Cyber Security
What is cyber security? A plain-English guide for small businesses
Cyber security explained for UK small business owners: what it covers, the threats that actually hit SMEs, and the baseline controls Cyber Essentials expects.
By Dig IT SolutionsUpdated 8 September 20266 min read
Short answer
Cyber security is the practice of protecting your systems, accounts and data from being accessed, damaged or held to ransom by people who should not have them. It comes down to five areas: controlling who can log in, keeping software updated, protecting devices from malware, configuring firewalls and systems securely, and being able to recover from backups.
Cyber security is one of those terms that means everything and therefore nothing. Vendors use it to sell products, insurers use it in questionnaires and the news uses it for nation-state espionage. None of that helps the managing director of a 30-person firm in Hertford who wants to know whether the business is exposed and what to do about it. This guide explains the subject in terms that apply to a business of your size.
Cyber security in one paragraph
Cyber security is everything you do to keep your systems, accounts and data available to the right people and unavailable to the wrong ones. Security professionals summarise this as three properties: confidentiality (only authorised people can see it), integrity (it has not been tampered with) and availability (it is there when you need it). Ransomware attacks availability. A phished mailbox attacks confidentiality. An attacker changing bank details on an invoice attacks integrity. Every control you put in place protects one or more of those three.
The threats that actually reach small businesses
Textbooks list dozens of attack types. Four account for almost everything that hits UK SMEs.
Phishing. Messages that trick someone into giving up a password, approving a login or paying a fraudulent invoice. The Cyber Security Breaches Survey finds it to be the most common attack by a wide margin. See phishing attacks explained.
Account takeover. Attackers try leaked passwords from other breaches against your Microsoft 365. Without multi-factor authentication, a reused password is all they need.
Ransomware. Malware that encrypts your files and servers, increasingly after first copying your data to threaten publication. Usually delivered via phishing, an unpatched remote access service or a stolen login. The NCSC's ransomware hub is the UK reference.
Fraud through compromised email. No malware at all, just a convincing request from a hacked or spoofed supplier to change bank details. Often the most expensive single incident an SME suffers.
Denial-of-service attacks, zero-day exploits and man-in-the-middle interception exist, but for a typical small business they are far down the list. Spend your attention on the four above.
The five areas every business has to cover
The UK government's Cyber Essentials scheme, overseen by the NCSC, distils cyber security for organisations of any size into five technical controls. They are a good map of the subject because they were designed to stop the common attacks listed above.
| Control | What it means in practice | Which threat it blocks |
|---|---|---|
| User access control | Named accounts, least privilege, MFA on cloud services, removing leavers promptly | Account takeover, insider misuse |
| Security update management | Patching operating systems, applications and firmware within 14 days of a critical fix | Ransomware, exploited services |
| Malware protection | Endpoint protection on every device, ideally EDR that watches behaviour | Ransomware, malicious attachments |
| Secure configuration | Removing default passwords and unneeded software, locking down settings | Exploited services, lateral movement |
| Firewalls | A boundary firewall plus the device firewall, with nothing exposed unnecessarily | Direct attacks on office and remote access |
Add two non-technical elements and you have the whole picture for an SME: tested backups you can recover from, and staff who know how to spot phishing and report it. Our Cyber Essentials guide goes through the controls in detail.
The layers behind the controls
If you want the vocabulary that vendors and insurers use, here is how the specialist areas map onto a small business.
- Identity and access management. Who can log in, from where, with what proof. In practice: Microsoft Entra ID, MFA, conditional access, and a joiner-leaver process. This is the single most important layer for a cloud-first SME.
- Endpoint security. Protecting laptops, desktops, servers and phones. Modern practice is endpoint detection and response rather than traditional antivirus, because it detects behaviour rather than relying on a list of known files.
- Network security. Firewalls, segmented Wi-Fi so guests cannot reach your servers, secure site-to-site links for multiple offices, and no remote desktop open to the internet.
- Email security. Filtering, link checking and sender authentication (SPF, DKIM, DMARC) so that phishing is reduced before it reaches people and your own domain cannot easily be spoofed.
- Data protection. Encryption on devices, sensible sharing permissions in SharePoint, retention rules and the ability to prove where personal data is, which is what UK GDPR and the ICO expect.
- Backup and recovery. Copies of your data that an attacker cannot reach, tested regularly. Cyber security without recovery is only half a plan.
- Monitoring and response. Somebody, or something, watching for the early signs of compromise and acting on them, rather than discovering the problem months later.
- People and policy. Awareness training, a written security policy, and an incident plan that says who does what when something goes wrong.
Why a small business is a target
The most common objection we hear is "nobody would bother attacking us". Attackers do not choose targets by reading company websites. They run automated tools that scan the whole internet for exposed services, try leaked passwords against every Microsoft 365 tenant, and send phishing to every address they can buy. A small business gets hit because it is there, and because it is more likely than a large one to have MFA off, a server two years behind on updates and a backup nobody has tested.
The consequences scale down but do not disappear. A week without systems, a fraudulent payment that the bank will not refund, a reportable breach to the ICO and the awkward conversations with clients that follow. For most SMEs the realistic question is not whether an attack will be attempted but whether the basics were in place when it was. Our article on why cyber security matters for small businesses covers the commercial case in more depth.
Cyber security versus IT support
A common misunderstanding: assuming that because someone looks after your computers, they are also securing them. Good managed IT includes a lot of security work (patching, backups, account management), but monitoring, incident response, security policy and certification are distinct activities that need to be explicitly in scope. Our comparison of IT support and cyber security sets out what sits where, and what to check in your current contract.
How to build a sensible programme
For a business of up to 250 people, this sequence works.
- Find out where you are. A cyber security audit against the five controls tells you the gaps in an afternoon.
- Fix the fundamentals. MFA everywhere, patching under management, EDR on every device, firewalls configured, leavers removed. Most of this can be done in weeks.
- Sort recovery. Backups that follow the 3-2-1 principle, including an offline or immutable copy, with a documented restore test.
- Train the people. Short, regular awareness sessions and simulated phishing.
- Write it down. A security policy, an acceptable use policy and an incident plan.
- Certify. Cyber Essentials gives you an external check and something to show customers and insurers.
- Keep it running. Monitoring, quarterly reviews, annual recertification. Security decays without maintenance.
What to do next
If you cannot say with confidence which of the five controls are fully in place in your business, an IT health check will tell you. It covers accounts, patching, endpoint protection, firewalls and backups, and gives you a prioritised list rather than a sales pitch.

