Skip to main content
Dig IT Solutions logo

Cyber Security

How to find the cyber security weaknesses in your small business

A cyber security self-assessment for UK small businesses built on the five Cyber Essentials controls plus backups, people and suppliers, with a fix for each.

By Dig IT SolutionsUpdated 8 September 20268 min read

Short answer

Check your business against the five Cyber Essentials controls: who has access and whether MFA is enforced, whether every device is patched within 14 days, whether all devices run managed malware protection, whether firewalls and settings are locked down, and whether default passwords are changed. Then test backups, staff awareness and supplier access.

Weak cyber security in a small business is rarely one dramatic hole. It is a pattern of small gaps that nobody owns: the MFA rollout that covered most people, the server that missed a few updates, the account belonging to someone who left in March. Individually each looks minor. Together they are how ransomware and invoice fraud actually happen.

This guide gives you a structured way to find those gaps. We have built it around the five technical controls of the UK's Cyber Essentials scheme, because they were designed by the NCSC to stop the common attacks that hit organisations of every size, and because assessing against them gets you most of the way to certification. We then add the three areas Cyber Essentials does not cover but every SME must: backups, people and suppliers.

Why weaknesses build up unnoticed

In a business of up to 250 people, security usually belongs to whoever is nearest to IT: an office manager, a director, an external support company whose contract covers "keeping things working". Systems get added as the business grows, each configured for convenience at the time. Staff join and leave. Nobody is measuring the whole picture, so the gaps accumulate quietly.

Businesses tend to discover the truth in one of five ways: a successful phishing email, a ransomware infection, a cyber insurance questionnaire they cannot honestly complete, a larger customer's supplier security review, or a Cyber Essentials application that fails on the first pass. All of those are expensive ways to learn what an afternoon's assessment would have shown. The Cyber Security Breaches Survey consistently finds that only a minority of small businesses have carried out any formal risk assessment, which is exactly the gap attackers rely on.

Control 1: user access control

This is where most SME weaknesses live, and it is where to start.

What to check

  • Does every person have their own named account, in every system? List shared logins ("accounts@", "reception", the CRM admin everyone uses).
  • Is multi-factor authentication enforced for every user on Microsoft 365 or Google Workspace, not just enabled and left optional? Check the remote access system, the accounts package and the CRM too. Cyber Essentials requires MFA on all cloud services where it is available.
  • Who has administrator rights? On Microsoft 365, on the domain, on individual PCs. The answer should be a very short list of people who use a separate admin account only for admin tasks.
  • When did someone last leave, and is every one of their accounts disabled? Check Microsoft 365, the VPN, the accounts software, the CRM, the website, the social media and the door entry system.
  • Do suppliers or contractors have logins, and are they still needed?

What weak looks like: MFA "rolled out" but with exceptions for a director and the accounts team, six global administrators, a former employee still able to reach the shared drive through the VPN, a password spreadsheet on the shared drive.

How to fix: enforce MFA through conditional access with no exceptions, reduce admins to two named accounts, run an access review every quarter, introduce a formal joiner and leaver process and use our offboarding checklist.

Control 2: security update management

Attackers overwhelmingly exploit known, already-patched flaws, because there are always businesses that have not applied the patch.

What to check

  • List every device: desktops, laptops, servers, phones, and also the firewall, switches, access points, NAS and printers. Firmware counts.
  • Is anything running an operating system that is out of support? Windows 10 reached end of support in October 2025, Windows Server 2012 went earlier. Unsupported software cannot be made compliant and must be replaced or paid for under extended support.
  • How are updates applied? "Automatically" is only true if someone confirms it. Ask for a report showing the patch status of every device.
  • Are third-party applications (browsers, PDF readers, Java, remote access tools) patched, or only Windows?
  • Are critical and high-severity patches applied within 14 days? That is the Cyber Essentials requirement.

What weak looks like: a server that "we don't reboot because of the accounts system", laptops that have been closed in a drawer for months, a firewall on the firmware it shipped with, nobody able to produce a patch report.

How to fix: put every device under remote monitoring and management (RMM) so patching is scheduled, reported and chased, retire unsupported systems, and include firmware in the schedule. This is standard within proactive monitoring.

Control 3: malware protection

What to check

  • Does every device, including servers and Macs, have protection installed, running and reporting to a central console?
  • Is it traditional antivirus or endpoint detection and response (EDR)? Antivirus checks files against known signatures, EDR watches behaviour and can isolate a machine automatically. See EDR vs antivirus.
  • Who receives the alerts, and what do they do with them?
  • Can staff install software freely? Application control (only permitted software runs) is one of the strongest defences against ransomware.

What weak looks like: free consumer antivirus on some machines and nothing on the server, alerts going to an unread mailbox, users as local administrators installing whatever they like.

How to fix: managed EDR on every endpoint with someone responsible for alerts, remove local admin rights, restrict installs.

Control 4: secure configuration

Default settings favour convenience over safety.

What to check

  • Are default passwords changed on the router, firewall, switches, Wi-Fi controller, NAS, printers and CCTV?
  • Is unneeded software removed from new machines, and are unused services (guest accounts, old file shares) disabled?
  • Are devices encrypted (BitLocker on Windows, FileVault on Mac) with the recovery keys stored centrally?
  • Do screens lock automatically? Is auto-run for USB media disabled?
  • Is the Microsoft 365 tenant configured securely: legacy authentication blocked, external forwarding disabled, app consent restricted, sharing settings sensible?

What weak looks like: a Wi-Fi controller on admin/admin, laptops with no disk encryption, a Microsoft 365 tenant on defaults from 2018, a NAS accessible from the internet.

How to fix: a configuration baseline applied through Intune or group policy for devices, and a hardening pass on Microsoft 365 as part of a Microsoft 365 security review.

Control 5: firewalls

What to check

  • Is there a proper boundary firewall (not just an ISP router) and is it under support with current firmware?
  • What is exposed to the internet? Remote desktop (RDP) open to the world is one of the most common causes of ransomware in SMEs. Check for open ports for the NAS, CCTV, the phone system and any "temporary" rules.
  • Is remote access via VPN with MFA, or via a properly secured gateway?
  • Is the Windows firewall enabled on every device, including laptops used at home and in cafés?
  • Is guest Wi-Fi separated from the business network?

What weak looks like: RDP on port 3389 open "so the accountant can get in", a firewall nobody has logged into for two years, guests and the finance server on the same Wi-Fi.

How to fix: close everything that does not need to be open, move remote access to VPN or a modern gateway with MFA, segment the network, and put the firewall on a support and firmware schedule. For multi-site businesses, secure site-to-site links as in our Mr Plant Hire case study.

Beyond the five controls: backups, people, suppliers

Cyber Essentials deliberately excludes these, but no SME assessment is complete without them.

Backups. When did you last restore a file, and a whole server, from backup? Is there a copy an attacker with your admin password could not delete (offline, immutable or in a separate cloud account)? Does the backup include Microsoft 365, which Microsoft does not back up for you? Is the recovery time measured or assumed? Weak looks like "it backs up to the NAS" with the NAS on the same network. Our backup and disaster recovery page sets out what good looks like.

People. When did staff last have any security training? Have you ever run a simulated phishing email and measured the click rate? Is there a written procedure for verifying supplier bank-detail changes? Do people know who to tell if they click something? Weak looks like an induction slide from years ago and a culture where reporting a mistake feels risky.

Suppliers. Which external firms have access to your systems or data: IT support, accountants, software vendors, cloud platforms? Do you know what security they operate, and are there contracts that say so? Under UK GDPR the ICO expects processor contracts and due diligence for anyone handling personal data on your behalf.

Turning findings into a plan

An assessment produces a long list. Do not try to fix it all at once. Rank each finding by two questions: how likely is it to be exploited, and how bad would it be? Then work down the list.

For most SMEs the order is predictable:

  1. MFA everywhere and leaver accounts removed (days).
  2. Anything exposed to the internet closed, RDP in particular (days).
  3. Unsupported operating systems replaced and patching put under management (weeks).
  4. EDR on every device, local admin removed (weeks).
  5. Backups restructured with an offline or immutable copy and a documented restore test (weeks).
  6. Configuration baseline, Microsoft 365 hardening, network segmentation (one to two months).
  7. Training, policy, incident plan, supplier review (ongoing).

Record what was fixed and when. The next assessment then measures progress, and if you go for Cyber Essentials the evidence is already there. Assessment is a snapshot, keeping the controls in place is the ongoing job, which is why we argue for continuous monitoring rather than periodic checks.

What to do next

If you would like the technical parts done for you, a cyber security audit covers all five controls plus backups, external exposure and Microsoft 365 configuration, and comes back as a prioritised list in plain English. Start with an IT health check.

Frequently asked questions

What is the most common cyber security weakness in small businesses?
Access control, specifically accounts without multi-factor authentication and accounts that should no longer exist. In assessments of businesses of up to 250 people, the usual findings are MFA switched on for some users but not all, shared logins, former staff still active in one or two systems, and more people with administrator rights than anyone can explain.
How often should a small business assess its cyber security?
Do a structured assessment against the five Cyber Essentials controls at least annually, and again after any significant change such as a new system, an office move or a merger. Between assessments, the basics (patching, account changes, backup success) should be monitored continuously rather than checked occasionally.
Can I assess our cyber security ourselves?
You can get a long way with the checklist in this article and the free Cyber Essentials readiness questions published by IASME. What an internal review usually misses is the technical detail: what is actually exposed to the internet, whether patches really applied, whether backups actually restore. An external audit or vulnerability scan fills those gaps.
What is the difference between a vulnerability scan and a penetration test?
A vulnerability scan is automated: it checks your systems against a database of known weaknesses and lists what it finds. A penetration test is a person actively trying to break in, chaining weaknesses together the way a real attacker would. Most SMEs need regular scanning and an audit, a penetration test is worth it for higher-risk firms or when a client demands one.
How do businesses usually discover their security is weaker than they thought?
Usually through an event: a phishing email that succeeds, a ransomware infection, an insurer's questionnaire, a larger customer's supplier security review or a Cyber Essentials application that fails. Each of those tends to reveal a chain of gaps rather than a single fault, which is why a proactive assessment is cheaper than waiting.
What should I do once I have found the weaknesses?
Rank them by how likely they are to be exploited and how much damage would follow, then fix in that order. For most SMEs that means MFA and leaver accounts first, then patching and unsupported systems, then endpoint protection and backups. Write down what was fixed and when, so the next assessment starts from evidence rather than memory.

Next step

Not sure how exposed you are?

An IT health check reviews your security, backups, Microsoft 365 and network and gives you a prioritised list, whether or not you work with us afterwards.

WhatsApp us