Free guide
Free SME cyber security checklist
40 practical checks to protect your organisation, based on NCSC guidance and the 2026 Cyber Essentials requirements. Work through it in about 30 minutes and finish with a clear action list.
What’s inside
Six areas every SME should check
Our cyber security checklist is written in plain English for owners, managers and charity leaders, not IT specialists.
Accounts and access
MFA, admin rights, password managers and removing access promptly when people leave.
01
Devices and updates
The 14-day patching rule, supported software, encryption and malware protection.
02
Email and payment fraud
Phishing, email authentication and the checks that stop AI-enabled invoice and impersonation scams.
03
Network and cloud
Firewalls, Wi-Fi, secure remote access and the cloud settings most often left on defaults.
04
Backup and recovery
How to make sure your backups would actually get you running again after a ransomware attack.
05
People, suppliers and planning
Training, incident response, supplier checks, Cyber Essentials and cyber insurance.
06
Download your free checklist
Enter your details and you’ll go straight to the download page.
Why we created it
We’ve helped UK organisations stay secure since 2009, and we’re certified to ISO 27001 and ISO 9001. This cyber security checklist brings together the controls we see making the biggest difference, including the stricter Cyber Essentials rules introduced in April 2026.
Prefer to talk it through? Our team can go through the checklist with you and help you prioritise any gaps.
Contact us