A practical cybersecurity guide for your business
Start with the controls that protect your day-to-day work: access to accounts, current software, recoverable data and a reliable response when someone spots a problem. Give each task an owner. An unassigned control is easy to assume is somebody else's responsibility.
If you need the broader context first, read what cybersecurity means for a small business. This guide focuses on turning it into work you can verify.
Secure the accounts that unlock other systems
Prioritise email, the domain registrar, hosting administration, finance and customer systems. Give each user an individual account and only the permissions their work requires. Keep administrative access separate from routine activity where practical.
Use a password manager and unique credentials. Enable suitable multifactor authentication, preferably phishing-resistant methods where supported. Store recovery information securely and test the recovery procedure without exposing codes to a shared document.
Maintain an access list that includes contractors and integrations. When someone leaves, remove or transfer access deliberately, revoke sessions where appropriate and check any shared secrets they could use. Disabling one email account may not automatically remove every connected service session.
Make backups recoverable
Ask what is copied, how often, where it is stored, how long versions remain and who can restore them. For a website, files without the database may not be sufficient. For an active shop, consider how much order data could be lost between copies.
Test restoration in an isolated environment. Check that the restored site actually works, not merely that an archive can be downloaded. Record the time required and any missing dependencies. The NCSC recommends regular backups and testing restoration as part of ransomware resilience. NCSC ransomware guidance.
ResaHost backups are daily and stored in two locations. Check the applicable service details for retention and restoration responsibilities; do not assume that every business system is included in a website backup.
Keep an update routine and an urgent route
List WordPress, plugins, themes, PHP and other relevant software. Remove components no longer needed, after checking dependencies. A disabled plugin still leaves files on the server.
Use a backup, appropriate pre-release testing and customer-journey checks. Test forms, checkout, login and integrations after changes. Our WordPress update guide explains the routine.
A regular schedule does not replace a process for an urgent security advisory. Decide who evaluates exposure and who can authorise faster action. If a component has no safe update, replacement or temporary removal may be necessary.
Review cloud sharing and email
Inspect external file shares, old invitations and third-party applications with broad permissions. Keep personal accounts out of administrative ownership wherever possible. Record who can export customer information and where those exports may be stored.
For email, review both account access and domain authentication. SPF, DKIM and DMARC address different parts of sender authentication. They do not prevent every fraudulent message, especially when a genuine mailbox is compromised or a lookalike domain is used.
Use a separate verification channel for payment changes. Protecting the mailbox and protecting the payment process are related but distinct tasks.
Give staff simple, usable rules
Train people to pause on unusual requests, report unexpected sign-in prompts and check recipients before sending sensitive material. Provide a known incident contact that is reachable if normal email is unavailable.
Avoid blame when someone reports an error. Fast reporting helps the response owner understand what happened. The staff training guide gives a structure for short exercises and onboarding.
For remote access, configure permissions to the resources a person needs. A business VPN or other managed access method does not replace an updated device or strong authentication.
Prepare a one-page incident procedure
Record primary and backup contacts, key providers and the authority to make urgent decisions. Explain where evidence should be preserved and how communications will continue if a system is unavailable.
If personal data is involved, assess notification duties promptly. GDPR can require notice to the supervisory authority within 72 hours of awareness unless the breach is unlikely to create risk to individuals; other duties depend on the circumstances. EDPB breach guidance.
Do not treat every website error as a reportable breach, but do not wait for a perfect technical report before starting the assessment.
Check the supplier boundary
Ask your provider what it maintains, what it monitors, when a person responds and what restoration includes. A first-response commitment is not a guaranteed resolution time. Put any endpoint, cloud-account or specialist security work into an explicit scope.
Start this week by checking privileged MFA, a restoration test and the update owner. Then use the website security checklist to record the remaining tasks. The aim is a maintained routine, not a one-off green score.