Just over four in ten UK businesses (43%) said they had a cyber breach or attack in the last 12 months, according to the government's Cyber Security Breaches Survey. That's about 612,000 businesses. The rate was 46% for small businesses and 65% for medium-sized ones.
By far the most common type was phishing, which 38% of businesses experienced. Ransomware, which gets most of the headlines, was reported by 1% of businesses, down from 3% in each of the two years before.
The National Cyber Security Centre (NCSC) says most cyber attacks are "basic in nature". Its Cyber Essentials scheme sets out a short list of basic controls, in five areas. You don't need the certificate to use the list, and it's a good place to start.
The five areas
Cyber Essentials covers firewalls, secure configuration, security update management, user access control and malware protection. What follows comes from the requirements in version 3.3 (April 2026), put into plainer words.
1. Your firewall or router
The firewall is your front door. In many small offices it's the router the broadband provider supplied, or a separate box. The requirements say to:
- change the default administrator password to a strong, unique one, or switch off remote administration altogether
- block unauthenticated inbound connections by default
- keep the administration page off the internet unless there's a clear, documented business need, and if there is, protect it with multi-factor authentication or a short list of trusted addresses
- have an authorised person approve and document any rule that lets traffic in, and remove rules you no longer need
2. Updates and old software
- Install updates that fix "critical" or "high risk" problems within 14 days of release.
- Remove software once its maker stops supporting it, or keep it away from the internet.
Unsupported software isn't only old PCs. Microsoft's support for Dynamics NAV 2016, for example, ended in April 2026.
3. Accounts
- Use multi-factor authentication for every cloud service. The requirements say cloud services must always use it. Start with email.
- Use separate accounts for administration, not the one you read email with.
- Remove or disable accounts when someone leaves or no longer needs them.
4. Malware protection
Every device in scope needs protection that is switched on. That means anti-malware software set to stop malware running and to block malicious websites, or a list of approved applications that nothing else is allowed to join. Either way, keep it updated.
5. Backups
Backups aren't one of the five areas, but if the other four fail, they decide how bad the day is. The NCSC's guide for small organisations says to:
- back up all the data the business needs to operate
- consider two backups, one online and one on a storage device
- keep the storage device disconnected when you aren't using it, because some viruses spread to connected devices
- protect online backups with two-step verification
- know how to restore the data, and check the backup holds everything important
Restoring is the step people skip.
What this looks like in practice
At Romero Insurance Brokers I replaced the old MPLS network with SD-WAN across the offices, working with network supplier Principle Networks, so that each office could carry on working if a connection failed. I also introduced cyber security there, including staff training and Cyber Essentials. My approach is the same on every job: find out what you have, fix the basics in priority order, and write it down so it stays fixed.
Should you get certified?
Cyber Essentials certification is priced by organisation size, starting at £320 plus VAT. It's issued through IASME, the NCSC's delivery partner, or through a certification body licensed by IASME. There's also Cyber Essentials Plus, which adds independent technical testing and is priced by quote.
The NCSC says a UK organisation with a turnover under £20 million that gets its whole organisation certified is entitled to cyber liability insurance arranged by IASME, including 24/7 incident response support. Check the conditions on IASME's site before you rely on it.
In the 2025/2026 survey, 5% of businesses held Cyber Essentials, up from 3% the year before. Certification is worth considering if customers ask for it, or if the insurance is useful to you. Either way, the checklist works without it.
Six questions to ask this week
- Is the administrator password on our firewall or router still the one it came with, and who knows it?
- Can anyone reach its administration page from the internet?
- Are critical updates installed within 14 days, and who checks?
- Are we using any software its maker no longer supports?
- Is multi-factor authentication switched on for every cloud service, starting with email?
- When did someone last restore a file from a backup to prove it works?
If you don't know an answer, that's useful. It tells you where an IT health check would start. Or ask me.
Sources
- GOV.UK, Cyber security breaches survey 2025/2026, published 30 April 2026.
- NCSC, Cyber Essentials overview.
- NCSC, Cyber Essentials: requirements for IT infrastructure, v3.3, April 2026.
- NCSC, Small organisations guide: backing up your data.
- Microsoft, Dynamics NAV 2016 support lifecycle.