A sensible cyber security baseline for an SME starts with knowing the systems and information that matter, assigning ownership and applying proportionate controls to accounts, devices, email, backups and suppliers. It is an ongoing operating discipline, not a certificate, a single product or a promise that every incident can be prevented.
Start with what the business cannot easily lose
Security work is easier to prioritise when it begins with the business services, information and people that would be most affected by disruption. List the systems used for customer work, finance, communication, records, production, remote access and supplier management. Include cloud applications, shared mailboxes, mobile devices, network equipment and backup administration. For each, name a business owner and note the provider, administrator, user group and a practical recovery or escalation route.
This inventory does not need to be perfect before action starts, but unknowns should be visible. A forgotten domain account, unmanaged laptop or shared administrator login can become significant only when an incident occurs. NCSC guidance for small organisations is a useful starting point for considering common weaknesses without treating every risk as equally urgent. The goal is to make informed choices about the controls that protect the organisation's most important work first.
- Identify critical services, information, devices and suppliers.
- Name a business owner and technical contact for each priority area.
- Record shared accounts, old systems and known access exceptions.
- Rank gaps by likely business impact as well as technical severity.
Control accounts and privileged access deliberately
Most organisations depend on cloud accounts for email, files, finance, customer systems and administration. Use named accounts wherever a service allows it, apply multi-factor authentication where appropriate, and remove access promptly when roles change. Review who can create administrators, reset accounts, change payment details or access recovery methods. These rights need more scrutiny than ordinary access because they can affect many users and systems at once.
Avoid solving access problems with a permanent shared password. A shared credential makes it difficult to trace action, remove one person's access or recover safely when a device is lost. Where a shared function is genuinely needed, use the platform's designed delegation or shared-access feature and document the owner. Keep emergency access arrangements limited, protected and tested. The right design depends on the service and the organisation, so record why an exception exists and when it will be reviewed.
- Use individual accounts and appropriate multi-factor authentication.
- Review administrator, recovery and billing permissions separately.
- Remove leavers and stale access through a defined process.
- Record justified exceptions and a date to reassess them.
Keep devices and software within a manageable boundary
A device list should show who uses each laptop, desktop, phone, server or shared workstation, what it accesses and who is responsible for its maintenance. Apply supported operating systems and applications, routine updates, malware protection appropriate to the environment and secure configuration choices. A useful process also covers what happens before a device is issued, when it is lost or replaced and when it is returned. Security controls are more reliable when they fit the way people actually work.
Do not assume every device can be managed in the same way. A specialist production system, an older application or a contractor-owned device may need a separate risk decision. Document whether it is isolated, monitored, replaced, supported by a supplier or excluded from access to certain services. Hiding an unsupported dependency creates false confidence. A clear boundary gives the business a chance to decide whether to accept, reduce or transfer the risk.
- Maintain an owner-led inventory of supported and exceptional devices.
- Apply updates and security tools through a controlled routine.
- Set joiner, mover, leaver and lost-device steps in writing.
- Escalate unsupported or specialist systems for an explicit decision.
Protect email, information and everyday decisions
Email remains a route for impersonation, malicious links and requests designed to exploit urgency. Combine technical controls with a simple culture of checking unusual requests, especially those involving payments, bank details, passwords or new suppliers. Give staff a known route to report a concern without embarrassment. The response should concentrate on gathering useful facts and containing risk rather than expecting users to diagnose a threat themselves.
The ICO's data-security guidance is relevant whenever the organisation holds personal information. Consider what data is collected, where it is stored, who needs access and what should happen if information is sent to the wrong place or cannot be reached. Use permissions, sharing settings and retention choices that suit the data and business process. These controls support better handling, but they do not by themselves determine legal duties or demonstrate compliance with any particular regime.
- Use sensible email protections and report suspicious messages quickly.
- Verify unusual payment, supplier and access requests through another route.
- Limit access and sharing according to the information's purpose.
- Train staff on the actions expected when something looks wrong.
Prepare for disruption and keep improving
Every organisation should be able to describe how an issue is reported, who makes business decisions, who contacts suppliers and how important services are recovered. Keep an accessible contact list and a short record of priorities outside the systems most likely to be affected. Check backups, recovery access and supplier escalation routes before an incident, not only during one. A practical exercise can reveal missing information, unclear authority or a process that is too complicated to use under pressure.
Review the baseline after a business change, new supplier, office move, major software change or security event. Look at recurring access requests, unpatched devices, unusual email reports and unresolved risks. Assign a named owner and next action rather than leaving a finding in a report. Continuous improvement is often a series of small, accountable changes. It does not mean the organisation can eliminate all cyber risk or predict the result of a future incident.
- Maintain an incident reporting, decision and supplier-contact route.
- Test a suitable restore, access recovery or tabletop scenario.
- Review controls after material technology or people changes.
- Track gaps to an owner, decision and planned follow-up.
Security controls have limits
This guide describes practical areas to assess; it cannot certify an organisation, establish compliance with a legal or contractual standard, or prove that an incident will not occur. The suitable controls and priorities depend on your systems, information, people, suppliers, risk appetite and evidence from ongoing review and testing.
Decisions to make first
A short risk discussion is most useful when it produces clear ownership and next actions rather than an unranked list of products.
- Which services and information would create the greatest business impact if compromised or unavailable?
- Who owns privileged access, device maintenance, email reporting and supplier escalation?
- Which exceptions are currently accepted, and what evidence would support a different decision?
- What response and recovery exercise would be safe and useful in the next quarter?
