Most businesses that experience a serious cyber incident did not lack sophisticated security tools. They lacked the basics. Unpatched systems, weak credentials, no working backups, and unrestricted access are responsible for the majority of successful attacks. Getting the fundamentals right is not a starting point before the real security work begins. It is the real security work for most organisations.

This guide covers the controls that form a credible cybersecurity baseline for a small or mid-size business. None of them require specialised hardware or large budgets. All of them materially reduce the likelihood and impact of a security incident.

Why baseline security is where most incidents start

Attackers follow the path of least resistance. For SMEs, that path is almost always through controls that were never implemented, not through controls that were defeated. Phishing succeeds because MFA was not in place. Ransomware spreads because systems were unpatched. Data is exfiltrated because access controls were too broad. Recovery fails because backups were never tested.

The Verizon Data Breach Investigations Report has consistently found that the overwhelming majority of successful attacks exploit known vulnerabilities, stolen credentials, or phishing rather than advanced techniques. This means the most effective investment for most organisations is not sophisticated detection tooling. It is making sure the basics are in place and maintained.

The baseline controls

Multi-factor authentication

MFA is the single highest-value control for most businesses. It means that a stolen password alone is not sufficient to access an account. Enable it on email, remote access, cloud services, and any system accessible from outside the network. Authenticator apps are significantly more secure than SMS-based codes. MFA should be mandatory, not optional, for any account with access to sensitive data or administrative functions.

Patch management

Operating systems, applications, and firmware should be patched on a defined cycle. Critical security patches, particularly for internet-facing systems, should be applied within 72 hours of release. Most ransomware campaigns exploit vulnerabilities for which patches have been available for months. A documented patch management process, even a simple one, closes the gap between a patch being available and being applied.

Endpoint protection

Every device that accesses business systems should have modern endpoint protection in place. This means more than legacy antivirus. Current endpoint detection and response tools identify and contain threats that signature-based tools miss. Ensure coverage extends to laptops used remotely, not just devices on the office network. Unmanaged personal devices accessing company email or files represent a significant and often overlooked exposure.

Access control and least privilege

Users should only have access to the systems and data their role requires. Administrator accounts should not be used for day-to-day work. Privileged access should be audited regularly and revoked when no longer needed. Stale accounts from former employees, contractors, or test accounts are a common entry point. A quarterly review of who has access to what takes less time than the incident it prevents.

Backup and tested recovery

Backups are only useful if they work and can be restored quickly enough to matter. Follow the 3-2-1 rule: three copies of data, on two different media types, with one stored offsite or in a separate cloud account not connected to the primary environment. Test restores at least quarterly. Ransomware frequently targets backup systems specifically, so air-gapped or immutable backups should be part of the design for any organisation handling sensitive data.

Network segmentation

Flat networks allow an attacker who gains access to one system to move freely to others. Basic segmentation, separating guest Wi-Fi from the corporate network, isolating operational technology from IT systems and restricting server-to-server communication, limits the blast radius of a compromise. This does not require complex infrastructure. VLAN configuration on a managed switch is sufficient for most SME environments.

Email security

Email is the primary delivery mechanism for phishing, malware, and business email compromise. At a minimum, configure SPF, DKIM, and DMARC records to prevent domain spoofing. Use a mail gateway or filtering service that inspects attachments and links before delivery. Train staff to recognise phishing, but do not rely on training alone. Technical controls catch what awareness misses.

Incident response plan

An incident response plan does not need to be long. It needs to answer three questions: who decides when an incident is serious enough to escalate, who gets called when it is, and what do we do in the first four hours. Organisations without a plan make worse decisions under pressure, take longer to contain incidents, and often make them worse by taking the wrong initial action. Write it down before you need it.

Frameworks that map to this baseline

If your organisation operates in a regulated sector or is considering cyber insurance, two frameworks are worth understanding in relation to this baseline.

Cyber Essentials (UK) covers five technical controls: firewalls, secure configuration, access control, malware protection, and patch management. Certification is relatively straightforward for organisations that have the basics in place and provides a useful third-party validation of your security posture. Many public sector contracts and some insurers require it.

ISO 27001 goes significantly further, requiring a full information security management system. It is appropriate for organisations with regulatory obligations, large client bases, or significant data handling responsibilities. The baseline controls described here form a subset of what ISO 27001 requires. See our ISO 27001 guide for SMEs for a more detailed walkthrough.

NIS2 applies to organisations in critical sectors across the EU and imposes mandatory incident reporting and minimum security measure requirements. The baseline controls in this article align closely with what NIS2 requires at the foundational level. Our NIS2 guide covers the full scope of obligations.

Cyber Essentials Is the Starting Point

The UK government-backed Cyber Essentials scheme is the most accessible entry point if you want to establish a credible security posture. Certification costs between £300 and £500 for the basic self-assessed route and covers five technical controls: firewalls, secure configuration, user access control, malware protection, and patch management. The NCSC's own analysis found that these five controls prevent around 80% of common cyberattacks. For under £500, that is hard to argue with.

Cyber Essentials Plus adds external vulnerability scanning and an independent hands-on assessment of your systems. IASME Cyber Assurance goes further, incorporating governance, risk management, and supply chain security requirements. The three tiers are a progression.

If your IT hygiene is already in reasonable shape, the basic certification takes two to four weeks to complete. It is also a mandatory requirement for bidding on UK government contracts that involve handling personal data or sensitive information.

Cyber Essentials does have clear limits. It does not cover social engineering, phishing simulation, incident response planning, or business continuity. A certificate will not stop an attacker who targets your people rather than your systems. The scheme confirms you have covered the fundamentals. Treat it as the floor and the starting gun for further work.

The Cost of Skipping Cybersecurity Basics

The most common reason SMEs delay security investment is cost. UK government data tells a different story.

The UK government's Cyber Security Breaches Survey 2024 found that 50% of UK businesses experienced a cyberattack or breach in the past 12 months. For small businesses, the average direct cost of a breach was £1,205. For larger SMEs, the figure climbs to £10,830 or more. Those figures cover only the immediate response: IT remediation, recovery activity, and notification. They exclude downtime, lost revenue, and reputational damage.

Operational disruption is the largest single cost. One to three days of downtime will almost always cost you more than the direct remediation bill if you have no tested recovery plan. For a professional services firm or a retailer, the calculation is straightforward: multiply your daily revenue by three and compare it against the cost of a tested backup solution.

Cyber insurance is becoming harder to obtain without evidence of basic controls. Insurers have raised premiums 20 to 30% per year for SMEs without demonstrable security. Many now require evidence of Cyber Essentials certification or an equivalent assessment before they offer a quote. Insurers can also void a claim if they find an undisclosed security gap after an incident, which is a worse outcome than a higher premium.

GDPR adds a regulatory dimension that many SMEs underestimate. The ICO levied £6.09 million in fines in 2023 and can fine you up to 4% of global annual turnover in the most serious cases. For a business with a £2 million turnover, that ceiling sits at £80,000, far above what it costs to get the fundamentals right.

Cyber Essentials Plus certification combined with a decent email security gateway, endpoint protection, and a half-day of staff awareness training costs between £2,000 and £5,000. That is ten to twenty times less than the average breach cost once you factor in downtime and recovery. Treating security basics as an optional extra is an unacknowledged bet that you will not be among the 50% of businesses hit this year.

Your 10-Point Cybersecurity Baseline Checklist

Use this as a quick sense-check against your current security posture. If you cannot answer yes to all ten, the gaps are your priority.

  1. 1Multi-factor authentication enabled on all remote access and email accounts
  2. 2Automatic patching enabled for operating systems and key applications, with a 48-hour window for critical patches
  3. 3Separate admin accounts used for privileged tasks; no day-to-day browsing or email as an administrator
  4. 4Email filtering active, such as Microsoft Defender for Office 365 Plan 1 or an equivalent mail gateway
  5. 5Offsite or cloud backups tested within the last 30 days and confirmed as restorable
  6. 6Endpoint protection active on all devices, including staff laptops used at home or remotely
  7. 7DNS filtering in place to block connections to known malicious domains
  8. 8A password manager rolled out to all staff, replacing spreadsheets and shared password documents
  9. 9At least one phishing simulation run in the past six months, with results reviewed and acted on
  10. 10An incident response contact list documented: who to call in the first hour if a breach is suspected

Where to start if you are starting from scratch

Trying to implement everything at once rarely works. Prioritise in this order:

  • MFA on email and remote access:this week
  • Patch management process:define, document, and execute within the month
  • Backup testing:confirm backups exist and can be restored
  • Access review:remove stale accounts and excess privileges
  • Endpoint protection:verify coverage across all devices
  • Email security configuration:SPF, DKIM, DMARC
  • Incident response plan:one page, written down

A security assessment gives you a clear view of where you stand against this baseline, what the gaps are, and what the priority order should be for your specific environment. It is a faster and more reliable starting point than trying to self-assess.