Small does not mean invisible
The NCSC describes a UK economy with roughly 5.5 million small organisations. Attackers do not need to research each one individually: automated scanning, stolen credentials and mass phishing make modest targets economical. The impact is personal. A few encrypted laptops can stop invoicing, bookings and customer support. A stolen mailbox can redirect payments. For a small team, the people handling the incident are also the people trying to keep the business alive.
Build the boring baseline
Turn on multi-factor authentication for email, finance, cloud administration and remote access. Apply security updates promptly, remove unused accounts and avoid using administrator privileges for routine work. Keep copies of important data that an attacker cannot erase through the same account. Automate backups, retain several points in time and regularly restore a sample to a clean device. A dashboard saying a backup succeeded is not proof the organisation can recover.
Plan one page ahead
Write a one-page incident sheet with the IT provider, insurer, bank, legal adviser and NCSC reporting route. Keep a copy outside the normal system. Decide who can stop payments, isolate devices and communicate with customers. Small organisations do not need a full security operations centre to become harder targets. They need ownership, a manageable baseline and confidence that recovery has been practised before the pressure arrives.
UK TECH TRENDIndependent analysis for the British technology market.
Continue to all articles