Tech Insight

Cybersecurity Checklist for UK SMEs: Practical Steps

A useful SME cybersecurity checklist does not promise that one product will stop every attack. It gives your team a repeatable way to find gaps, reduce avoidable risk and know what to do when something goes wrong. Use the steps below as a starting point, then adapt them to your systems, suppliers and risk profile.

4 min read
UK SME cybersecurity office

Cybersecurity checklist at a glance

  • Know what you have: record devices, users, cloud services, data and suppliers.
  • Control access: use least privilege, multi-factor authentication (MFA) and prompt leaver removal.
  • Keep systems current: apply supported software and firmware updates and replace unsupported technology.
  • Prepare people: train staff to spot phishing and report concerns without delay.
  • Plan for recovery: maintain tested backups and an incident response plan.

This is a control checklist, not a certification test or a guarantee of security. The National Cyber Security Centre small business guidance and the Cyber Essentials scheme are useful reference points for UK organisations.

1. Map your technology and data

Start with an inventory of laptops, desktops, phones, network equipment, cloud services, accounts and important data. Include home-working equipment and systems operated by suppliers. Record who owns each service, which business process depends on it and where its data is stored.

Mark systems that are business-critical, hold personal or confidential information, or provide administrator access. You cannot prioritise a vulnerability if you do not know which asset it affects. Review the inventory when staff, suppliers or systems change rather than treating it as a one-off spreadsheet.

2. Control identities and access

Apply least privilege: each person should have the access needed for their role, and no more. Use separate administrator accounts for administrative work, remove dormant accounts and review permissions when someone changes role or leaves.

Enable MFA wherever it is available, prioritising email, remote access, administrator accounts and financial systems. Prefer an authenticator app or security key where appropriate; make sure there is a documented recovery route so a lost device does not create an unmanaged exception. A password manager and unique passwords also reduce the damage from reused credentials.

Write down who can approve access and how urgent access changes are recorded. Review privileged access at a defined interval and after a significant change.

3. Secure devices and software

Keep operating systems, applications, browsers, network equipment and security tools supported and patched. Turn on automatic updates where they are suitable, but retain a way to check that updates have actually succeeded. Unsupported software should be removed, isolated or replaced.

Use centrally managed endpoint protection where possible, configure firewalls appropriately and encrypt business devices. Security tools are only one layer: configuration, patching, access control and monitoring still matter. Review alerts and define who responds to them.

Cloud services also need secure configuration. Check administrator roles, sign-in policies, external sharing, audit logs and third-party integrations. For Microsoft 365, the Microsoft 365 service page is a starting point for a broader platform review.

4. Train staff and practise reporting

Give people short, relevant guidance on phishing, unexpected attachments, payment-change requests, MFA prompts and safe use of removable media. Training should explain how to report a suspicious message and what information to preserve. A quick report is more valuable than a quiet mistake.

Use constructive reminders and, where suitable, controlled exercises to reinforce the process. Do not assume that a single annual session is enough; refresh guidance when a scam, system or working practice changes.

5. Protect and test recovery

Decide which data and services must be restored first, how quickly they are needed and who can approve recovery. Keep backups separate from ordinary user access, protect them against unauthorised deletion and test that files can actually be restored. A backup that has never been tested is an assumption, not evidence of recoverability.

Include ransomware, accidental deletion, lost devices and supplier outage in the exercise. Record the result, fix gaps and repeat the test after major system changes. Link this work to a wider disaster recovery policy where the business needs a coordinated response.

6. Prepare an incident response plan

Keep a short, accessible plan covering who declares an incident, who isolates systems, who contacts suppliers, how evidence is preserved and who communicates with staff, customers and regulators. Include out-of-hours contacts and a paper or offline copy in case normal accounts are unavailable.

After an incident or exercise, hold a review without blame. The aim is to turn lessons into a specific owner and a dated action, then confirm that the action is complete.

How often should an SME review its checklist?

Review the checklist at least annually and whenever there is a major change such as a new cloud service, acquisition, office move, supplier change or serious incident. Some controls, including alerts, backups and leaver access, need more frequent operational checks.

Next steps for UK SMEs

Choose the two or three highest-impact gaps, assign an owner and set a review date. If you need an independent view of priorities, J700 Group’s cyber security service can provide context for the technical work without replacing your own business decisions.

Need help turning the checklist into an action plan?

Privacy controls

Choose optional analytics and marketing categories independently. Marketing technologies are not active in this development configuration.

Necessary

Always active

Required for core website functionality and security. These cannot be disabled.

Analytics

Allows J700 to understand how visitors use the website and improve content and services. Optional and disabled until consent.

Marketing

Reserved for approved marketing technologies. None are active in this development configuration.

Read our Privacy & Cookie Policy.