Online safety checklist for a UK small business
A practical UK small-business checklist covering accounts, devices, backups, payment fraud and remote working.
Small-business online safety is less about expensive products and more about consistently doing the basics. Start with the accounts and information that would stop the business operating, then reduce the chance that one stolen password, lost laptop or fraudulent email becomes a crisis.
Key points
- Use multi-factor authentication on email, banking, cloud storage and administration accounts.
- Keep tested backups that are not permanently connected to the same systems.
- Create a clear process for urgent payment and bank-detail changes.
Protect the accounts that unlock everything else
Business email is often the route to password resets, invoices and trusted conversations. Give every person their own account, use a password manager to create unique passwords and enable multi-factor authentication. Remove access promptly when someone leaves or changes role.
Keep a current list of the owners and recovery methods for the domain name, website, email, banking, accounts software, cloud storage and social media.
Update and control devices
Turn on automatic security updates for computers, phones, browsers and supported network equipment. Use screen locks and device encryption, and know how to disable a lost phone or laptop remotely.
Staff should not need administrator access for everyday work. Separating ordinary use from software installation reduces the damage a malicious attachment can cause.
Make backups usable, not just present
Keep more than one copy of important data and ensure at least one copy cannot be altered through the same login or device as the live files. Ransomware can encrypt connected backups as well as the original data.
Test a small restore regularly. A backup that nobody has successfully restored is only an assumption.
Slow down payment fraud
Create a second-channel check for new bank details, unusual payments and urgent requests from directors or suppliers. Call a known number from your own records rather than the number in the message asking for money.
- Never approve a bank-detail change from email alone
- Use two people for high-value or unusual payments
- Train staff to report mistakes quickly without blame
- Keep the bank and insurer incident numbers available offline
Support remote and travelling staff
Set simple rules for public Wi-Fi, device sharing and confidential calls. A business VPN can protect traffic on an untrusted network, but it does not replace secure cloud services, multi-factor authentication or staff awareness.
VersusVPN offers a plain-English online safety consultation for UK small businesses. It is a practical review and action plan, not a penetration test or a guarantee that an incident cannot occur.
Keep the protection in perspective. A VPN is one useful privacy and security layer. Keep devices updated, use unique passwords and multi-factor authentication, and remain cautious with unexpected messages.