A free NCSC Cyber Action Toolkit for small businesses
Cyber security advice can feel too broad for a small organisation to turn into action. The National Cyber Security Centre's Cyber Action Toolkit addresses that problem with short, prioritised tasks designed for sole traders, micro businesses and small organisations.
The free service starts with urgent foundation measures and then builds stronger layers of protection at a manageable pace. It is a useful prompt to review the technology that keeps communications, customer service, payments and everyday administration running.
Practical areas to review
- Use multi-factor authentication for email, administration portals and other important accounts.
- Install security updates promptly on computers, phones, routers and business applications.
- Keep tested backups that are not permanently exposed to the same accounts and devices as live data.
- Give staff a simple way to report suspicious messages, calls or account activity.
- Record who is responsible for responding when an account, supplier or service is compromised.
Treat cyber risk as business risk
The UK government's Cyber Governance Code of Practice also encourages leaders to identify the technology and services that are critical to their organisation, assign ownership of cyber risks and consider risks introduced by suppliers. For a smaller business, that can begin with a concise register of essential systems, named owners and a tested recovery plan.
Communications resilience and cyber resilience overlap. Protect portal accounts, remove access promptly when roles change, and make sure call-routing or messaging changes are traceable and recoverable.