Security Controls Insurers Require
Cyber Security for Businesses: A Practical Checklist for UK SMBs
Good cyber security for businesses is not about buying the most expensive product on the market. It is about closing the handful of gaps that attackers actually walk through, in the right order, and being able to prove you have done it. The UK government’s Cyber Security Breaches Survey 2025 found that phishing remains the most common attack, hitting 38% of businesses, and that among firms that suffered an incident, 85% pointed to phishing as the root cause. Almost none of those attacks were clever. They succeeded because a basic control was missing. This checklist walks through the controls that matter, grouped so you can work top to bottom and tick each one off.
Start here: the five that stop most attacks
If you do nothing else this quarter, do these. They map onto the five Cyber Essentials controls, which exist precisely because they block the attacks that cause most real-world damage.
- Turn on multi-factor authentication (MFA) everywhere it is offered. Email, Microsoft 365 or Google Workspace, your accounting software, remote access and any admin login. This is now the single highest-value control you can enable, and from April 2026 a cloud service that supports MFA but does not have it switched on is an automatic Cyber Essentials failure.
- Patch within 14 days. Enable automatic updates on operating systems, browsers and apps, and retire anything the vendor no longer supports. Unpatched, internet-facing software is one of the most common ways in.
- Run reputable malware protection on every laptop, desktop and server, and keep it updated. On modern Windows and macOS the built-in protection is a reasonable baseline for a micro business.
- Lock down user accounts. Give people the least access they need to do their job, use separate admin accounts that are never used for daily email or browsing, and remove leavers the same day they go.
- Configure firewalls and devices securely. Change default passwords on routers and network kit, turn off features you do not use, and make sure your boundary firewall is actually on.
Protect your people (because attackers target them first)
Human error is the biggest single risk, yet the breaches survey found only 39% of SMEs give staff any cyber security training. Fixing that is cheap.
- Run short, regular phishing and awareness training, not a one-off induction slide. People forget, and the scams evolve.
- Teach staff the specific UK scams that drain small firms: fake supplier bank-detail changes, invoice fraud and “CEO” payment requests. Agree that any change to payment details is verified by phone using a known number, never by replying to the email.
- Use a password manager so people can have long, unique passwords without writing them down, and ban password reuse across work and personal accounts.
- Make it safe and quick to report a suspected phishing email. The person who clicked and owns up in two minutes is your best early warning system.
Protect your data and your ability to recover
Ransomware and accidental loss are survivable if your backups are. This is also the section insurers scrutinise most.
- Follow the 3-2-1 rule: three copies of your data, on two types of media, with one copy off-site and offline or immutable so ransomware cannot encrypt it.
- Test a restore. A backup you have never restored from is a hope, not a plan.
- Know where personal data lives and keep only what you need, for only as long as you need it. That is both a UK GDPR duty and a way to shrink the damage of any breach.
- Encrypt laptops and phones so a lost or stolen device is not a reportable data breach.
Prove it and insure it
Attackers are one problem; contracts, insurers and the ICO are another. This is where a tidy paper trail pays off.
- Complete a cyber security risk assessment and keep it current. Insurers ask for it at renewal and larger clients ask for it in procurement.
- Get Cyber Essentials certified. It forces the five controls above, is recognised by UK insurers, and is required for many public-sector contracts. Basic certification also comes with a level of free cyber insurance for small firms that qualify.
- Buy appropriate cyber insurance once your controls are in place, so a claim is not refused for a missing control you said you had.
- Write a simple incident response plan: who to call, how to isolate a machine, how to reach your insurer’s breach line, and the 72-hour clock for reporting a personal data breach to the ICO.
When to bring in help
You do not need an in-house security team, but you should know your limits. If you have no internal IT, a good managed security provider can run patching, MFA, monitoring and backups for you, which is usually cheaper than the first serious incident. If you handle sensitive data or hold larger contracts, consider a deeper network security review or independent testing rather than relying on self-assessment alone.
For the official baseline, the NCSC Small Business Guide is free and plain English, and the government’s Cyber Security Breaches Survey is worth a skim so you can see where the real risks sit. Cyber security and business resilience are the same conversation now: the goal of this checklist is not a certificate on the wall, it is a business that keeps trading after something goes wrong.
Frequently asked questions
What are the most important cyber security steps for a small business? Turn on multi-factor authentication everywhere, patch software within 14 days, run malware protection, use least-privilege accounts with separate admin logins, and keep tested, off-site or immutable backups. These five map onto Cyber Essentials and block the majority of attacks UK businesses actually face.
How much does cyber security for businesses cost? Many of the highest-value controls, such as MFA, automatic patching and staff awareness, cost little more than time. Bigger costs come from managed security services, penetration testing or specialist tools, which scale with your size and risk. Cyber Essentials certification is a modest fixed fee and often reduces insurance premiums.
Is Cyber Essentials enough on its own? Cyber Essentials covers the technical basics that stop most commodity attacks, which is why insurers and public-sector buyers value it. It is a strong foundation but not a complete programme. Pair it with staff training, tested backups, an incident response plan and, for higher-risk firms, deeper testing.
What is the biggest cyber security risk to businesses? People. Phishing is consistently the most common attack, and the government’s 2025 survey found 85% of businesses that had an incident identified phishing as the cause. Regular training, verified payment processes and MFA cut this risk sharply.
Do I legally have to do any of this? UK GDPR requires you to protect personal data with appropriate security and to report qualifying breaches to the ICO within 72 hours, so the data-protection controls here are effectively mandatory if you hold customer or staff data. The specific technical controls are not all mandated by law, but contracts and insurers increasingly require them.
How does good cyber security help with insurance and compliance? Insurers price on the controls you have in place and can refuse a claim if a stated control was missing, so strong cyber security management lowers premiums and protects payouts. The same controls provide the evidence for supplier security questionnaires and demonstrate the cyber security compliance that larger clients demand.