Free checklist · Nothing to download

Ten easy wins to secure your business

Feel safer by Friday. Ten things a manager can put in place without an IT department, a budget round, or a single meeting about strategy.

Most attacks aren’t clever. In the Government’s own Cyber Security Breaches Survey 2025/2026, 43% of UK businesses identified a breach or attack in the previous year — and over half of those experienced phishing and nothing else. The ten steps below block the big four: dodgy emails, stolen passwords, ransomware, and fake payment requests.

Being straight with you: ticking all ten does not make you secure, and anyone who tells you a checklist can is selling something. What it does is shut the easy doors, so an attacker has to work for it — and most of them won’t bother. That is worth more than it sounds.

No email required Written for managers, not IT staff An afternoon’s work, not a project
Cybersecurity Essentials Checklist

Cybersecurity Essentials Checklist

Complete these 10 essential steps to secure your business

Your Progress
0% Complete

Add a second step to logins

Turn on the "code to your phone" step for email, banking, Microsoft 365, payroll, and anything sensitive. If it's important, it needs the extra step.

Stop re-using passwords

Make one rule: everyone uses long, unique passphrases (think 3–4 random words). Store them in a trusted password tool so people don't have to remember them.

Turn on auto-updates everywhere

Phones, laptops, apps. Set them to update automatically so fixes install while you sleep.

Back up—and test the restore

Back up your key files daily (or at least weekly). Once a month, actually restore one file to prove it works. Five-minute spot check.

Teach "pause before click"

Run a 10-minute scam awareness reminder monthly. Golden rule: if you weren't expecting an attachment, link, or bank-detail change—don't click, don't pay, don't reply.

Two-person payment checks

No money leaves without a second person verifying changes to bank details by calling a known number (not the one in the email). Simple, powerful fraud blocker.

Lock every device

Set screens to auto-lock after a few minutes. Require a PIN/Face/Thumb to get back in. If a device goes missing, know who to tell and what to do.

Control who can install software

Only trusted people can add apps. Everyone else asks first. Quarterly tidy-up: remove anything unused or unknown.

Use a Joiner–Mover–Leaver checklist

When someone joins, moves role, or leaves: add the right access, remove the wrong access, and shut down old accounts the same day.

Write a 1-page "If something's wrong" plan

Who to call, how to isolate a dodgy device (unplug Wi-Fi/ethernet), where to find backups, and who talks to customers. Print it and stick it by the kettle.

🎉 Congratulations!
You've completed all cybersecurity essentials. Your business is much safer now!

Where this list comes from

Six of these ten are already someone else’s standard

This isn’t a list I made up. Six of the ten — the second step on logins, password re-use, automatic updates, device locking, who can install software, and what happens when someone joins or leaves — are things a Cyber Essentials assessor will ask you about. That’s the UK Government-backed scheme, and plenty of public sector contracts now won’t start without it.

The other four — backups you’ve actually tested, teaching people to pause before they click, two pairs of eyes on payments, and a one-page plan for when something goes wrong — are not in the scheme. I’ve put them in anyway, because in fifteen years of doing this they are the four that decide whether a bad morning becomes a bad year.

If you need the certificate rather than just the habits, that sits inside the QuantumCare packages — prices published, no quote required.

Is this a sales pitch?

No. It’s a practical worksheet you can use today. If you want help implementing it, that’s optional.

What is this checklist?

A simple, non‑technical set of 10 actions any manager can lead this week to cut the biggest day‑to‑day risks: dodgy emails, weak passwords, missed updates, payment fraud, and poor off‑boarding.

Who is it for?

This checklist is for managers and business owners who want easy, practical wins they can implement this week to lower business risk — no jargon, no provider change, just clear actions. Ideal for teams of 5–100 on Microsoft 365 or Google Workspace.

How much time will this take?

You can start today. Most items are “set and forget.” Aim to complete the list by Friday, then test backups monthly and refresh the reminders monthly.

What if someone needs admin rights?

Keep day‑to‑day users without admin. Where admin is necessary, keep it to named people and time‑boxed tasks. Misuse of admin access can sit outside service guarantees — we’ll help you lock this down with minimal friction.

Image

Innovation

Fresh, creative solutions.

Excellence

Excellence

FOLLOW US

Systems Secure® Limited·Registered in England and Wales, company no. 07295869 6 The Meadow, Copthorne, West Sussex RH10 3RG·07702 896 910·[email protected]

How to check you’re dealing with us

Serving Crawley, East Grinstead, Brighton and businesses across Sussex · UK-wide remote support

Copyright 2026. Systems Secure. All Rights Reserved.