The ultimate guide to cyber security for businesses
Cyber security is one of the most pressing business risks of 2025 and 2026. Whether you run a small business or a large enterprise, the threats are real, growing, and increasingly sophisticated. This guide covers everything UK businesses need to know: from the most common cyber attacks (phishing, ransomware, and business email compromise) to emerging dangers like AI-generated deepfakes and supply chain vulnerabilities.
You will find practical, actionable guidance on how to protect your organisation, meet your UK GDPR and Cyber Essentials obligations, and build a security culture that makes your people your strongest defence, not your weakest link. All statistics are drawn from authoritative 2025 sources including the UK Cyber Security Breaches Survey, the IBM Cost of a Data Breach Report, and the Verizon Data Breach Investigations Report.
Why cyber security matters more than ever
Cybercrime is no longer a problem reserved for banks and tech giants. Every organisation, regardless of size, sector, or structure, is a potential target. The data you hold on your customers, employees, and suppliers is valuable to criminals. Your systems are a gateway. Your people are a vulnerability.
The numbers make sobering reading:
- 43% of UK businesses reported a cyber security breach or attack in 2025, equivalent to around 612,000 companies nationwide. (Source: UK Cyber Security Breaches Survey 2025/2026, DSIT and Home Office - gov.uk/government/statistics/cyber-securitybreaches-survey-20252026)
- The average cost of the most disruptive breach for a UK business was £3,550 in 2025, rising significantly for larger organisations. (Source: UK Cyber Security Breaches Survey 2025/2026)
- Globally, the average cost of a data breach reached $4.44 million in 2025. (Source: IBM Cost of a Data Breach Report 2025 - ibm.com/reports/data-breach)
- Cybercrime is projected to cost businesses worldwide $15.6 trillion by 2029.
- Phishing attacks remained the most prevalent type of breach or attack reported by UK businesses. (Source: UK Cyber Security Breaches Survey 2025/2026)
And the financial cost is only part of the story. Reputational damage, loss of customer trust, regulatory fines, and operational disruption can be far more devastating and far longer-lasting than any direct financial loss.
Under the UK GDPR, a data breach can result in a fine of up to £17.5 million or 4% of global annual turnover, whichever is higher. The ICO has shown it is willing to use these powers.
The good news? The vast majority of successful cyber attacks exploit known, preventable vulnerabilities. This guide will walk you through everything you need to know, from the threats you face to the practical steps you can take to protect your business today.
The threat landscape: classic attacks
There are broadly two categories of cyber attack: those that attempt to steal your login credentials, and those that trick you into downloading malicious software. Both can be equally devastating. Most begin with a human being making a mistake, which is why understanding the methods attackers use is your first line of defence.
Human error
Before we get to deliberate attacks, it is worth acknowledging that one of the biggest risks to your data is simple human error. Sending an email to the wrong recipient, misconfiguring a system, or leaving a screen unlocked, these everyday mistakes account for a significant proportion of data breaches. According to the Verizon 2025 Data Breach Investigations Report (verizon.com/business/resources/reports/dbir), human error accounted for 26% of data breaches in the reporting period.
The answer is not to punish mistakes. It is to build processes and a culture that make mistakes less likely and easier to catch.
Phishing
Phishing is the most common form of cyber attack, and it is not going away. According to the Verizon 2025 DBIR (verizon.com/business/resources/reports/dbir), phishing was the initial access vector in 16% of attacks resulting in a data breach, making it the most common root cause studied in the report.
A phishing attack is where a criminal impersonates a trusted person or organisation, such as a bank, a delivery company, or a colleague, to trick you into revealing sensitive information (such as login credentials) or clicking a malicious link that downloads malware.
Classic phishing emails are sent in bulk, with little personalisation. They rely on volume: even a 1% success rate across millions of emails yields thousands of victims. Common red flags include:
- The sender's email address does not match the organisation it claims to be from (hover over the 'from' field to check)
- Your name is not in the 'To' field, meaning you have been blind-copied along with many others
- The email is not addressed to you personally, for example 'Dear Customer' or 'Attention Beneficiary'
- Urgent or alarming language, such as 'Your account will be suspended' or 'Immediate action required'
- Links that do not go where they claim, so always hover over a link before clicking to see the true destination
- Unexpected attachments, especially .exe, .zip, or Office files with macros
- Poor grammar or spelling, though AI is making this less reliable as a warning sign
- Requests for sensitive information that a legitimate organisation would never ask for by email
TIP: Homoglyph attacks replace letters with visually identical characters from other alphabets (for example, Cyrillic). The domain dhl.com and a Cyrillic lookalike appear identical to the human eye but are different to a computer. Always check links carefully.
Spear phishing
Where standard phishing casts a wide net, spear phishing is targeted. The attacker researches their victim, including their role, colleagues, clients, and suppliers, and crafts a highly convincing, personalised message.
The results are dramatically more effective. Standard phishing emails have an open rate of around 3% and a click-through rate of 5%. Spear phishing campaigns, by contrast, are opened 70% of the time, with a click-through rate of 50%. If you are on the receiving end of a well-crafted spear phishing email, the odds are you will open it and click.
Newer employees are particularly vulnerable, as they are less familiar with internal processes and more likely to comply with requests that appear to come from senior colleagues.
Whaling
Whaling is spear phishing aimed at senior executives, the 'big fish' in an organisation. CEOs, CFOs, and directors are high-value targets because they have greater access to systems and data, more authority over financial transactions, and more power to instruct others.
A whaler will research their target thoroughly, including through social media, to craft a convincing attack. They may impersonate a trusted client, supplier, or board member. They may use personal information gleaned from LinkedIn or other public profiles to make the message seem authentic.
Social media hygiene matters. Review what information is publicly visible on your profiles. Be cautious about accepting connection requests from people you do not know, as fake 'honeypot' profiles are a known tactic.
Clone phishing
Clone phishing requires an existing email to have already been intercepted or a legitimate account to have been compromised. The attacker clones a real email, keeping the sender, subject line, and content, but replaces the links or attachments with malicious ones. They then resend it, often claiming to be a corrected or updated version.
This is particularly dangerous because the email looks entirely legitimate. Always hover over links before clicking, even in emails from known contacts.
Vishing (voice phishing)
Vishing is phishing over the phone. An attacker calls pretending to be from IT support, a bank, a regulator, or even a senior colleague. They use the authority and immediacy of a phone call to pressure victims into revealing credentials, granting remote access, or transferring funds.
Common vishing scenarios include:
- Fake IT support calls: 'We have detected a problem with your computer. Please go to this URL so we can fix it.'
- Bank fraud calls: 'There has been suspicious activity on your account. Please confirm your details.'
- CEO fraud: An attacker impersonates a senior executive and pressures a junior employee into making an urgent bank transfer.
With the rise of AI voice cloning (covered in section 3), vishing attacks are becoming significantly more convincing. A caller can now sound exactly like your CEO. Always verify the identity of callers before sharing any sensitive information or taking any action, especially for requests involving money or system access. Call back on a number you know to be genuine.
Smishing (SMS phishing)
Smishing uses text messages to deliver phishing attacks. Common examples include fake parcel delivery notifications, bank alerts, or HMRC tax refund messages. The link in the message leads to a spoofed website designed to steal credentials or install malware.
Water holing
A watering hole attack targets a website that the victim regularly visits. The attacker compromises the site and injects malicious code that infects visitors' systems. The victim does not need to click anything suspicious; simply visiting a trusted site is enough. Keeping software and browsers up to date, using reputable security software, and being cautious about what you download all help reduce the risk.
Baiting
Baiting exploits curiosity or greed. The most common form involves leaving a USB drive or other physical media in a car park or common area, labelled with something enticing like 'Payroll 2025' or 'CONFIDENTIAL'. When an unsuspecting employee plugs it in, malware is installed. Baiting also occurs online through fake advertisements offering free software or prizes that, when clicked, download malware.
Never plug unknown USB drives or physical media into a work device. If you find one, hand it to your IT team.
Tailgating (physical security)
Tailgating is where an attacker physically follows an authorised person into a secure area, often by holding the door open or posing as a delivery person, contractor, or new employee. Once inside, they may access unattended computers, steal physical documents, plant hardware, or gather intelligence for a future attack.
Best practice:
- Use electronic entry systems (RFID cards or fobs) with a reception area as a buffer
- Require all visitors to sign in and wear visible visitor badges
- Never hold the door open for someone you do not recognise; direct them to reception
- Challenge anyone in the office you do not recognise
Pretexting
Pretexting is the creation of a fabricated scenario to manipulate a victim into taking an action or revealing information. Examples include posing as an auditor to request financial records, impersonating a supplier to update bank details, or claiming to be a new IT contractor to gain access to systems. Robust verification procedures, requiring identity to be confirmed through a separate, trusted channel before any sensitive action is taken, are the best defence.
The new frontier: emerging threats
The threat landscape has changed dramatically in recent years. Artificial intelligence has fundamentally shifted the balance of power between attackers and defenders, and not always in defenders' favour.
AI-powered attacks and deepfakes
This is the most significant development in cyber security in recent years, and it is accelerating rapidly.
AI-generated phishing is now indistinguishable from legitimate communication. The traditional tell-tale signs, such as poor grammar, generic greetings, and implausible scenarios, are being eliminated. According to the Microsoft Digital Defense Report 2025 (microsoft.com/en-us/corporate-responsibility/cybersecurity/microsoft-digitaldefense-report-2025), AI-driven phishing is now three times more effective than traditional campaigns.
Deepfake audio and video have moved from novelty to serious business threat. Attackers can now generate convincing audio or video of executives, managers, or clients with minimal source material, just a few seconds of audio or a handful of images. These are being used to:
- Impersonate executives in video calls to authorise fraudulent transfers
- Clone voices to instruct employees over the phone
- Create fabricated IDs for financial fraud
- Manipulate employees into resetting MFA or granting remote access
In one high-profile case, a finance employee was tricked into transferring $25 million after a deepfake video call appeared to show their CFO and other colleagues authorising the payment.
Agentic AI attacks represent the next evolution. AI tools can now autonomously conduct reconnaissance, identify vulnerabilities, craft personalised attacks, and execute them at scale, without human intervention at each step. According to the IBM Cost of a Data Breach Report 2025 (ibm.com/reports/data-breach), the average cost of an AI-powered breach is $5.72 million, 13% higher than the average breach cost overall.
What this means for you: The old advice, 'look for bad grammar and suspicious links', is no longer sufficient. [OH6.1]Verification procedures, security culture, and technical controls are more important than ever.
Ransomware 3.0
Ransomware remains the dominant threat for businesses of all sizes. According to the Verizon 2025 DBIR (verizon.com/business/resources/reports/dbir), ransomware was linked to 75% of system-intrusion breaches. Classic ransomware encrypts your files and demands payment (usually in cryptocurrency) to restore access. Modern ransomware goes further:
- Data exfiltration: attackers steal your data before encrypting it, then threaten to publish it publicly or sell it on the dark web unless you pay
- Customer notification threats: attackers threaten to contact your customers directly, maximising reputational pressure
- DDoS attacks: some groups simultaneously launch denial-of-service attacks to increase pressure
The median ransomware payment in 2025 was $115,000, but 64% of victims chose not to pay, according to the Verizon 2025 DBIR. Paying is not recommended. It marks you as a target for repeat attacks and does not guarantee data recovery.
Ransomware-as-a-Service (RaaS) has lowered the barrier to entry dramatically. Criminal groups now sell ransomware toolkits on the dark web, meaning technically unsophisticated attackers can launch sophisticated attacks. This has significantly increased the volume of ransomware incidents.
Supply chain attacks
Rather than attacking your organisation directly, attackers increasingly target your suppliers, software vendors, or service providers and use that access to reach you. According to the Verizon 2025 DBIR (verizon.com/business/resources/reports/dbir), third-party involvement in breaches doubled to 30% in 2025, driven in part by vulnerability exploitation and business interruptions.
A single compromised vendor can trigger a domino effect across hundreds of businesses. The 2020 SolarWinds attack, where malicious code was inserted into a software update, compromised thousands of organisations worldwide, including government agencies. Supply chain attacks are particularly dangerous because they exploit trust. Your defences may be excellent, but if your payroll provider, cloud storage vendor, or IT support company is compromised, your data may be at risk regardless.
Insider threats
Not all threats come from outside. Insider threats, whether malicious or accidental, are among the hardest risks to manage:
- Accidental insiders: employees who fall for phishing attacks, send data to the wrong recipient, or misconfigure systems
- Negligent insiders: employees who bypass security policies for convenience, for example by using personal devices, weak passwords, or unsecured networks
- Malicious insiders: employees who deliberately steal or leak data, often motivated by financial gain or grievance
According to the Verizon 2025 DBIR (verizon.com/business/resources/reports/dbir), nearly a third (29%) of breaches in EMEA originated from within the organisation. With remote and hybrid working now the norm, monitoring and controlling access has become significantly more complex.
Business email compromise (BEC)
Business Email Compromise is one of the most financially damaging forms of cybercrime globally. Attackers infiltrate or spoof email accounts to trick employees into transferring funds or sharing sensitive data. According to the FBI Internet Crime Complaint Center (IC3), more than $6.3 billion was transferred as part of BEC scams in 2024 alone. Common scenarios include:
- CEO fraud: an email appearing to come from the CEO instructs the finance team to make an urgent, confidential transfer
- Invoice fraud: a supplier's email is compromised or spoofed, and payment details are changed to a fraudulent account
- Payroll diversion: HR receives a request to change an employee's bank details to a fraudulent account
Always verify any request to change payment details or make urgent transfers through a separate, trusted channel, such as a phone call to a known number, not a reply to the email.
How to protect your business
Understanding the threats is the first step. Taking action is the second. Here is a practical framework for protecting your organisation.
Build a security culture
Technology alone cannot protect your business. The most important investment you can make is in your people. A strong security culture means that every member of your team, from the CEO to the newest recruit, understands the risks, knows what to do, and feels empowered to act.
How to build it:
- Get buy-in from the top. Security culture starts with leadership. If senior management does not take it seriously, nobody else will.
- Involve everyone in developing procedures. Policies that are imposed without consultation are ignored. Policies that staff helped create are followed.
- Make training regular, engaging, and practical. Annual tick-box training is not enough. Use simulated phishing exercises, interactive modules, and real-world examples.
- Do not punish honest mistakes. If employees fear punishment for reporting a breach, they will hide it, making the damage far worse. Create a blame-free reporting culture.
- Reward good security behaviour. Recognise and reward staff who spot threats, report incidents, or champion security in their teams.
- Appoint security champions. In larger organisations, identify individuals in each team who take a particular interest in security.
- Keep procedures under constant review. The threat landscape changes. Your procedures should too.
Zero trust architecture
The traditional approach to network security, 'trust everything inside the perimeter, block everything outside', is no longer fit for purpose. With remote working, cloud services, and mobile devices, there is no longer a clear perimeter to defend.
Zero Trust is a modern security framework built on a simple principle: never trust, always verify. Every user, every device, and every access request must be authenticated and authorised, regardless of where it originates. The Microsoft Digital Defense Report 2025 (microsoft.com/en-us/corporate-responsibility/cybersecurity/ microsoft-digital-defense-report-2025) recommends that security teams follow the Zero Trust concept of assuming breach and designing for continuity. Key principles include:
- Continuous verification: identity is verified at every access request, not just at login
- Least privilege access: users only have access to the systems and data they need for their role, nothing more
- Micro-segmentation: the network is divided into small zones, so a breach in one area cannot spread freely
- Assume breach: design your systems on the assumption that attackers may already be inside
Zero Trust is not a single product. It is a strategic approach that evolves with your organisation. Start with identity and access management, then expand gradually.
Multi-factor authentication (MFA)
MFA is one of the single most effective security controls available, and it remains critically underused. According to the UK Cyber Security Breaches Survey 2025/2026 (gov.uk/government/statistics/cyber-security-breaches-survey-20252026), only around 40% of UK businesses had any form of two-factor authentication in place.
MFA adds a second verification step to the login process, typically a code sent to your phone, a notification in an authenticator app, or a biometric check. Even if an attacker has your password, they cannot access your account without this second factor. MFA should be enabled on all accounts, particularly: email, cloud services, financial systems, remote access tools, and password managers.
A note on MFA bypass: Attackers have developed techniques to circumvent MFA, including 'adversary-in-the-middle' (AiTM) attacks that intercept authentication tokens in real time. This is why MFA is a critical layer of defence, but not the only one. Phishing resistant MFA methods (such as hardware security keys or passkeys) offer stronger protection than SMS codes. The IBM 2025 report (ibm.com/reports/data-breach) recommends adopting modern, phishing-resistant authentication methods such as passkeys to significantly reduce the risk of credential abuse.
Password hygiene
Despite years of advice, weak and reused passwords remain one of the most common causes of breaches. Current best practice:
- Use a passphrase, not a password. The NCSC (ncsc.gov.uk) recommends choosing three random, unrelated words as your password. This is both easier to remember and harder to crack than a complex string of characters.
- Use a password manager. A reputable password manager generates and stores unique, strong passwords for every account. Enable MFA on your password manager itself.
- Never reuse passwords across accounts. If one account is compromised, attackers will try the same credentials on other services (a technique called credential stuffing).
- Change passwords immediately if you suspect they have been compromised, for example if you receive an unexpected MFA verification request.
Patch management
Keeping software up to date is one of the most basic and most neglected security practices. Software vendors regularly release patches to fix known security vulnerabilities. Attackers actively scan for systems running unpatched software and exploit these vulnerabilities, often within days of a patch being released.
The 2017 WannaCry ransomware attack, which crippled the NHS and affected hundreds of thousands of organisations worldwide, exploited a vulnerability that Microsoft had already patched. The organisations affected simply had not applied the update.
Best practice:
- Enable automatic updates wherever possible
- Establish a formal patch management process with defined timescales
- Prioritise patches for internet-facing systems and critical infrastructure
- Maintain an inventory of all software and hardware in use
- Plan for the retirement of end-of-life systems that can no longer be patched
Remote and hybrid working security
The shift to remote and hybrid working has significantly expanded the attack surface for most organisations. Employees working from home or public spaces face risks that do not exist in a controlled office environment. Key risks and mitigations:
- Public Wi-Fi (man-in-the-middle attacks): use a VPN or mobile data hotspot for all work activity
- Shoulder surfing: use a privacy screen filter and sit with your back to the wall
- Unsecured home networks: ensure home routers are updated and use WPA3 encryption
- Personal devices accessing work systems: enforce device management policies
- (MDM) and require PIN/biometric lock
- Blurred boundaries between personal and work accounts: use separate devices or profiles for work and personal use
Ensure that MFA is mandatory for all remote access. Consider implementing Zero Trust Network Access (ZTNA) as a more secure alternative to traditional VPNs.
Device management
Every device that connects to your network or accesses your data is a potential entry point for attackers. This includes laptops, smartphones, tablets, and increasingly IoT devices such as smart printers, building access systems, and connected equipment.
- Maintain an inventory of all devices with access to company systems
- Enforce minimum security standards (PIN/biometric lock, encryption, up-to-date OS)
- Use Mobile Device Management (MDM) software to enforce policies and remotely wipe lost or stolen devices
- Ensure devices are securely wiped before disposal or reuse
- Restrict the use of personal devices for work where possible, or enforce clear BYOD (Bring Your Own Device) policies
- Do not overlook IoT devices; they are often missed in security strategies but can provide attackers with access to wider networks
Clear desk, clear screen
Sensitive documents should be locked away when not in use, and computer screens should be locked whenever you step away from your desk. This protects against both physical intruders and opportunistic snooping. Confidential waste should be disposed of using locked confidential waste bins and professional disposal services, or shredded onsite.
Supply chain due diligence
Your security is only as strong as your weakest supplier. Before engaging any supplier that will have access to your systems or data, conduct proper due diligence:
- Do they hold relevant security accreditations? (ISO 27001, Cyber Essentials, SOC 2)
- What is their data protection policy?
- Who are their sub-processors or sub-contractors?
- What is their incident response process?
- What contractual protections can they offer?
The NCSC's 12 Principles of Supply Chain Security (ncsc.gov.uk) provide a useful framework, organised around four stages: understand the risks, establish control, check your arrangements, and continuously improve. Set minimum security standards for all suppliers and review them regularly. Require evidence, not just self-attestation.
The UK Cyber Security Breaches Survey 2025/2026 (gov.uk/government/statistics/ cyber-security-breaches-survey-20252026) highlighted continuing weaknesses in supply chain risk management, noting that only one in ten businesses reported reviewing risks associated with their immediate suppliers.
Incident response planning
No security posture is perfect. The question is not whether you will experience a cyber incident, but whether you are prepared to respond effectively when you do. An incident response plan should cover:
- Detection: how will you know an incident has occurred? What monitoring is in place?
- Containment: how will you isolate affected systems to prevent the spread?
- Eradication: how will you remove the threat from your environment?
- Recovery: how will you restore systems and data? Are your backups tested and offline?
- Communication: who needs to be notified? (Customers, regulators, insurers, law enforcement)
- Review: what can you learn from the incident to prevent recurrence?
Test your plan regularly. A plan that has never been exercised is unlikely to work under pressure. Run tabletop exercises at least annually. The IBM Cost of a Data Breach Report 2025 (ibm.com/reports/data-breach) recommends regularly testing incident response plans and backups, defining clear roles in the event of a breach, and conducting crisis simulations.
Backup best practice: Maintain regular, tested backups following the 3-2-1 rule: three copies of data, on two different media types, with one copy stored offline or off-site. Ransomware increasingly targets backup systems, so offline backups are essential.
Need help building or testing your incident response plan? Access Managed Services provides 24/7 SOC monitoring, threat containment, and incident response support so threats are identified and contained before your team even notices.
Compliance and regulation
Cyber security is not just a technical issue. It is a legal and regulatory one. Organisations operating in the UK face a growing body of requirements.
UK GDPR and Data Protection Act 2018
Under UK GDPR, organisations must implement 'appropriate technical and organisational measures' to protect personal data. A breach of personal data must be reported to the ICO within 72 hours of becoming aware of it, if it is likely to result in a risk to individuals' rights and freedoms. Affected individuals must also be notified without undue delay where the risk is high. Fines for serious breaches can reach £17.5 million or 4% of global annual turnover.
Cyber Essentials
Cyber Essentials (ncsc.gov.uk/cyberessentials/overview) is a UK government-backed certification scheme that helps organisations protect against the most common cyber threats. It covers five key controls: firewalls, secure configuration, user access control, malware protection, and patch management. Cyber Essentials Plus includes independent technical verification. Both are increasingly required by public sector contracts and are a strong baseline for any organisation. Insurance data shows that organisations with Cyber Essentials certification are 80% less likely to make a cyber insurance claim.
ISO 27001
ISO 27001 is the international standard for information security management systems (ISMS). It provides a systematic approach to managing sensitive information and demonstrates to clients and partners that you take security seriously.
UK Cyber Governance Code of Practice (2025)
Launched in April 2025, the UK Cyber Governance Code of Practice sets board-level expectations for cyber security governance. It links to the NCSC Board Toolkit (ncsc.gov.uk) and signals the direction of travel for UK regulation. Cyber security is increasingly a board-level responsibility, not just an IT issue.
Cyber Security and Resilience Bill
The UK's Cyber Security and Resilience Bill (policy statement published April 2025) signals expanded scope for essential digital services, stronger regulator powers, and enhanced incident reporting requirements. Organisations in regulated sectors should monitor its progress closely.
When things go wrong
If you suffer a breach, your obligations typically include:
- Notify affected individuals promptly, explaining what happened and what steps you are taking
- Report to the ICO within 72 hours (if the breach poses a risk to individuals)
- Notify your cyber insurance provider and follow their guidance
- Report to Action Fraud (actionfraud.police.uk) if a crime has been committed
- Preserve evidence for investigation
Do not pay ransoms without taking legal and law enforcement advice first.
Where to get help
National Cyber Security Centre (NCSC)
The NCSC is the UK's national authority on cyber security. It provides free, authoritative guidance for organisations of all sizes, including the Cyber Essentials scheme, the 10 Steps to Cyber Security framework, and the Small Business Guide. It is the first place any UK organisation should turn for cyber security guidance.
Cyber Essentials certification
Achieving Cyber Essentials certification demonstrates a baseline level of security to clients, partners, and insurers. It is a practical starting point for any organisation looking to formalise its security posture. UK organisations with a turnover under £20m that achieve certification are also entitled to free cyber liability insurance.
Managed security services
For organisations without in-house security expertise, a Managed Security Service Provider (MSSP) can provide monitoring, threat detection, incident response, and ongoing security management. When selecting an MSSP, look for relevant accreditations (ISO 27001, Cyber Essentials Plus) and ask about their own security practices.
Security awareness training
Regular, engaging training is essential. Look for providers that offer simulated phishing exercises, interactive modules, and role-specific content. Training should be ongoing, not a one-off annual event.
Action Fraud
Action Fraud is the UK's national reporting centre for fraud and cybercrime. Report incidents here and receive a crime reference number.
Cyber insurance
Cyber insurance can help cover the financial costs of a breach, including legal fees, notification costs, business interruption, and ransom payments. However, insurers are increasingly requiring evidence of baseline security controls before providing cover, and premiums reflect the risk profile of your organisation.
Quick reference: cyber security checklist
People and culture
- All staff have received cyber security awareness training in the past 12 months
- Simulated phishing exercises are conducted regularly
- A blame-free incident reporting culture is in place
- Security champions are identified in key teams
Technical controls
- MFA is enabled on all critical accounts
- A password manager is in use across the organisation
- All software and operating systems are kept up to date
- Anti-virus/endpoint protection is installed and current
- A firewall is in place and correctly configured
- Regular, tested backups are maintained (including offline copies)
Processes and policies
- A written cyber security policy exists and is reviewed annually
- A clear desk/clear screen policy is in place
- Remote working security guidelines are documented
- A formal incident response plan exists and has been tested
- Supply chain due diligence is conducted for all key suppliers
- A process exists to verify identity before acting on urgent requests
Compliance
- UK GDPR obligations are understood and met
- Cyber Essentials certification is in place (or planned)
- The ICO breach notification process is understood
- Cyber insurance is in place and reviewed annually
Not sure where to start? Access Managed Services can help.
Implementing everything in this guide takes time, expertise, and ongoing vigilance. Access Managed Services works with UK businesses of all sizes to take the complexity out of cyber security - from baseline Cyber Essentials certification through to 24/7 SOC monitoring and full managed security.
Sources and further reading
- NCSC: ncsc.gov.uk
- NCSC 10 Steps to Cyber Security: ncsc.gov.uk/collection/10-steps
- NCSC Cyber Essentials: ncsc.gov.uk/cyberessentials/overview
- UK Cyber Security Breaches Survey 2025/2026 (DSIT and Home Office): gov.uk/government/statistics/cyber-security-breaches-survey-20252026
- IBM Cost of a Data Breach Report 2025: ibm.com/reports/data-breach
- Verizon 2025 Data Breach Investigations Report: verizon.com/business/resources/reports/dbir
- Microsoft Digital Defense Report 2025: microsoft.com/en-us/corporate-responsibility/cybersecurity/microsoft-digital-defense-report-2025
- Action Fraud: actionfraud.police.uk
This guide is intended as an educational resource and starting point. Cyber threats evolve rapidly. We recommend reviewing your security posture at least annually and consulting qualified security professionals for advice tailored to your organisation.
AU & NZ
SG
MY
US
IE