities within strict deadlines.

Report a cyber incident

Who to contact, what to report, and the 72-hour deadline for data breaches

ncsc.gov.uk

NCSC Cyber Action Plan (opens in a new tab)

Free online tool that creates a personalised security action plan for your business