Worried About Cybercrime? How Technology Can Help Keep Your Business Safe
Cybercrime is an increasingly important concern for businesses of all sizes. Small businesses can be particularly attractive to cybercriminals because they often hold valuable customer, financial and business information, but may have fewer resources available for cybersecurity.
The good news is that protecting your business does not have to be complicated or expensive. A combination of sensible technology, good housekeeping and a little common sense can significantly reduce your risk.
So, what should you be doing to help keep your business safe?
Cybercrime: what does it mean?
Information – or ‘data’ – is valuable. If you run a business, you are likely to hold information that could be useful to a criminal.
This could include customer contact details, payment information, employee records or other confidential information. For other businesses, the information worth protecting might include intellectual property, commercially sensitive documents, financial information or details about suppliers and customers.
The amount of information businesses now store online has also increased. You might keep files on a laptop or office server, or use cloud-based services for email, accounting, customer relationship management, file storage or your website.
All of these systems can potentially become targets for cybercriminals.
The ‘cyber’ element
The ‘cyber’ element simply refers to the way criminals use computers, phones, networks or the internet to commit a crime.
A cybercriminal might try to steal login details, trick someone into transferring money, install malicious software, access confidential information or disrupt your business.
And you don't need to be a large company to be targeted. The National Cyber Security Centre (NCSC) estimates that there are around 5.5 million small organisations in the UK and says that 4 in 10 small businesses experience a cyber incident each year.
What form can a cyber attack take?
You might imagine a cybercriminal as a highly skilled hacker breaking through complicated computer systems. Sometimes that happens, but many attacks are much less sophisticated.
Criminals may try to steal passwords, exploit outdated software or send convincing emails designed to trick someone into clicking a link, opening an attachment or revealing sensitive information.
Phishing
Phishing is one of the most common ways criminals try to gain access to accounts or information.
You might receive an email or text message that appears to come from your bank, a supplier, a customer or a familiar online service. It could ask you to click a link, make a payment, open an attachment or confirm your login details.
These messages can look surprisingly convincing.
If something seems unusual or unexpected, take a moment before acting. Check who the message is really from and, if necessary, contact the organisation using a phone number or website you already know to be genuine.
Malware
Malware is short for ‘malicious software’. It is software designed to cause harm or gain unauthorised access to a computer or network.
Viruses are one type of malware, but there are many others, including ransomware and spyware.
Ransomware, for example, can prevent you from accessing your files and may demand payment in exchange for restoring access.
Keeping your devices and software up to date, using appropriate security protections and maintaining reliable backups can all help reduce the impact of malware.
Stolen or compromised accounts
Criminals do not always need to break into your computer. If they obtain a username and password, they may be able to log directly into an online account.
This is one reason why protecting your business email and other important online accounts is so important.
Never reuse an important password across multiple services. Better still, use a passkey where one is available, or use multi-factor authentication (MFA) or two-step verification (2SV).
Human error
People can sometimes make mistakes, but it is important not to think of employees as simply being the ‘weakest link’.
Good security is about making it easier for people to do the right thing.
Make sure employees know how to spot suspicious emails and messages, understand how to report something that looks wrong and know that it is acceptable to pause and check before taking an unusual action.
How should you protect your business?
There isn't a single piece of software that will protect your business from every cyber threat.
For small businesses, staying protected means putting several sensible measures in place. These are likely to include the following…
Choose reliable technology and service providers
Many businesses now rely on cloud-based services for everything from email and file storage to accounting, customer relationship management and e-commerce.
Using a reputable provider can give you access to sophisticated security features, but moving your information to the cloud does not mean that security is automatically taken care of.
You are still responsible for protecting your accounts, managing who has access to information and configuring the available security controls correctly.
Before choosing a service, look at its security features as well as its price and functionality. Consider whether it offers multi-factor authentication, encryption, appropriate access controls and regular security updates.
Stay on top of updates
It is easy to click ‘Remind me later’ when your computer or phone asks you to install an update.
Try not to.
Software updates often include important security fixes that address newly discovered vulnerabilities. Leaving devices and software unpatched can give criminals an opportunity to exploit known weaknesses.
Where possible, turn on automatic updates and make sure your operating system, applications, phones, tablets and other internet-connected devices are kept up to date.
Use passkeys where available
Passwords have been part of online security for decades, but there is now a more secure and convenient alternative: passkeys.
A passkey allows you to sign in using something such as your fingerprint, face recognition or your device's screen lock, rather than typing a password.
One of the major advantages is that passkeys are designed to resist phishing. There is no password for a criminal to trick you into entering on a fake website.
In 2026, the NCSC announced that it recommends using passkeys wherever a service supports them.
So, when an important business service gives you the option to create a passkey, it is worth considering.
Use multi-factor authentication
Not every service supports passkeys yet. Where they are not available, turn on multi-factor authentication (MFA) or two-step verification (2SV).
MFA adds another layer of protection by requiring more than just a password to access an account.
For example, you might be asked to approve a sign-in on your phone or use another authentication method after entering your password.
Pay particular attention to your business email, cloud storage, accounting software, banking and other services containing sensitive information.
MFA is also increasingly important from a compliance perspective. Under the 2026 Cyber Essentials requirements, MFA is required for access to cloud services where it is available.
Use strong, unique passwords when you need them
If a service does not support passkeys, use a long, unique password and avoid using the same password for more than one important account.
You do not need to remember dozens of passwords yourself. A reputable password manager can generate and store unique passwords for you.
Most importantly, never share passwords between employees or use a single password for an entire team. Each person should have their own account wherever possible.
Protect your devices
Computers, laptops, tablets and smartphones can all contain valuable business information.
Make sure devices are protected with appropriate security software and that built-in security features are switched on. Use screen locks and device encryption where available, particularly on laptops and mobile devices that could be lost or stolen.
You should also consider what happens when an employee leaves the business. Remove their access to business systems and recover company devices promptly.
Use firewalls and built-in security protections
A firewall helps control network traffic between your devices or network and external networks such as the internet.
Modern computers and operating systems also include a range of built-in security features. Make sure these protections are enabled and kept up to date.
For businesses, security is about using several layers of protection rather than relying on one product to do everything.
Back up your important data
Imagine losing access to your customer records, accounts, documents and other important business files tomorrow.
Could your business continue?
Regular backups can make a significant difference if your data is accidentally deleted, a device fails or you are affected by ransomware.
Identify the information your business could not operate without and make sure it is backed up regularly. Your backups should be protected from unauthorised access and, where appropriate, from being affected by the same incident as your main systems.
It is also a good idea to test your backups occasionally. A backup is only useful if you can actually restore your data when you need it.
Be careful about who has access
Not everyone in your business needs access to every system or every file.
Give employees access to the information and services they need to do their jobs, and review those permissions from time to time.
This is particularly important when employees change roles or leave the business.
Avoid shared accounts where possible. Individual accounts make it easier to manage access and identify unusual activity.
Have a plan for when something goes wrong
Even with good security measures in place, no business can eliminate cyber risk completely.
Think about what you would do if your email account was compromised, your files became unavailable or you discovered that a fraudulent payment had been requested.
Knowing who to contact, which accounts need to be secured and where your backups are kept can save valuable time during an incident.
The NCSC recommends that small organisations take practical steps to protect their email and accounts, secure their devices, back up their data and learn how to spot common cyber attacks.
Don't let cybersecurity become an afterthought
Cybercrime can sound intimidating, particularly if you are running a small business without a dedicated IT or security team.
But you don't need to be a cybersecurity expert to improve your business's defences.
Keep your software updated, protect your accounts with passkeys or MFA, use strong and unique passwords where necessary, back up important information, control access to your systems and make sure everyone in the business knows what suspicious activity looks like.
Taking these simple steps can make it considerably harder for criminals to access your systems and can reduce the damage if something does go wrong.
Cybersecurity is an ongoing process rather than a one-off task. As your business grows and the technology you use changes, take some time to review your security measures and make sure they are still doing the job.
For more advice on technology, running your business and managing the risks that come with being a business owner, check out our other blog posts.