Many leaders of a 70- to 150-person business don’t know what good cyber security looks like, so they can’t tell whether their IT provider is delivering it. This guide covers cyber security basics for business leaders, with a starting order and the questions to ask.
Start with what you’d lose (money, client data, the ability to work) before you choose any tools. Then secure email and accounts first with multi-factor authentication, keep every device updated, and test your backups. Use the free UK help, the NCSC’s Cyber Action Toolkit and Cyber Essentials, as your framework.
What does cyber security actually mean for a business like yours?
Cyber security is the set of habits and controls that stop someone else from getting into your systems, data or money without permission. For a small to medium-sized business (SMB), it’s a leadership issue first and an IT issue second. You decide what to protect first and how much risk is acceptable, and your IT team or provider puts the controls in place.
Those decisions depend on what matters most to your clients and your revenue, which only you can judge. A good provider will advise you and carry out the work, and the priorities still come from the leadership team.
Where should a non-technical leader start?
Work through six steps in order, starting with what you’d lose and ending with how your team reports problems. Each one says what it is, why it matters and what done looks like.
1. Know what you would lose
Before any technical control, run a simple what-if. What happens if client data is exposed, if a payment is intercepted, or if nobody can work for three days? Naming the real consequence (lost clients, lost revenue, lost trust) turns everything that follows into a decision you can weigh up.
Done looks like: a short list of your three worst-case outcomes, agreed by the leadership team, that you can read out in a meeting.
2. Secure email and accounts first
Email is the master key to almost everything else in a modern business, because password resets for other systems usually arrive there. Switch on multi-factor authentication everywhere it’s offered, starting with email and any system holding financial or client data. For shared credentials across the team, we recommend 1Password, which ends the habit of reusing one password everywhere.
Done looks like: every person in the business signs in to email with multi-factor authentication, and shared logins live in a password manager.
3. Keep every device updated
This covers phones as well as Macs. A postponed update is a known gap sitting open on a device that holds client work. macOS 27 is a live example: Apple changed how updates are managed, so a Mac can show as managed in your console and still be missing updates.
Done looks like: your IT team or provider can show you a list of every device and its update status, with nothing weeks overdue.
4. Back up, and test the backup
Ransomware, a failed disk and a deleted shared folder all raise the same question: can you get your data back, and how fast? A backup nobody has restored from is only a hope, so test it on a regular schedule and know it works before you need it.
Done looks like: a restore test on a fixed schedule, with a written result you can ask to see.
5. Decide what happens when it goes wrong
In an incident, the first hour can disappear into working out who to ring. Decide who’s called first, second and third well ahead of time, with names and numbers written down, so nobody is working it out while it’s happening. Our guide to what to do after a cyber security breach covers the details.
Done looks like: a one-page contact list with phone numbers that work out of hours, held somewhere you can reach if email is down.
6. Make reporting easy for your team
One known way to report anything suspicious, with no blame for false alarms, means problems reach IT early. In practice, that’s simple: screenshot it and send it to IT. Our guide to reporting a phishing email at work sets out the full process.
Done looks like: anyone on the team can tell you in one sentence how they’d report a suspicious email.
What should you own, and what can you delegate?
You own the decisions about risk: what to protect, how much risk is acceptable and what gets funded. Your IT team or provider runs the controls day to day. The table below sets out who does what.
| Area | Leader owns | Delegate to IT/provider |
|---|---|---|
| Risk appetite | Deciding what level of risk is acceptable | Implementing controls that match it |
| Incident response plan | Agreeing who's contacted and in what order | Running the technical response itself |
| Budget and priorities | Deciding what gets funded first | Recommending what needs funding |
| Policy | Setting expectations for staff behaviour | Enforcing and monitoring compliance |
| Compliance | Deciding whether certification is worth pursuing | Running the certification process |
| Day-to-day security | Asking the right questions regularly | Patching, monitoring and responding to alerts |
Is a Mac-first business already safer?
Macs have strong built-in security, and that’s a real advantage. Most attacks still go after the person at the keyboard, through a convincing email, a fake login page, or a trick like ClickFix that talks someone into running a command themselves. A Mac-first business gets a good platform and still needs the same habits as everyone else. Our piece on the most expensive assumption in a Mac-first agency covers this in more depth.
Do you need Cyber Essentials?
For a business your size, it’s a sensible baseline, and often a requirement. Cyber Essentials is the UK government-backed minimum standard for basic cyber security. Clients ask for it during due diligence, and some public sector contracts require it outright, so having it in place before you’re asked saves time when a tender or supplier questionnaire arrives.
What free UK cyber security help is available?
Four free resources are worth knowing about. Most are built for smaller organisations, so a business of 70 to 150 people will need more than they cover, but each one is a good place to start.
- The NCSC Cyber Action Toolkit gives short, prioritised actions at Foundation, Improver and Enhanced levels. It’s built for sole traders, micro businesses and small organisations.
- The Check Your Cyber Security tool, listed in the gov.uk cyber security guidance for business, gives a quick check for vulnerabilities in your IT.
- A free 30-minute session with a Cyber Advisor is open to small and medium-sized businesses preparing for Cyber Essentials, and the sign-up page asks you to confirm you haven’t held Cyber Essentials before.
- Free Cyber Governance Training for boards helps non-technical directors ask better questions at governance level.
Would your team know what to do with a suspicious email right now?
Dr Logic can set up a reporting flow your staff will use, and the response process behind it.
Five questions to ask your IT provider this month
Put these to your IT provider this month. Each one comes with what a good answer sounds like.
- What’s our multi-factor authentication coverage across email and key systems? A good answer names specific systems and gives a real percentage. A vague “most things” means nobody’s checked.
- How would we know if a backup failed to restore properly? A good answer describes a scheduled test that’s already happened, with a real result.
- What’s our current patch status, and how do you know? A good provider can show you this on request, backed by real data.
- What happens in the first hour if we’re hit by ransomware? A good answer names exactly who’s contacted first and in what order.
- Are we ready for Cyber Essentials if a client asked tomorrow? A good answer is a clear yes or no, with the reasons behind it.
For a straight read on those five answers, Dr Logic can run a Cyber Essentials readiness review and show you where you stand.
Related articles
- Vulnerability and CVE detection: closing the Cyber Essentials Plus window
- Why most UK businesses are failing Cyber Essentials Control 3 and how 1Password fixes it
- Cyber Essentials has changed. Here’s what the April 2026 Danzell update means for your Mac fleet
FAQs
What is the first thing a small business should do for cyber security?
Turn on multi-factor authentication for email and any other account that holds financial or client data. Email is the key to almost everything else in the business, because password resets for other systems usually arrive there. Most platforms already include it, so switching it on is usually a settings change.
Is cyber security my IT provider's job or mine?
Both, in different ways. Your provider runs the controls day to day: patching, monitoring, backups and alerts. You own the risk decisions, meaning what to protect first, how much risk is acceptable and what gets funded. The ownership table above sets out who does what, so nothing falls between you.
Do Macs need antivirus?
Macs have strong built-in protection, and most businesses still need managed endpoint protection or equivalent controls, particularly for Cyber Essentials. Ask your IT team or provider what’s running on each Mac and who monitors it. Our piece on the Mac-first assumption covers the reasons in more detail.
Is Cyber Essentials worth it for a business with 100 staff?
Yes, as a baseline. Clients often ask for it during due diligence, and some public sector contracts require it outright, so having it in place before you’re asked saves time when a tender or supplier questionnaire arrives. It also gives your IT provider a clear standard to work towards.
Where can I get free cyber security advice in the UK?
The NCSC’s Cyber Action Toolkit offers free, prioritised actions, and the gov.uk Cyber Advisor scheme offers a free 30-minute session for eligible small and medium-sized businesses preparing for Cyber Essentials. Neither needs technical knowledge to start, and the gov.uk cyber guidance collection links to both.





















