Small Business Cyber Security

“When, Not If”: A Small Business Guide to Cyber Security

Every October, Small Business Cyber Security Awareness Month rolls round — a good reminder to give your business a digital MOT. But 2025 has made something painfully clear: cyber attack in the UK is no longer a far-off risk reserved for big brands. It’s a when, not an if. Household names like Marks & Spencer, Co-op, Jaguar Land Rover and even Heathrow suffered major disruption this year — from frozen check-ins to halted production lines and weeks of operational pain. The UK’s National Cyber Security Centre (NCSC) reports a sharp rise in “nationally significant” incidents and has urged business leaders of all sizes to prepare for a day when the screens go dark.

At Cash Cow Marketing, we’re a web design and digital marketing agency — and we’re often the first call when a client’s website is hacked, ecommerce is offline, or social accounts have been seized. The truth? For every headline-grabbing incident, hundreds of small and medium-sized businesses are quietly hit by ransomware, account takeovers, invoice fraud and website compromises. Most small business cyber security incidents never make the news, but the financial and reputational damage is very real.

Below, we’ll set out the UK picture, outline practical steps you can take now, and share a realistic “paper plan” for the worst-case scenario (because if your systems are out, your plan needs to be readable without a computer). And if you want hands-on help hardening your website, small business cyber security, or building that plan, Cash Cow Marketing can help.

 

The UK reality in 2025: what’s changed

Frequency and scale are up

The most serious incidents have risen significantly year-on-year, with leaders warned to treat cyber risk as a board-level issue, not “just IT”.

Big brands were hit — and so were their suppliers

From Jaguar Land Rover’s multi-week production halt to retail disruption at M&S and Co-op, 2025 showed how supply-chain dependencies turn one compromise into many.

Who’s attacking?

Attribution is complex, but the UK repeatedly flags hostile state-linked activity from Russia, China, Iran, and North Korea, alongside a thriving global criminal ransomware ecosystem. For small firms, the primary risk is criminal – phishing, credential theft, and ransomware-as-a-service – but you’re also exposed via suppliers targeted by state or criminal groups.

Bottom line: small UK businesses are attractive targets because you’re connected (payments, logistics, marketing platforms), hold valuable data, and are more likely to have gaps that criminals can monetise quickly.

 

“We’re too small to be a target” — why that’s dangerously wrong

  • Automation lets attackers phish millions and scan the internet for unpatched software and weak passwords.
  • Credential stuffing takes leaked passwords from unrelated breaches and tries them on your email, Microsoft/Google, Shopify, Xero, Meta, WordPress, and more.
  • Supply-chain and vendor risk means you can be collateral damage when a service you rely on is compromised.

Small firms also face brutal second-order effects: cash-flow shock from halted sales, missed payroll, contract penalties, ICO notifications, insurance excesses, and weeks of distraction for the owner-manager. For many SMEs, one bad week can mean a bad year.

 

Practical prevention: what UK SMEs can do now

Think of cyber hygiene like locking your shop, fitting an alarm, and training staff to spot counterfeit notes. It’s not about perfection; it’s about raising the cost for attackers and shrinking impact when something goes wrong.

1) Protect identities & access (your biggest doors)

  • Turn on MFA/2FA for email, Microsoft 365/Google Workspace, banking, payroll, ecommerce, social media, domain registrar, hosting, and your password manager. (MFA = a second step after your password, e.g., an app code or hardware key.)
  • Use a password manager (one strong, unique password per account). Ban password reuse.
  • Review admin roles: only trusted users, with the least access needed. Remove ex-staff access everywhere (email, CRM, ads, socials, hosting).

2) Keep software updated & reduce attack surface

  • Operating systems, browsers, plugins — patch monthly or auto-update.
  • On WordPress: keep core, theme and plugins current; uninstall unused plugins; use a reputable WAF and bot-mitigation; rate-limit logins; use 2FA for wp-admin; restrict XML-RPC; enable daily Off-Page backups.
  • On SaaS (Shopify, Squarespace, Wix, HubSpot): audit installed apps and permissions; remove what you don’t use; enable available security controls.

3) Backups you can actually restore

  • Follow 3-2-1: three copies, two media, one Off-Page/offline.
  • Test a full restore quarterly (files + database + DNS records + email).
  • Keep a clean offline copy of customer lists, order exports, and key documents.

4) Train people to spot the traps

  • Run short, practical phishing drills (quarterly).
  • Teach simple checks: hover over links, be suspicious of payment-detail changes, verify by phone using a number you already trust.
  • Create a “stop and ask” culture — no blame for reporting a mistake quickly.

5) Harden payments, finance & supply chain

  • Dual approval for new payees and any change to supplier bank details.
  • Maintain out-of-band contacts for your bank, accountant, top suppliers and logistics (a separate phone list).
  • Ask key vendors for their security basics (MFA, patching, backups, incident process). Put it in writing.

6) Monitor & respond faster

  • Turn on security alerts in Microsoft/Google.
  • Centralise logs where possible (even basic email forwarding of alerts).
  • Consider managed EDR/endpoint protection for company devices; if that’s too heavy right now, ensure built-in protections are enabled and centrally managed.

7) Website & marketing stack basics (our lane)

  • Enforce HTTPS and HSTS; renew certificates early.
  • Protect forms and admin portals behind WAF and rate-limits; add CAPTCHA where appropriate.
  • Lock down DNS at your registrar; use MFA; monitor for unexpected DNS changes.
  • Tighten ad accounts & pixels: MFA on Google Ads, Meta, LinkedIn; restrict admin roles; set spend alerts.

Not sure where to start? Cash Cow Marketing can help with a practical Small Business Cyber Security tune-up” across your website, hosting, DNS, analytics, and marketing platforms — prioritised for quick wins and real-world risk.

 

Plan for the worst: when you arrive and nothing works

The NCSC is blunt: treat Small Business cyber security resilience like fire safety. Assume a day will come when your screens are dark. We recommend every small business keeps a printed incident playbook in a known location (and a sealed copy Off-Page). That paper plan should cover:

Your paper incident plan (checklist)

1) Immediate actions (the first 60 minutes)

  • Disconnect: If a device is acting strangely, isolate it from the network/Wi-Fi (pull the cable; turn off Wi-Fi) — don’t turn it off unless advised (you may lose forensic evidence).
  • Call your response leads (names/numbers on paper):
    • Incident Lead (usually the owner/MD)
    • Technical Lead (internal/IT partner)
    • Comms Lead (customer & supplier comms; may be you)
  • Record what you see: times, error messages, files encrypted, ransom notes, who did what. Pen and paper is fine.
  • Quarantine email: halt bulk email sends/automations until you’re sure your account isn’t being abused.

2) Who to contact (print the numbers!)

  • IT partner / hosting provider / domain registrar
  • Bank (fraud line) and payment processors
  • Cyber insurer (if you have it) — many require you to call them first
  • Law enforcement (report to Action Fraud)
  • Key suppliers & top customers (if operations or deliveries are affected)
  • PR/communications support (even a pre-agreed freelance contact)
  • Cash Cow Marketing (for website, DNS, marketing stack containment & comms)

3) Systems & access inventory

A printed list of all critical systems with owner, URL, and non-SSO/emergency access method:

  • Email & office suite (Microsoft/Google)
  • Website/hosting/CDN/DNS/WAF
  • Ecommerce/POS and payment gateways
  • Finance (Xero/QuickBooks), payroll, banking
  • CRM/marketing automation (HubSpot/Mailchimp), ad accounts (Google/Meta/LinkedIn)
  • Logistics/booking/EPOS tools
  • Social media accounts
  • Any unique line-of-business apps

4) Decision points

  • Contain vs. continue: who can authorise taking the site/app offline?
  • Customer comms: template messages for website banner, email, and social (plain language, no speculation, commit to updates).
  • Regulatory: if personal data may be at risk, note the 72-hour ICO notification window under UK GDPR (speak to counsel/insurer).
  • Ransom: note your policy (usually don’t engage/pay) and who must approve any external negotiation via insurer/legal.

5) Recovery steps

  • Restore from clean backups (know where they live and who can access them).
  • Rotate credentials: reset passwords and invalidate tokens/keys (email, cloud, hosting, API keys).
  • Re-verify ad accounts & pixels; check spend limits and audiences.
  • Monitor closely for re-infection and suspicious logins for at least 14 days.

6) After-action

  • Document what happened, what worked, and what changes you’ll make (technical, process and training).
  • Brief staff; notify customers/suppliers transparently if impacted.
  • Schedule a follow-up security review in 30 days.

Keep this plan short, clear and printed. In a real incident, you won’t be hunting through SharePoint to find it.

 

Don’t give attackers a blueprint

A quick word of caution: detailed, step-by-step technical configs (ports, IP ranges, internal architecture) do not belong in public documents. Your external-facing policy should explain who does what and how to reach them, not publish the exact wiring of your network. Keep sensitive details in a private annex and distribute on a need-to-know basis.

 

Where to focus first (a 30-day roadmap)

Week 1: Identity & website hardening

  • Turn on MFA everywhere; remove stale admins; enforce a password manager.
  • Patch the website, prune plugins/apps, enable WAF, verify backups.

Week 2: Backups & finance controls

  • Implement 3-2-1 backups; test a restore.
  • Add dual approval for new payees; verify bank detail changes by phone.

Week 3: Training & alerts

  • Run a 20-minute phishing refresher; set up security alerts in Microsoft/Google.
  • Print and distribute the paper plan.

Week 4: Supplier sanity-check

  • Ask your top 5 vendors for their security basics; record contacts and SLAs.
  • Simulate a one-hour outage: what breaks? what needs updating in the plan?

If you want this prioritised, scheduled and implemented with you — Cash Cow Marketing can help. We’ll start with a lightweight risk review, fix the quick wins, and leave you with a plan you understand.

 

Final thought (and a nudge to take action today)

We hope this post has been useful. The goal isn’t to turn you into a cyber expert — it’s to protect revenue, reputation and sleep by getting the essentials right and having a clear plan for a bad day. The UK threat picture is getting tougher, and small businesses are very much in scope. Please act now: switch on MFA, back up properly, print your plan, and brief your team.

If you’d like help hardening your website and marketing stack or drafting a practical, printed incident plan tailored to your business, get in touch with us at Cash Cow Marketing — we’re ready to help you make cyber risk manageable.

Glossary of abbreviations used in this post

Use this quick-reference to clarify the acronyms and initialisms mentioned in this post;

Small Business Cyber Security

TL;DR

Too Long; Didn’t Read: a very short summary of the key points.

UK

United Kingdom.

SME / SMEs

Small and Medium-sized Enterprise(s).

MFA

Multi-Factor Authentication: a second step after your password (e.g., a code in an app or a hardware key).

2FA

Two-Factor Authentication: a common form of MFA using two checks (password + one extra step).

SaaS

Software as a Service: cloud apps accessed via a browser (e.g., ecommerce, CRM, marketing tools).

WAF

Web Application Firewall: filters malicious traffic before it reaches your website.

HSTS

HTTP Strict Transport Security: forces browsers to use secure HTTPS on your site.

DNS

Domain Name System: the internet’s address book that points your domain to your website and email.

CDN

Content Delivery Network: speeds up and helps protect your site by serving it from multiple global servers.

CRM

Customer Relationship Management: software for managing contacts, leads and customers.

POS

Point of Sale: the system where you take payments (till/checkout).

EPOS

Electronic Point of Sale: a digital/connected POS system (often cloud-based).

EDR

Endpoint Detection and Response: advanced protection that detects and contains threats on laptops/desktops.

ICO

Information Commissioner’s Office: the UK data-protection regulator.

3-2-1 (backups)

Three copies of your data, on two different types of media, with one copy Off-Page/offline.

API

Application Programming Interface: keys/tokens that let different systems talk to each other.

URL

Uniform Resource Locator: a web address (e.g., https://yourdomain.com).

TL;DR: (Too long? Didn't read?) Grab the summary here
For UK SMEs, cyber attack is a when, not if. Turn on MFA everywhere, patch systems monthly, back up with 3-2-1, train your team to spot scams, and keep a printed incident plan for the day the screens go dark. If you’d like a practical security tune-up and a one-page paper plan, Cash Cow Marketing can help.
We use cookies to ensure that we give you the best experience on our website.
OK