Cyber threats aren’t slowing down — if anything, 2026 is shaping up to be the most challenging year yet for small businesses. Two-thirds of UK SMEs experienced at least one cyber attack in 2025, and attackers are getting smarter. The good news? Most of the things that will protect your business aren’t complicated or expensive. Here’s what you should be doing right now.
1. Treat Phishing as Your Biggest Risk — Because It Is
Phishing is behind the vast majority of cyber incidents affecting small businesses, and in 2026 those emails are increasingly convincing, often crafted with AI. If your team can’t spot a well-written phishing attempt, your technical defences don’t matter much. Run a phishing simulation, see who clicks, and use it as a no-blame learning opportunity. Free tools exist — you don’t need a big budget to start.
2. Get Cyber Essentials Certified
Cyber Essentials is a UK government-backed certification that covers five basic security controls every business should have in place. It’s not just a badge — certified organisations suffered significantly lower breach costs last year. It also increasingly comes up in supplier and procurement questionnaires, so it’s becoming a commercial advantage as much as a security one. Costs start from a few hundred pounds.
3. Turn On MFA — Everywhere, Not Just Email
Multi-factor authentication blocks the vast majority of automated credential attacks, and it’s free on most platforms. Most businesses have it switched on for email but forget about their accounting software, CRM, or remote access tools. Go through every system your team logs into and make sure MFA is enabled across the board. It takes minutes and makes stolen passwords far less useful to attackers.
4. Lock Down Your Microsoft 365 Settings
If your business is on Microsoft 365, the default settings out of the box leave gaps that attackers know how to exploit. Make sure MFA is enforced for every user, old-style authentication methods are blocked, and you know who has admin access. If you set it up a few years ago and haven’t looked at it since, it’s worth a review — a lot may have changed.
5. Check Your Backup Actually Works
Having a backup is one thing. Knowing it works is another. When did you last do a test restore? If you can’t remember, that’s your answer. Whether you’re backing up to the cloud, a local device, or both, the only backup that matters is one you can actually restore from. Schedule a test this month — it takes an hour and could save your business.
6. Review Who Has Access to What
People change roles, move on, or leave entirely — but their logins often stay active. Take some time to go through user accounts across your key systems. Remove old accounts, pull back access that’s no longer needed, and make sure admin rights are only held by the people who genuinely need them. It’s one of the easiest wins in security and one of the most overlooked.
7. Don’t Let Old Software Be the Open Door
Unpatched software is one of the most common ways attackers get in. Windows 10 reached end of support in October 2025, meaning no more security updates — if you’re still running it, you’re running a risk. Check what’s in your environment and prioritise anything that’s out of date or no longer supported. If updates have been piling up, now is the time to clear them.
8. Write Down What You’d Do If Something Went Wrong
If your systems were hit tonight, who would you call? What would you do first? Most small businesses have a rough plan in someone’s head but nothing written down. Even a single page covering who to contact, how to isolate affected machines, and how to access your backups makes an enormous difference when things get chaotic. You don’t need a 40-page document — just something your team can follow under pressure.
9. Don’t Assume You’re Too Small to Be Targeted
Attackers don’t manually pick their victims — automated tools scan the internet constantly looking for weak passwords, unpatched systems, and open doors. Small businesses are attractive precisely because they tend to have fewer defences. If you’ve been operating on the assumption that you’re not interesting enough to attack, it’s worth revisiting that view.
10. Make Cybersecurity Someone’s Responsibility
In small businesses, security often belongs to everyone — which in practice means it belongs to no one. Assign one person ownership of the basics: checking backups, reviewing accounts, making sure updates are being applied. It doesn’t need to be a full-time role, just someone with a simple checklist and the time to work through it regularly.
Not Sure Where to Start?
If any of this has hit a nerve, we can help. Whether it’s a quick review of your setup or a full IT health check, ML Services is here to make technology work for your business — not against it.
Get in touch today to book a free, no-obligation chat about your IT.
ML Services (Sussex) Ltd — Practical IT support for small businesses across Sussex and beyond.
