Technology

Five Essential Cyber Security Checks for UK Small Businesses This September

September is a useful time to review your business’s cyber security before the final quarter. These five practical checks cover account access, software updates, backups, staff awareness and remote working, helping you reduce avoidable risks and prepare for disruption.
Five Essential Cyber Security Checks for UK Small Businesses This September

As teams return from summer holidays and attention turns to autumn trading, September offers an opportunity to tackle security tasks that may have slipped down the priority list. For small businesses, even a brief loss of access to email, payment systems or customer records can interrupt daily operations.

The threat is widespread. The government’s Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses reported a cyber security breach or attack in the previous 12 months. That figure includes attempted attacks identified by businesses, rather than only incidents resulting in stolen data or financial losses.

Improving protection does not have to begin with a large technology investment. Reviewing a few essential controls can help identify gaps and give your team a clearer understanding of what to do when something goes wrong.

1. Review Who Can Access Your Accounts

Start with the systems your business relies on most: email, banking, accounting software, customer databases and shared file storage. Check who has access, what permissions they hold and whether they still need them.

Remove accounts belonging to former employees and contractors, including temporary summer staff. Review administrator access carefully, limiting powerful permissions to people who need them for their role. Where possible, give each person an individual account so access can be managed and withdrawn reliably.

Enable multi-factor authentication, or MFA, wherever it is available, prioritising email and other critical services. This adds verification beyond a password, making it harder for someone to access an account using stolen credentials alone.

Some methods offer stronger protection than others. The NCSC’s guidance on multi-factor authentication recommends approaches that better resist phishing. Ask your IT provider about suitable options, including passkeys or security keys where supported, and ensure account recovery arrangements are secure.

2. Check Software Updates and Unsupported Devices

Software updates often fix security weaknesses, making them an essential maintenance task rather than an occasional convenience.

Review laptops, desktops, smartphones and tablets, along with browsers and business applications. Include equipment that is easily forgotten, such as routers and other internet-connected devices. The NCSC’s small organisations guide provides practical advice on protecting devices and accounts.

Enable automatic updates wherever practical and check that installations have completed. A device waiting for a restart may still have outstanding updates, while an unused laptop may have missed several months of maintenance.

Identify software and equipment that no longer receive security support. These need a replacement or migration plan, rather than repeated checks for updates that will never arrive.

If an external provider manages your IT, ask for confirmation of outstanding updates, unsupported systems and who is responsible for resolving them. Give each action an owner and a deadline.

3. Test Whether Your Backups Can Restore Operations

A successful backup notification is useful, but it does not prove your business can recover quickly. The real test is whether you can restore the information and services you need.

Check that backups cover essential customer records, financial information and working documents. Confirm how frequently they run, how long copies are retained and how much recent work could be lost between backups.

Protect backup copies from the same attack that could affect your live systems. Depending on your setup, this may involve offline storage or immutable backups, which prevent changes or deletion for a defined period. The NCSC’s ransomware-resistant backup guidance explains the principles behind protecting recovery copies.

Arrange a controlled restoration test with your IT team or provider. Record what was recovered, whether it worked and how long the process took.

Backups can reduce disruption, but they cannot erase every consequence of ransomware. Attackers may also steal information and threaten to publish it, as the NCSC’s ransomware guidance explains. Recovery planning therefore needs to address both restoring systems and responding to the wider incident.

4. Refresh Phishing Awareness and Payment Checks

A short, practical refresher can help staff recognise suspicious requests without expecting them to become security specialists.

Use examples relevant to their work: an unexpected invoice, a password-reset message, a supplier requesting new bank details or an urgent payment instruction apparently sent by a director. Explain that convincing branding and fluent writing do not establish that a message is genuine.

For payment requests and changes to bank details, require verification through an established contact method. Call a supplier using a number already held on file, rather than one included in the suspicious message.

Make reporting straightforward. Staff should know who to contact if they receive something unusual, click a link or enter information on a questionable website.

The NCSC’s phishing guidance stresses that fear of reprimands can discourage prompt reporting. Encourage people to raise concerns quickly, and support training with technical protection and clear approval processes. Security should not depend on someone spotting every deceptive message.

5. Review Remote Working and Mobile Security

Company information needs protection wherever work takes place. Check that devices used for business have appropriate encryption, automatic screen locking, supported software and security protection.

Clarify whether staff may use personal devices and which applications are approved for accessing or storing business data. Ensure there is a clear process for reporting a lost phone or laptop, including who can revoke access or remotely wipe managed devices where available.

Remote access should follow your organisation’s agreed setup. A company-managed VPN may be appropriate for accessing internal systems over an untrusted network; the NCSC’s VPN guidance explains its role in protecting connections.

However, a VPN does not make a fraudulent website or compromised device safe. Secure accounts, updated devices and approved services remain essential.

Turn Your September Review Into Regular Maintenance

Finish the review with a short action list, named owners and realistic deadlines. Keep emergency IT contact details somewhere accessible if company email becomes unavailable, and make sure someone is responsible for checking progress.

Cyber security also belongs in wider business planning. Our guide to the cash flow habits that help SMEs stay in control explores another part of maintaining operational resilience.

September can be the starting point, but access reviews, updates, backup tests and staff reminders should continue throughout the year. Consistent maintenance helps your business enter the final quarter better protected and better prepared to recover if disruption occurs.

Continue Reading