CRAIG WILLETTS ISO & BUSINESS CONSULTANT
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
    • Compliance Master
  • Business Articles
    • New Business Tips >
      • Cash Flow Planning
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
      • Business Insurance
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Tips
    • ISO 14001 Tips
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Tips
    • ISO 22000 Tips
    • ISO 37301 Tips
    • ISO 27701 Tips
    • ISO 20000 Tips
    • ISO 26000 Tips
    • ISO 15189 Tips
    • ISO 20121 Tips
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting
    • Integrating ISO Standards

Cybersecurity Basics for SMEs

Picture
Most small businesses assume cyber attacks target large corporations with valuable data to steal. That assumption is exactly why so many SMEs remain under-protected — attackers know smaller businesses are less likely to have proper defences in place, which makes them an easier, faster target regardless of how much data they hold. Getting the basics right doesn't require a big budget or a dedicated IT security team. It requires knowing what actually matters and doing it consistently.

In this article:
- Why SMEs are targeted
- The core basics every business needs
- Cyber Essentials explained
- Common mistakes SMEs make
- Practical steps to get started

Why SMEs Are Targeted

Small businesses often hold valuable data — customer records, payment details, supplier information — while having far fewer defences than large enterprises, making them a comparatively easy target. Many SMEs also sit within the supply chains of larger organisations, meaning a breach at a small supplier can become the entry point into a much bigger target. Attackers aren't necessarily choosing SMEs deliberately either; a large proportion of attacks are automated, scanning the internet for any system with an unpatched vulnerability or weak password, regardless of the size of the business behind it.

The Core Basics Every Business Needs

- Strong, unique passwords and multi-factor authentication (MFA). Password reuse across accounts is one of the most common ways attackers escalate a single compromised login into access across multiple systems. MFA adds a second barrier that stops most automated attacks even if a password is stolen.
- Regular software updates and patching. Unpatched software is one of the most exploited weaknesses because known vulnerabilities are publicly documented, and attackers actively scan for systems that haven't applied the fix.
- Secure configuration. Default settings on routers, firewalls, and devices are often not secure out of the box — turning off unnecessary services and changing default admin credentials closes off easy entry points.
- Access control. Staff should only have access to the systems and data they actually need for their role, limiting the damage if one account is compromised.
- Malware protection. Antivirus and anti-malware tools, kept updated, on every device that connects to business systems.
- Regular data backups. Backups stored separately from the main network (and tested periodically) are often the single factor that determines whether a ransomware attack is a minor disruption or a business-ending event.

Cyber Essentials Explained

Cyber Essentials is a UK government-backed certification scheme built around the core basics above, designed to help organisations demonstrate they have essential protections in place against common cyber threats. It comes in two tiers — Cyber Essentials, a self-assessed certification, and Cyber Essentials Plus, which includes an independent technical verification of the controls in place. For many SMEs, it's also a practical commercial requirement: an increasing number of contracts, tenders, and larger clients now require suppliers to hold Cyber Essentials certification before they'll do business with them.

Common Mistakes SMEs Make

- Treating cybersecurity as an IT-only issue. The majority of breaches involve some element of human error — a clicked link, a reused password, a misdirected email — making staff awareness as important as technical controls.
- Assuming a firewall and antivirus is "done." These are necessary but not sufficient; without patching, backups, and access control, gaps remain wide open.
- No incident response plan. Many SMEs have no clear plan for what to do in the first hours after a breach is discovered, which turns a manageable incident into a chaotic one.
- Ignoring third-party and supplier risk. A secure business can still be compromised through a poorly secured supplier or vendor with access to its systems.
- Delaying until "we're big enough to be a target." By the time a business feels big enough to justify investment, it's often already been targeted.

Practical Steps to Get Started

- Start with a basic risk assessment. Identify what data and systems matter most and where the weakest points currently sit.
- Roll out MFA everywhere it's supported, starting with email and any system holding customer or financial data.
- Set a patching schedule rather than relying on ad hoc updates — even a monthly check makes a significant difference.
- Train staff on phishing recognition. Short, regular training sessions are more effective than a single annual session.
- Test your backups, not just take them — a backup that can't be restored isn't a backup.
- Consider Cyber Essentials certification as a structured way to formalise the basics and reassure clients and partners.

The Bottom Line

Cybersecurity for SMEs isn't about matching the budget of a large enterprise — it's about consistently getting the fundamentals right. Businesses that treat the basics as non-negotiable, rather than optional extras, are the ones that avoid becoming the easy target attackers are looking for.

If you'd like support assessing your current cybersecurity posture or working towards Cyber Essentials certification, CAW Consultancy can help.

Get in touch with CAW Consultancy today for a free, no-obligation consultation — visit www.cawconsultancy.co.uk to find out how we can help you stay compliant and confident.

Many Thanks

​

If you need any advice or have any questions, then please get in touch - [email protected]

Don't forget to share this blog to help others with get great free advice

Picture
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
    • Compliance Master
  • Business Articles
    • New Business Tips >
      • Cash Flow Planning
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
      • Business Insurance
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Tips
    • ISO 14001 Tips
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Tips
    • ISO 22000 Tips
    • ISO 37301 Tips
    • ISO 27701 Tips
    • ISO 20000 Tips
    • ISO 26000 Tips
    • ISO 15189 Tips
    • ISO 20121 Tips
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting
    • Integrating ISO Standards