Small organisations guide to cyber security
Protect your business with the NCSC’s cyber security tips on backups, protecting your devices and accounts, and spotting scams.
Page 3 of 6
Secure your important online accounts
Once you've secured your email, you should check all the other online accounts your business relies on, especially those that store customer or staff information, or would cause serious disruptions if stolen.
This might include:
- banking and finance accounts
- HR and payroll systems
- social media (Instagram, Facebook, X, LinkedIn)
- online storage (Google Drive, OneDrive, iCloud)
- your company website (and domain hosting if that is a separate account)
- point of sale (POS) software
Protecting how users sign in to these accounts is one of the most effective ways to reduce the risk of compromise.
Using passkeys for important accounts (recommended)
Passkeys are still a relatively new technology, but many popular websites, apps and organisations (such as Ebay, LinkedIn, Amazon, PayPal and WhatsApp) are adding passkey support all the time.
Passkeys provide a simpler and more secure way of signing in than using passwords or 2‑step verification (2SV). They protect against common attacks such as phishing because you can’t be tricked into sharing a passkey with a criminal.
If you use passkeys, you don’t need to remember passwords for the accounts you regularly access, as your device will securely store them for you.
Where passkeys are available, you should enable them for business‑critical accounts as a priority.
You can check which services support passkeys by visiting the WhoSupportsPasskeys website.
Use strong passwords and 2‑step verification (2SV)
If a service does not yet support passkeys, you should make sure accounts are protected using a strong password and 2‑step verification (2SV). Even when you are using passkey, if your accounts still have passwords set, they should be strong, unique to the account, and supported by 2SV.
As with your email account, make sure important online accounts are protected using a strong password that you don’t use for any other account. If you have reused passwords across business‑critical accounts, you should change them as soon as possible.
Turning on 2SV is one of the most effective ways to protect online accounts when passwords are still in use, as it helps prevent criminals from gaining access even if they know the password.
Use strong passwords for important accounts
If a service does not yet support passkeys, you should make sure accounts are protected using a strong password and 2‑step verification (2SV).
As with your email account, you should make sure that all your online accounts are protected using a strong password that you don’t use for any of your other accounts. Refer to the previous section for tips on creating strong passwords, and on using a password manager.
If you have re-used any of your passwords across business-critical accounts, you should change them as soon as possible. Below we've provided links that give specific instructions about changing passwords for common accounts.
Update your online storage passwords
Update your social media passwords
Turn on 2SV
Below we've provided links that give specific instructions about turning on 2SV for common products. You can find instructions for other products on their official support websites.
Turn on 2SV for social media
Turn on 2SV for other accounts
There are different types of 2SV available - including using ‘authenticator apps’ or backup codes - which you should consider (for instance, if you’ve lost your phone). Any type of 2SV is better than none. For more details refer to the NCSC’s guidance on setting up 2-step verification.
Removing unnecessary user accounts
Over time, your business may have created accounts for staff, suppliers or contractors, across tools like email, cloud storage, social media and finance systems. When people leave or no longer need access, those accounts often stay active without anyone noticing, so are more likely to have outdated passwords and security settings. For this reason, you should remove or disable the accounts you no longer use.
Below we've provided links that give specific instructions about removing common accounts. For services related to your business's website, banking and finance, HR and payroll, point of sale, and payment, visit their official website for guidance on removing or disabling users.
Remove online storage accounts
Remove social media accounts
Tip
Staff come and go, and people’s roles change. Make it a habit to review who has access to important accounts every few months, and remove anyone who no longer needs it.
Create separate user and administrator accounts for laptops/desktops
Most laptops, PCs and Macs come with one main account, usually an administrator, that you use when logging in. That account can install apps, change settings and control the whole device.
If you're using this administrator account when you suffer a cyber attack, a criminal could take full control of your device and accounts, and even lock you out. For this reason, you should create an additional standard user account, and use this for all your day-to-day work.
By using a standard user account for everyday tasks (and reserving administrator access only when needed) you reduce the risk of serious harm. We’ve included links below that explain how to create additional user accounts for Windows and Apple devices. Note that you must be logged in as administrator to add standard accounts.
- Microsoft: Manage user accounts in Windows
- Apple: Add a user on MAC