Home » Articles » Small Business Cybersecurity Checklist 2026

Small Business Cybersecurity Checklist 2026

What this means

A practical 2026 checklist for micro and small businesses — access, updates, invoices, backups, people, and a 90-day starter plan.

Small business cybersecurity checklist 2026

Note: This site may show light ads and occasional affiliate links. How that works.

Small businesses rarely lose sleep over “advanced persistent threats.” They lose mornings to invoice fraud, locked laptops, and staff who meant well. This checklist is a practical 2026 baseline — not a compliance certificate, and not something you finish in one sitting.

How to use this: Print it or copy it into a shared note. Tick what you already do. Circle three gaps to close this month. Revisit quarterly.

Educational guidance for UK micro and small organisations — adapt to your size and sector.

PDF: Download the printable checklist (PDF).


1. Identity & access (the keys)

  • Every person has their own login — no shared “shop” email password on a sticky note for banking.
  • A password manager is in use for staff who handle money, email, or admin panels.
  • An extra step to guard important accounts — multi-factor authentication (mfa) — is on for email, banking, accounting, Microsoft/Google workspace, and the website admin.
  • Leavers lose access the same day (email, cloud, POS, social, supplier portals).
  • Admin rights on PCs are limited; day-to-day work uses a standard account.

Deeper habit help: password habits · household password framing (useful for micro-teams too).

2. Devices & updates

  • Laptops and phones used for work have screen locks and current OS versions.
  • Automatic updates are on for OS and browsers; a monthly check covers routers and any “set and forget” kit.
  • Lost/stolen process exists: who to call, what to wipe, which accounts to reset.
  • Personal “bring your own” phones that read work email follow the same mfa and update rules.

Why updates matter · malware basics.

3. Email, invoices & money movement

  • Staff know to verify bank-detail changes out-of-band (known phone number), never from the email alone.
  • A simple rule: new payee or changed IBAN = pause and confirm.
  • Finance has a second pair of eyes above a sensible threshold.
  • Staff can report a suspected phish without blame — speed beats embarrassment.

Stop! Pause! Before you approve a payment or bank change: Is it urgent? Do you know who asked? Did you confirm on a number you already trust — not one in the email? If not sure — hold the payment.

Online scams hub · spotting fake email.

4. Backups you can actually restore

  • Important files and systems have backups that are separate from the live machine (cloud and/or offline).
  • Someone has tested a restore in the last 12 months — even a single folder test counts.
  • Ransomware reality check: if every copy is on the same always-connected drive, it isn’t a backup.

5. Website, payments & customer data

  • Website and plugins/themes are updated; unused plugins removed.
  • Admin URLs and hosting logins use mfa where offered.
  • If you take cards, you know your PCI DSS SAQ type and who supports it — don’t guess.
  • Customer data isn’t copied to random USB sticks or personal drives “just in case.”

PCI DSS for small businesses · SAQ A & C-VT guide.

6. People (still the front door)

  • New starters get a 30-minute security briefing: phishing, invoices, mfa prompts, who to ask.
  • Quarterly, share one real example (an email you almost trusted) in a team huddle.
  • Staff know AI tools are useful — and that pasting customer data into public bots is not.
  • A one-page “if something feels wrong” card lists: pause, tell a colleague, use known numbers.

Awareness training guide · AI policy template · Human firewall.

7. When things go wrong

  • You know who decides if systems go offline, who talks to customers, and who calls the bank/insurer.
  • Important account recovery codes / break-glass admin access are stored safely offline.
  • You have notes for reporting: Action Fraud (UK), ICO if personal data is involved, and your cyber insurer if you have one.

A 90-day starter plan

  • Days 1–30: mfa on email + banking + accounting; password manager for owners; leaver checklist written down.
  • Days 31–60: Backup test; invoice-change verification rule; update pass on PCs/router.
  • Days 61–90: 30-minute staff huddle; AI tool rules written; website/plugin tidy; revisit this list.

Further reading: NCSC top tips · report incidents via Action Fraud. Printable PDF checklist.

A self-check

Circle three gaps on this list. Of those three, which one would hurt most if it failed tomorrow — email login, invoice verification, or backups? Start there. One fix this month beats a perfect plan you never begin.

More on this site’s focus: AI, human risk & scams.