Cyber Security for Small Businesses: The Essential Checklist
Small businesses rarely get breached by anything clever. They get caught by an old account nobody closed, a password reused across three systems, or a backup that had quietly stopped running months earlier. This is the checklist we'd work through with a firm in Edinburgh or Livingston that wants to know where it actually stands — nine controls, in the order that gives you the most protection for the least disruption.
1. Multi-factor authentication on everything that faces the internet
If you only do one thing, do this. Email, remote access, accounting, your file storage, anything a stranger could reach a login page for. A stolen password on its own then buys an attacker nothing. Start with email, because that's the account used to reset all the others. Our guide to strong passwords and MFA covers how to roll it out without a mutiny, including what to do about shared logins.
2. Updates applied, and a way of knowing they were
Plenty of successful attacks exploit flaws that were patched long ago. The gap is never knowing whether the fix reached every machine. Automatic updates are the right default, but they fail silently on the laptop that's rarely on, or the one that's been asking to restart since spring.
- Cover the whole estate. Operating systems, browsers, and the business applications people actually use — not just Windows.
- Watch for end of support. Software that stops receiving security fixes becomes a liability on a known date, as plenty of firms found when Windows 10 reached the end of its life.
- Keep a list. You cannot patch devices you've forgotten you own.
3. Backups that someone has restored from
A backup you've never restored is a belief, not a control. The 3-2-1 principle is still the plain-English standard: three copies, on two kinds of media, one of them off-site or otherwise out of reach of your network. That last point is what defeats ransomware, which deliberately looks for connected backup drives. Test a restore on a schedule and note the date, so "when did we last prove this" has a factual answer.
4. Least privilege, including for you
Give people the access their job needs and nothing more. Day-to-day work should not happen in an administrator account, because anything that runs, runs with the rights of whoever is logged in. Review access when people change roles, and keep the number of full administrators small enough to name from memory.
5. Email filtering and the human layer behind it
Filtering removes a great deal of what arrives. What gets through is the targeted, plausible message — an invoice with changed bank details, a supplier asking for an urgent transfer. Train staff on spotting phishing emails, and make reporting one easy, blame-free step. The cultural half matters more than the technical half here: if people fear being told off, you find out about the click a fortnight late.
6. Encryption on every device that leaves the building
Laptops and phones get lost. Full-disk encryption — BitLocker on Windows, FileVault on Mac, on by default on modern phones — turns a lost device from a data breach into a hardware replacement. Check it's genuinely switched on, and that recovery keys are stored somewhere other than the encrypted machine.
7. An offboarding routine you follow every time
Live accounts belonging to former staff are among the easiest weaknesses to fix and the most commonly missed. Write a short leavers' checklist: disable accounts the same day, recover hardware, change anything they had shared access to, and forward the mailbox rather than leaving it open. Do the same for contractors whose work has ended.
8. A plan for the bad day, on paper
Decide now who is called, who talks to customers, and how you keep trading while systems are down — because you will not think clearly at the time. Print it. A plan stored only on the network is unavailable exactly when it's needed. Our piece on what ransomware actually does explains why the first hour of a bad day tends to decide how the rest of it goes.
9. Cyber Essentials as a recognised baseline
Cyber Essentials is the UK government-backed scheme covering roughly the ground above, and it's increasingly asked for in tenders and supply-chain questionnaires. Even if you never certify, its five control areas are a sensible structure to work towards. Whether you need certification, and at what level, is worth taking proper advice on for your sector.
Get a straight assessment of where you stand
Don't attempt all of this in one weekend — MFA on email and one proven restore come first. We're based in Wishaw and work with businesses across Edinburgh, Musselburgh and the wider Lothians. If you'd like someone to walk the checklist with you honestly and say what matters most for your setup, that's what our cyber security and managed IT services work covers, with a clear quote before anything starts.