Small organisations guide to cyber security
Protect your business with the NCSC’s cyber security tips on backups, protecting your devices and accounts, and spotting scams.
Page 2 of 6
Secure your email
If a criminal hacks into your business email account, they could:
- access private information about you (including your banking details)
- post emails and messages pretending to be from you (and use this to trick other people)
- gain access to other accounts (for example by resetting passwords)
Business emails also qualify as data, so you must protect your account as part of your GDPR obligations.
Email accounts are a common target for attackers because access to one inbox often gives access to other systems and sensitive information. Protecting how users sign in is one of the most effective ways to reduce the risk of compromise.
Use passkeys where possible
Passkeys are a more secure alternative to passwords that you don't need to remember as they are created and managed safely by a service on your device(s).
The main benefits of using passkeys are:
- They are more secure
Passkeys can’t be intercepted, reused or stolen like passwords. This removes one of the most common ways accounts are compromised. - They are fast and convenient
Passkey logins much faster than signing in with username, password and 2SV code, and you don’t need to remember anything. - They offer greater resilience
When combined with keeping your devices and apps up to date, passkeys significantly reduce the likelihood of phishing attacks. This means the more UK organisations choose to adopt passkeys, the greater our national resilience to phishing attacks.
Where your email provider supports passkeys, you should enable them for staff accounts as a priority.
For instructions on how to use passkeys for your email accounts, please refer to the following links:
- Microsoft Outlook: Signing in with a passkey
- Google Gmail: Sign in with a passkey instead of a password
- Yahoo Mail: Create a passkey
Use strong passwords and 2-step verification
If your email service does not yet support passkeys, protect accounts using a strong, unique password and 2‑step verification (2SV). Even when you are using a passkey, if your email account still has a password set, it should be strong and unique, and supported by 2SV.
Use a strong and unique password
If you’re not using passkeys, it’s essential that your email account is protected by a strong and separate password. That is, use a password that you don’t use for any of your other accounts, either at home or at work. If you've used the same password across different accounts, cyber criminals only need one password to access all your accounts. Refer to the section above for tips on creating strong passwords.
If you have re-used your email password across other accounts, change your email password as soon as possible. Below we've provided links that explain how to change email passwords.
- Change your password in Outlook
- Google: Change or reset your password
- Change your Apple Account password
- Reset or change your Yahoo password
- Change or reset your BT Email password
Turn on 2SV
2SV, which is also known as two-factor authentication, keeps cyber criminals out of your accounts even if they know your passwords.
When you set up 2SV, you’ll normally be sent a PIN or code, often by SMS or email. You then need to enter this PIN to prove that it's really you - since it’s presumed only you (not the cyber criminal) can access your phone or email.
Below we've provided links that explain how to turn on 2SV for your email passwords.
Note
There are different types of 2SV available - including using ‘authenticator apps’ or backup codes - which you should consider (for instance, if you’ve lost your phone). Any type of 2SV is better than none. For more details refer to the NCSC’s guidance on setting up 2-step verification.
Use a password manager
Creating different passwords for all of your important accounts - and remembering them - is difficult. This is why the NCSC recommends you save your passwords to your device/browser, or use a password manager. Password managers can also help you to create new passwords, and to create and store passkeys.
You will need to use a password manager (also called a credential manager) if you use passkeys to secure any of your accounts.
Saving passwords on your device
If your team all use the same types of device (for instance, all iPhones, or all Android phones), then using the password managers that are built into your device is a good option. As with all passwords, your ‘master password’ should be unique, strong, and not be based on any personal info.
Using a password manager app
If you use different browsers to access your work accounts, and perhaps even different types of devices (such as laptops and phones), then using a ‘password manager app’ is a good option. These apps can synchronise your passwords across different devices. Many password manager apps will also provide extra features, such as generating strong passwords for you. You can use trusted sites online to find a password manager that’s right for you. Remember, if you're downloading a password manager app, make sure it's from an official app store.
Saving passwords in your browser
If you use a browser to access most of your online work accounts, then browser-based password managers that are built into all popular browsers (such as Chrome, Safari and Edge) are a good option. They remember and ‘auto-fill’ your passwords, meaning you can log in with a single click.


