Skip to main content
Cyber Security 12 min read

10 Cyber Security Mistakes Small Businesses Make

A practical guide for UK business owners and teams who want to reduce avoidable cyber risk without building a complicated security programme.

By NorthWave Solutions Updated 29 August 2026 Practical SME guide

Cyber security is often treated as something only larger organisations need to take seriously. In practice, a small business can have just as much to lose from a compromised email account, stolen credentials, ransomware incident or fraudulent payment.

The good news is that a useful security baseline does not have to be enormous. The National Cyber Security Centre (NCSC) recommends straightforward measures for small organisations covering accounts, email, devices, backups and recognising attacks. This guide turns those areas into a practical review you can work through with your team.

A useful rule of thumb

Start with the things that would cause the most damage if they were compromised: your email, privileged accounts, customer or financial information, important devices and business-critical data.

1. Relying on passwords alone

Passwords are still common entry points for account compromise. Reused, weak or exposed passwords can put multiple services at risk at once. NCSC guidance recommends strong, unique passwords and two-step verification for important accounts, and recommends using passkeys where they are available.

For a small business, the practical question is not “Do we have passwords?” but “Which accounts would be most damaging if someone else gained access?” Email, Microsoft 365 administration, banking, payroll, website hosting, cloud storage and domain management are usually high-priority accounts.

Action check

  • List your most important online accounts.
  • Remove reused passwords and secure shared credentials.
  • Enable MFA or 2-step verification where available.
  • Use passkeys for business-critical services when supported and appropriate.

2. Protecting staff accounts but forgetting administrators

Administrator accounts can change security settings, create users, reset passwords and control business services. Giving an attacker an administrator account can therefore turn a single stolen credential into a much wider incident.

Privileged access should be limited to people who genuinely need it. Administrators should ideally have a separate standard account for everyday activities and a privileged account used only when administrative work is required.

NCSC identity guidance recommends MFA for privileged accounts and encourages separation of administrative and everyday access.

Action check

  • Identify every administrator and privileged account.
  • Confirm MFA is enforced for privileged access.
  • Remove unnecessary administrator rights.
  • Review dormant or legacy admin accounts.

3. Treating email security as somebody else's problem

Business email is a high-value target because it can expose confidential information and provide a route into other accounts. If an attacker controls a mailbox, they may be able to impersonate the employee, read sensitive conversations or use password-reset links to reach other services.

Technical controls matter, but so does the operating process around email. Staff should know how to handle unexpected login alerts, requests for payment changes and messages that ask them to disclose credentials.

NCSC guidance specifically highlights protecting business email because access to one inbox can expose other systems and information.

Make payment-change requests harder to fake

Create a simple rule for your business: a change to supplier bank details or a significant payment instruction must be independently verified using a trusted contact route. Do not rely on replying to the same email thread that requested the change.

4. Assuming “we have antivirus” means the devices are secure

Endpoint security is broader than a single antivirus product. Business laptops, desktops and phones can contain credentials, business data and access to cloud applications. A lost, stolen or compromised device can therefore become a stepping stone into other systems.

A sensible device baseline includes supported operating systems, timely security updates, screen locking, appropriate user permissions and protection against malicious software. Personal devices used for work should also be considered because they may hold business information or provide access to business accounts.

Device baseline

  • Know which devices are used for business work.
  • Keep operating systems and important applications supported and updated.
  • Use standard accounts for day-to-day work where practical.
  • Enable device encryption and screen locking where supported.
  • Have a process for lost or stolen devices.

5. Backing up files without testing recovery

A backup is only valuable if you can actually restore what the business needs. Files may become unavailable because of ransomware, accidental deletion, hardware failure, account problems, theft or other incidents.

The NCSC recommends backing up data that the organisation needs to operate and checking that backups contain the information required for recovery. It also recommends considering more than one backup location and protecting online backups with strong authentication.

Ask these four questions

  1. What business data must be recoverable?
  2. How often is it backed up?
  3. Who can delete or change the backups?
  4. When did we last test a real restoration?

Do not assume that having files in OneDrive, Google Drive or another cloud service automatically answers every backup requirement. Understand what the service protects, what it does not protect, and how you would recover if data were deleted or an account were compromised.

6. Keeping old accounts, suppliers and access permissions forever

Small businesses often accumulate accounts over time: former employees, contractors, agencies, suppliers, temporary logins and test accounts. The longer unnecessary access remains in place, the greater the chance it will be forgotten and misused.

The NCSC recommends removing unnecessary user accounts and reviewing who has access to important services.

Joiner / mover / leaver check

  • Disable accounts promptly when people leave.
  • Review permissions when responsibilities change.
  • Remove supplier access when the work ends.
  • Review shared accounts and replace them with named access where practical.

7. Letting users approve suspicious MFA prompts

MFA reduces the value of a stolen password, but a user can still be tricked into approving an unexpected authentication request. A member of staff who receives repeated prompts may eventually approve one simply to make the notifications stop.

Give staff a very simple instruction: an unexpected sign-in prompt is a security event, not a nuisance. They should deny it and report it through the business's normal support route.

Where the platform supports stronger authentication or phishing-resistant methods, evaluate those options for administrators and other higher-risk users.

8. Having no process for suspicious messages or incidents

Technical controls do not remove the need for a human response. A staff member might click a suspicious link, lose a phone, spot an unfamiliar login or discover that an account has sent messages they did not write.

The first few actions can matter more than having a perfect incident document. Staff need to know who to tell, what information to preserve and when to stop using an affected device or account.

A simple incident rule

Encourage early reporting. A staff member who thinks they may have clicked something suspicious should be able to report it immediately without worrying that they will get into trouble for asking for help.

A basic first-response sequence

  1. Tell the person responsible for IT/security.
  2. Protect or disable the affected account if appropriate.
  3. Preserve useful evidence such as the message, alert or timestamp.
  4. Check for related account or device activity.
  5. Decide whether customers, suppliers, insurers, regulators or law enforcement need to be involved.
  6. Document what happened and what should change afterwards.

9. Buying security tools without defining who owns them

A business can have several security products and still have gaps. The problem is often not the tools themselves but the ownership model. Someone needs to know what each control is supposed to do, which alerts matter, who investigates them and what happens when an alert is missed.

Before buying another product, identify the problem you are trying to solve. A smaller, well-managed set of controls can be more useful than a collection of tools that nobody reviews.

For every security tool, record:

  • What risk does it address?
  • Who administers it?
  • Who receives important alerts?
  • What happens when an alert is raised?
  • When is the configuration reviewed?

10. Never reviewing the security baseline

A security setup that was sensible two years ago may not match today's business. New staff join, people leave, devices are replaced, new cloud services are adopted and suppliers change.

Security should therefore be treated as an ongoing business process rather than a one-time installation project. A quarterly or six-monthly review is often enough to identify obvious changes that need attention, with more frequent checks for high-risk accounts and critical services.

A practical review agenda

  1. Review administrators and privileged users.
  2. Check MFA coverage and exceptions.
  3. Review important online accounts and third-party access.
  4. Check device patching and unsupported equipment.
  5. Confirm backups and test a restoration.
  6. Review recent suspicious messages or incidents.
  7. Check who owns key security tools and alerts.
  8. Update the incident contact list.

A 30-day small-business security plan

Trying to improve everything at once can become another reason to delay. A better approach is to prioritise the controls that reduce the most meaningful risks first.

Week 1 — Accounts

List critical accounts, secure administrators, remove unnecessary access and enable MFA/2SV.

Week 2 — Devices & email

Review patching, device protection, user permissions and simple email/payment verification rules.

Week 3 — Backup & recovery

Identify essential data, check backup coverage and perform a practical restoration test.

Week 4 — Response

Agree who handles incidents, how staff report concerns and which outside contacts may be needed.

Small Business Cyber Security Checklist

Use this as a quick review. A “no” answer is not a failure; it identifies something worth investigating.

  1. We know which accounts are critical to the business.
  2. Important accounts use MFA/2-step verification or another strong authentication method where available.
  3. Privileged accounts are limited and separately managed.
  4. Former staff and suppliers no longer have unnecessary access.
  5. Business devices are supported, updated and protected.
  6. Staff know how to report suspicious emails and unexpected login prompts.
  7. Payment-detail changes are independently verified.
  8. Important business data is backed up.
  9. Backups are protected from inappropriate access or deletion.
  10. A restoration test has been completed.
  11. There is a clear incident contact and basic response process.
  12. The security baseline is reviewed periodically.

What should a small business do next?

Start with visibility rather than spending. Identify the accounts, devices, services and data that matter most to your business. Then work through the highest-risk gaps first.

The NCSC provides free guidance for small and medium-sized organisations, including advice on important accounts, email, devices, backups and recognising attacks. Those resources are a useful baseline, especially for businesses that do not have a dedicated security team.

NorthWave Solutions can help businesses turn that baseline into a practical technology and security plan covering Microsoft 365, identity, devices, backup, networks and ongoing IT support.

Take the next step

Find the gaps before they become incidents.

A Free IT Health Check can help you identify sensible priorities across accounts, Microsoft 365, devices, backup, security and your wider IT environment.

Further reading

This article provides general information for business planning and is not a substitute for a security assessment, legal advice or incident-response advice tailored to your circumstances.