All guides
SecurityLast reviewed 27 August 2026· 6 min read

The small-business cyber checklist for 2026

Breach rates stayed high in the 2025/26 survey. A calm, ordered list of what a small team should actually do, accounts first, heroics never.

Small teams do not get breached by sophisticated attackers. They get breached through a reused password on an email account that also controls password resets for everything else. Fix things in the order that actually reduces risk.

Key takeaways

  • 43% of UK businesses reported identifying a breach or attack in the last 12 months (2025/26 survey); 46% of small businesses did.
  • Email and identity come first: MFA on everything that supports it.
  • Automatic updates are the cheapest control you will ever implement.
  • Backups only count if you have restored from one.
  • Cyber Essentials gives you a structured target and is often asked for in procurement.

The order that matters

Work down this list. Do not skip to the interesting parts.

  • Turn on multi-factor authentication for email, banking, cloud admin and your domain registrar.
  • Stop password reuse, a password manager for the whole team, no exceptions for founders.
  • Enable automatic updates on laptops, phones and browsers.
  • Back up business-critical data, keep a copy that ransomware cannot reach, and test a restore.
  • Review who has admin access to what, and remove leavers the day they leave.
  • Write a one-page incident plan: who is called, what is disconnected, who tells customers.

Where to go deeper

The NCSC Small Organisations Guide covers each of these in more detail and is written for teams without a security specialist. The Cyber Essentials resources, including the readiness tool, let you assess yourself against a defined standard before paying for certification.

Proportion

You are not defending a bank. The aim is to be a harder target than the automated attacks that hit everyone, and to be able to recover quickly if something gets through.

What to ask other founders

Guidance tells you the rules. Other founders tell you what actually happened. These are worth asking as a structured Advice or Critique request.

  • What did a customer or buyer ask you to prove about security, and when?
  • Was Cyber Essentials worth it for your sales cycle?
  • Has anyone here recovered from an incident, what actually helped?

Sources & further reading

Read next

Stuck on one of these?

NoNetwork is where founders ask for practical help and give it. Free for founders.

Join free