Cyber security for small businesses

Cyber security for small businesses: what actually keeps you safe

Cyber security for small businesses is mostly five things done properly and kept that way, and none of them needs a security department. This is the practical version of business cyber security: what matters, a checklist you can run this week, who’s going to ask you about it, and what it costs. We’re a Microsoft partner looking after small offices across Liverpool, the Wirral and Cheshire, and everything below is how we’d set it up for you.

Run to the NCSC’s Cyber Essentials standards. Twenty years securing hospital and government systems. Microsoft and Datto partner.

43%of UK businesses reported a cyber attack or breach in the last year (DSIT 2025).
85%of those attacks started with a phishing email (DSIT 2025).
40%of businesses use multi-factor sign-in on email (DSIT 2025).
£8,260average cost of an impactful breach to a business (DSIT 2025).

What business cyber security means for a small office

For a business with two to thirty people, cyber security isn’t a wall of screens or a product with a dashboard. It’s a short list of controls that stop the attacks small businesses actually get, run all the time by somebody whose job it is. The attacks are mostly automated and mostly start in an inbox, so the defence is mostly discipline: the right settings on, the updates applied, the backup proven, the sign-in protected.

That’s why good cyber security and good IT support are, for a small business, largely the same work. The monitoring, patching and backups that keep you running are the things that keep you safe. It’s also why cyber security for small businesses doesn’t have to cost what the enterprise version does.

Small business cyber security is mostly discipline, not products.
Small business cyber security is mostly discipline, not products.

The five things that stop most attacks on a small business

Small business cybersecurity advice comes in hundreds of versions, and most of them come back to the same five. This is the NCSC’s own list for small organisations, in the order we’d tackle it. DSIT’s 2025 survey found only 40% of businesses use multi-factor sign-in on email, so getting all five right puts you ahead of a lot of firms your size.

1. Backups you’ve restored from

Not a backup that runs, a backup somebody has opened and restored a file from. Kept separate from the machines it protects, so ransomware can’t reach it, and covering Microsoft 365 email as well as files.

2. Protection from malware

Antimalware on every laptop and PC, including the one at home that’s used for work. Ideally the kind that watches how programs behave, not just a list of known threats.

3. Devices kept up to date

Updates applied on a cycle rather than when somebody remembers. Cyber Essentials asks for critical and high-risk updates within 14 days of release, which is a good standard to hold whether or not you certify.

4. Multi-factor sign-in everywhere

On every Microsoft 365 account, every admin login and anything reachable from outside the office. It’s the single setting that turns a stolen password from a disaster into a non-event.

5. Staff who spot the email

With 85% of attacks starting with phishing, the last line is a person who pauses before clicking. Short, regular practice with realistic examples beats an annual slideshow.

And a one-page plan

Who’s rung first, who decides to shut things down, where the numbers are written if email’s gone. It doesn’t need to be long. It needs to exist before the day it’s needed.

A cyber security checklist for small businesses

Run this on your own business this week. It takes twenty minutes and it’s worth doing whether you ever ring us or not. If you can tick all ten, you’re in good shape. The ones you can’t tick are the whole job.

If you’d rather have the answers written up for you, the Free Cyber Health Check is six questions and gives you a written fix list in the order worth doing it.

  • Multi-factor sign-in is on for every Microsoft 365 account, including the directors’ and any shared ones.
  • Somebody has restored a file from the backup in the last three months, and you know who.
  • The backup includes email and OneDrive, not just the server or one PC.
  • Every laptop and PC used for work has antimalware that’s running and up to date.
  • Updates are applied on a schedule, and nothing’s running software past its end of support.
  • Nobody uses an administrator account for everyday work.
  • When someone leaves, their access ends the same day.
  • You could list every system that holds client data, and who supplies it.
  • Staff know who to tell if they’ve clicked something odd, and they’d tell them.
  • There’s a one-page incident plan written down somewhere that doesn’t need the network.

Who’s going to ask about your cyber security

For most small businesses, cyber security stops being optional the day somebody else asks about it. It’s usually one of three people. Your insurer, on the renewal form, asking about multi-factor sign-in, backups and patching, and expecting honest answers. A bigger client, sending a supplier questionnaire before they’ll sign. Or a regulator: the ICO under UK GDPR for anyone holding personal data, the SRA for law firms, AML supervision for accountants and estate agents, FCA Consumer Duty for financial advisers.

They’re all asking for broadly the same controls, and Cyber Essentials is the framework most of them recognise. Answering well means having the controls in place and the evidence written down. Our guide to cyber insurance requirements maps the common insurer questions to the evidence that answers them.

The questionnaire is easier when the answers are already written down.
The questionnaire is easier when the answers are already written down.

What cyber security costs a small business

All of it is included in our managed IT support at £55 a person a month: antimalware with threat detection and response, updates on a schedule, multi-factor sign-in, email filtering, phishing practice, breached-password monitoring, account-takeover alerts, tested backups and monitoring. There’s no security tier on top and no upgrade to be talked into.

What isn’t in the monthly price is one-off work: a review of your setup, answering a client’s questionnaire, or getting ready for Cyber Essentials. That’s a fixed price, agreed before we start. Round-the-clock monitoring by a security operations centre is available as an extra.

See managed cyber security in full

Small business cyber security, per person

Managed IT support, per person£55.00
Threat detection and responseincluded
Email filtering, phishing practiceincluded
Backups, updates, MFA, monitoringincluded
A month£55 x people

Same number every month. Microsoft licences billed separately.

Cyber security for small businesses: the questions people ask first

What does cyber security mean for a small business?

Mostly five things done properly and kept that way: backups you've restored from, protection against malware on every device, updates applied on a schedule, multi-factor sign-in on every account, and staff who know what a phishing email looks like. That's the NCSC's own list for small organisations. Cyber security for small businesses is less about buying products and more about the discipline of keeping those five in place.

Is cybersecurity the same thing as cyber security?

Yes. Cybersecurity is the spelling Microsoft and most American sites use; cyber security is the usual UK spelling, and it's the one the NCSC and GOV.UK use. Same subject, same controls. You'll see both on this page because people search for both.

Do small businesses really get targeted?

Yes, though rarely by name. Most attacks on small businesses are automated: a phishing email sent to thousands of inboxes, a password tried against thousands of accounts. DSIT's 2025 survey found 43% of UK businesses reported a breach or attack in the previous year, and 85% of those started with phishing. Being small doesn't make you invisible; it usually means fewer controls in the way.

Is antivirus enough cyber security for a business?

It's one of the five, not all of them. Antivirus catches what it recognises. A stolen password, a convincing email from someone pretending to be your supplier, or a backup that turns out not to restore all get straight past it. Multi-factor sign-in and tested backups do more for a small business than any antivirus upgrade.

Do we need Cyber Essentials?

If a client, a contract or an insurer asks for it, yes. If nobody's asking, running to Cyber Essentials standards without certifying is still worth it, because the scheme is a sensible checklist of the basics. We run to Cyber Essentials standards ourselves, and it's how we'd set you up.

How much should a small business spend on cyber security?

Less than the scare stories suggest. All of it is inside our managed IT support at £55 a person a month: antimalware with threat detection and response, updates on a schedule, multi-factor sign-in, email filtering, phishing practice, breached-password monitoring, account-takeover alerts, tested backups and monitoring. One-off work, a review or getting ready for Cyber Essentials, is a fixed price agreed before we start.

Can you do business cyber security alongside our current IT provider?

Yes. They keep the helpdesk and the day-to-day, we run the security layer, and the boundary's written down so nobody's guessing whose job the alert is.

Have a chat with Eric

Fifteen minutes with Eric. Bring the checklist, or the questionnaire that started this.

Or just ring: 0151 452 3060. A person picks up.

Cyber security for your business, without the scare

The five controls that stop most attacks, run properly for small offices across Liverpool, the Wirral and Cheshire, built into IT support from £55 a person a month. Ring and a person picks up.