Skip to content

Guides

Cyber security for a small business: where should you actually start?

Improving cyber security can feel like a much bigger job than it needs to be. There are frameworks, tools, assessments, policies and technical controls to choose from. For a smaller organisation, the challenge is often knowing what to prioritise first.

H ChangePublished 4 minute read

Start with the business, not the technology

One of the easiest ways to make cyber security unnecessarily complicated is to start with a list of products or technical controls.

Start with the organisation instead.

What information do you depend on? Which systems would cause a serious problem if you couldn't access them? Which accounts could somebody misuse? What services do your customers rely on you to provide?

You should also consider what requirements already apply to the business. These might come from customers, contracts, insurers, regulators or recognised standards.

This gives you something much more useful than a generic list of security measures. It gives you a picture of what actually matters.

Get the fundamentals right

Once you understand what needs protecting, look at the basics.

The National Cyber Security Centre's current guidance for small organisations focuses on practical areas including securing email, protecting important online accounts, keeping devices secure, backing up important information and recognising cyber attacks.

These aren't particularly glamorous areas of cyber security. But they matter.

For many smaller organisations, improving the fundamentals will provide more value than immediately investing in increasingly sophisticated security technology.

Ask whether important accounts use appropriate authentication. Check whether devices are being kept updated. Understand where important information is stored and whether it can be recovered. Make sure people know what suspicious activity looks like and how to raise a concern.

Start there before making things more complicated.

Know where your gaps are

It can be difficult to prioritise improvements if you don't have a clear picture of your current position.

This doesn't always require a lengthy audit.

A proportionate assessment can help establish what is already working, where obvious gaps exist and which improvements should come first.

The important part is prioritisation.

Ten recommendations labelled as equally urgent aren't particularly helpful to a small organisation with limited time and resources.

A useful assessment should help you understand what needs attention now, what can be improved next and what may be appropriate as the organisation develops.

Don't forget people and processes

Cyber security isn't only about technology.

Someone needs to understand who is responsible for important security decisions. People need clear expectations for how they use systems and information. They need to know what to do when something doesn't look right.

That might mean improving policies, strengthening induction or training, making reporting routes clearer or simply agreeing who takes responsibility for particular security activities.

These arrangements don't need to create unnecessary bureaucracy.

They should make secure ways of working easier to understand and apply.

Be ready for something to go wrong

Good security reduces risk. It doesn't remove it completely.

The NCSC recommends that organisations plan for cyber incidents as part of their wider risk planning.

For a smaller organisation, that can start with some straightforward questions.

Who needs to know if an important account is compromised? Who can contact your IT provider? Where are backups held? How would you continue operating if an important system became unavailable? Who would communicate with customers if services were disrupted?

You don't need to predict every possible cyber attack.

You do need enough preparation to avoid working everything out for the first time while an incident is happening.

What this means for your organisation

If you're trying to work out where to start, focus on five things:

1. Understand what matters. Identify the information, systems, accounts and services the organisation depends on.

2. Check the fundamentals. Review important accounts, devices, updates, backups and basic protections.

3. Identify the biggest gaps. Understand your current position and prioritise improvements rather than trying to fix everything at once.

4. Make responsibilities clear. Ensure people understand the security expectations relevant to their work and who is responsible for key decisions.

5. Prepare for an incident. Know how you would respond if an important account, device, system or piece of information was compromised.

Cyber security doesn't need to begin with a major transformation programme.

For most smaller organisations, the better approach is to understand where you are, establish the fundamentals and improve from there.

Cyber Foundations

Not sure where your gaps are?

H Change helps smaller organisations understand their current cyber security position, identify practical priorities and build stronger foundations without unnecessary complexity.