Business security solutions for UK small businesses

Business Security Solutions for UK Small Businesses: What to Buy and When

Table

Security spending for a small business is mostly about sequencing: cheap controls first, specialist services only when something specific demands them. The terms vendors use, from cloud security solutions to privileged access management, sound similar but solve different problems and carry very different price tags.

Buy in this order

StageWhat to put in placeWhen it matters
1Backups kept offline or immutable, automatic updates, multi-factor authentication, antivirus or endpoint protection and a business password managerAlways
2Cyber Essentials certification, the government-backed schemeCustomers or tenders ask for it
3Cloud security solutionsMost of your work runs in cloud apps
4Privileged access managementSeveral administrators, contractors or regulated data
5Penetration testingBefore a launch, a large contract or a compliance deadline
6An incident response provider on callYou hold data you can't afford to lose

Stage 1 covers most of the risk for a small firm. See our guide to cloud backup software for small business for the backup side.

Cloud security solutions

Cloud security solutions protect the cloud services you already use: strong sign-in with multi-factor authentication, configuration checks so storage isn't left open to the internet, and alerts on unusual logins. A cloud security solutions company or reseller can set this up, but start with the controls built into Microsoft 365 or Google Workspace. A cloud security solutions architect is a job title rather than a product: a specialist who designs this, usually for larger organisations. Most small firms are better served by a managed IT provider.

Privileged access management (PAM)

Privileged access management software controls and records who can use powerful accounts, such as server administrators. Privileged access management solutions typically vault shared admin passwords, grant access for a limited time and log sessions. CyberArk is one of the best-known vendors, and analyst reports such as Gartner's cover the market, but PAM tools are built for organisations with many administrators and compliance demands. A ten-person business usually gets most of the benefit from separate admin accounts, multi-factor authentication and a password manager. Open-source privileged access management tools exist, but they need in-house expertise to run and maintain.

Penetration testing

Penetration testing services in the UK simulate an attack to find weaknesses before criminals do. Look for providers accredited by CREST, and ask who will do the work and what qualifications they hold. A pen testing certification such as OffSec's OSCP, or CREST's own exams, shows hands-on skill, which matters more than a long list of acronyms. Testers often use Kali Linux, a free distribution built for security testing, but you should only test systems you own or have written permission to test: unauthorised access is an offence under the Computer Misuse Act 1990. Integrated penetration testing usually means a package covering network, web application and sometimes phishing tests, so get the scope in writing and ask for a retest once you have fixed the findings.

If ransomware hits

The NCSC and UK law enforcement do not encourage paying a ransom. There is no guarantee you will get your data back, your systems will still be infected, you fund criminals and you are more likely to be targeted again. The ICO does not treat paying as an appropriate way to restore personal data, and if a breach is likely to put people at risk you must report it to the ICO within 72 hours. The NCSC recommends using an NCSC-assured Cyber Incident Response provider.

Be careful with ransomware recovery services and ransomware data recovery services that promise to unlock any file type. Some firms have been reported to pay the attacker on the client's behalf while charging extra, so ask exactly how they recover data and whether they pay ransoms. A recent offline backup remains the best protection.

Insurance covers the financial side but doesn't replace these controls; insurers often ask about backups, multi-factor authentication and endpoint protection. See our guide to cyber liability insurance for small business.

Go up