Small-business security basics (UK, 2026): the essentials, in order, and the 3-2-1 backup rule
On this page
- What actually goes wrong (the honest threat model)
- 1. A password manager (the single biggest win)
- 2. Turn on two-factor authentication everywhere
- 3. A VPN for public wifi and working on the move
- 4. Back up everything (the 3-2-1 backup rule)
- 5. Keep software updated
- 6. Email: stop spoofing, and stay sceptical
- 7. Your website (where this becomes our job)
- The 10-minute checklist
- The disclosure, plainly
The businesses that get hit are rarely the ones with a determined hacker on their trail. They are the ones running the whole company on three reused passwords, a laptop with no backup, and a coffee-shop wifi connection that anyone in the room can read. The good news is that the boring basics remove most of that risk, and almost none of them are expensive or technical.
This is the plain-English version: what actually matters for a UK small business in 2026, in the order we would do it. You do not need all of it this week. You need the first two or three things done properly, and the rest over the following month.
A note before we start, because honesty is the whole point of a piece like this: some of the links below are affiliate links, and UK Web Marketing may earn a small commission if you sign up, at no extra cost to you. It does not change the advice. Where a free or open-source option is the better pick, we say so and name it.
What actually goes wrong (the honest threat model)
You do not need to defend against a state actor. For a small business, the real risks are mundane and common:
- A password reused across your email, your bank and your shop, and one of those other services gets breached, so now the attacker has the password to all three.
- A phishing email that looks like your accountant, your bank or Companies House, asking you to log in or change bank details.
- A laptop or phone lost or stolen with everything still logged in.
- Working on public wifi (a cafe, a hotel, a client site) where the connection is not yours and not encrypted.
- A drive that dies, or a ransomware lock, with no backup to fall back on.
Cover those five and you have handled the overwhelming majority of what actually happens to businesses like yours. Everything below maps to one of them, and the same ground is covered, in more formal language, by the NCSC Small Business Guide, the UK government’s own cyber-security advice for small firms.
1. A password manager (the single biggest win)
Reused passwords are the number one cause of small-business account takeovers, and a password manager fixes the whole category in one move. It generates a long, unique password for every account, stores them encrypted, and fills them in for you, so you never reuse one and never have to remember them. You memorise one strong master password and that is it.
This is the first thing we would set up, ahead of everything else on this page.
The picks:
- For the easiest, most mainstream option with a free tier to start on: NordPass → (affiliate link: we may earn a commission, at no extra cost to you). It is free for one user, has paid family and team plans, runs frequent multi-year deals, and its parent company sits in Lithuania (inside the EU). The apps are polished and beginner-friendly, which matters, because the best password manager is the one your team will actually use.
- For the cleanest open-source, data-protection story: Bitwarden. It is free, EU-resident by default, and audit-friendly. If anyone ever asks how your password manager works, an open codebase is the easiest answer.
Either is a good choice. For the full breakdown, including 1Password and Proton Pass and which fits a regulated practice, see the password-manager comparison.
2. Turn on two-factor authentication everywhere
Two-factor authentication (2FA) means that even a stolen password is not enough on its own, the attacker also needs a code from your phone. It is the single highest-value free thing you can do after the password manager.
Turn it on for your email first (your email is the master key, because it can reset everything else), then your bank, your domain registrar, your Google Business Profile, and your payment and accounting logins. Use an authenticator app (the free Google Authenticator, Microsoft Authenticator, or the one built into your password manager) rather than text-message codes where you have the choice, as app codes cannot be intercepted by a SIM-swap.
3. A VPN for public wifi and working on the move
When you work from a cafe, a hotel, an airport or a client’s office, you are on a network you do not control. A VPN (virtual private network) encrypts your connection so that whoever runs that wifi, or anyone else sitting on it, cannot read what you are doing. For a business owner who works on the move, or has staff working remotely, it closes the public-wifi risk from the threat model above.
It is worth being honest about what a VPN does and does not do. It protects your connection on untrusted networks and adds privacy. It is not antivirus, it is not a magic shield, and if you and your team only ever work from one trusted office or home connection, it is a lower priority than the password manager and your backups. It earns its place the moment anyone works from a network they do not own.
The pick: NordVPN → (affiliate link: we may earn a commission, at no extra cost to you). It is well known, fast, works across your laptop and phones, and runs multi-year deals that bring the monthly cost down. Same EU-based parent as NordPass, so it is one account family if you use both.
4. Back up everything (the 3-2-1 backup rule)
Backups are the difference between a bad afternoon and a closed business. The method worth committing to memory has a name: the 3-2-1 backup rule. Keep three copies of anything you cannot lose, on two different types of storage, with one of them off-site. It is a long-standing rule of thumb from the world of digital archiving, and it has stuck because it is short enough to remember and complete enough to work.
For a typical small business the 3-2-1 backup rule means: the working copy on your computer, a copy on an external drive, and a copy in a cloud backup that runs automatically. The off-site copy is what saves you from theft, fire and ransomware, the on-site drive alone does not. Once a year, actually try to restore a file, because a backup you have never tested is a hope, not a backup.
5. Keep software updated
Most security holes that get exploited are old and already patched, the businesses that get hit are the ones that never installed the update. Turn on automatic updates for your operating system, your web browser, your phones, and anything running your website (the platform and any plugins). It is the least glamorous item on this list and one of the most effective.
6. Email: stop spoofing, and stay sceptical
Email is the main way attacks arrive, so it is worth two small jobs. First, the technical one: make sure your domain has SPF, DKIM and DMARC set up, the three records that stop other people sending email that looks like it came from you, and that help your own email land in inboxes rather than spam. We explain the three records properly in why business emails go to spam. If you are not sure whether yours are in place, that is part of what a managed setup handles, and the UK/EU sovereign stack guide and the sub-processor page show how we wire it.
Second, the human one: treat any unusual request to log in, pay an invoice, or change bank details as suspicious, even when it looks like it came from someone you know. Verify it through a different channel (a phone call to a number you already have) before you act. Most successful attacks on small businesses are a convincing email, not clever code.
7. Your website (where this becomes our job)
An honest line to draw: items one to six are things only you can do, because they live on your devices and in your accounts. Your website is the one item on this list you can genuinely hand to someone else, and it is part of your security surface too: it should be on HTTPS, kept patched, backed up, and monitored so a problem is caught before a customer sees it. This is exactly the boring operational layer that a managed website covers, and the part most one-off builds quietly leave to you. We set out what that layer involves on our website security page.
If you would rather not think about it, that is the whole idea of a managed website service: the hosting, the SSL, the patching, the backups and the monitoring are run for you, with website management from £49/month, quoted to your business. It is also the practical difference between website management and website maintenance, if you are weighing up what a plan should actually include.
The 10-minute checklist
You will not finish all of this in ten minutes, but you can start every item:
- Install a password manager and move your five most important logins into it (NordPass (affiliate link) or Bitwarden).
- Turn on two-factor authentication for your email, first.
- If you work from public wifi, set up a VPN (NordVPN (affiliate link)).
- Check you have an automatic, off-site backup following the 3-2-1 backup rule, and that you can restore a file.
- Switch on automatic updates everywhere.
- Confirm your domain has SPF and DKIM, and brief your team to verify payment changes by phone.
- Confirm your website is on HTTPS and is being patched and backed up by someone.
The disclosure, plainly
NordPass and NordVPN are affiliate links, so UK Web Marketing may earn a small commission if you sign up, at no cost to you. Bitwarden, the open-source password-manager option, is not an affiliate link, and it is named here precisely because it is the better pick for some readers. The advice on this page would be identical with or without the commission, the tools are recommended because they genuinely fit the job, not the other way round.
And if you would rather hand the whole website-security half of this to one accountable partner that runs it for you, that is what we do. Start with a free Site Score to see where your site stands today, or get in touch and we will talk through your setup.
Frequently asked questions
What is the single most important security step for a small business?
A password manager, set up ahead of everything else. Reused passwords are the number one cause of small-business account takeovers, and a password manager fixes the whole category by generating a long, unique password for every account and storing them encrypted.
Which password manager should I use?
For the easiest mainstream option with a free tier, NordPass, whose parent company sits in Lithuania inside the EU. For the cleanest open-source, data-protection story, Bitwarden, which is free and EU-resident by default. Either is a good choice.
Do I need a VPN for my business?
You need one the moment anyone works from a network they do not own, such as a cafe, hotel or client office. A VPN encrypts your connection so nobody on that wifi can read it. If you and your team only ever work from one trusted connection, it is a lower priority than the password manager and backups.
What is the 3-2-1 backup rule?
Keep three copies of anything you cannot lose, on two different types of storage, with one of them off-site. The off-site copy is what saves you from theft, fire and ransomware. Once a year, actually try to restore a file, because a backup you have never tested is a hope, not a backup.
How do I stop people spoofing my business email?
Make sure your domain has SPF, DKIM and DMARC set up. These three records stop other people sending email that looks like it came from you and help your own email reach inboxes rather than spam. If you are not sure, that is part of what a managed setup handles.