Guidance
Small organisations guide to cyber security
Protect your business with the NCSC’s cyber security tips on backups, protecting your devices and accounts, and spotting scams.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Protect your business with the NCSC’s cyber security tips on backups, protecting your devices and accounts, and spotting scams.
Page 6 of 6
Cyber attacks often start quietly, and might include:
of cyber attacks against businesses start with a scam email
Phishing is when scammers use fake emails, texts or calls to trick people into handing over sensitive information or transferring money. Phishing is often the means by which cyber criminals access your accounts or devices, and they might try to get:
Many phishing messages look convincing. They might pretend to be from someone you know or trust (like a bank, or a part of government), and pressure you into acting fast. They will often contain links to websites controlled by criminals, which may download a virus onto your computer, or steal your login/bank details.
The following example of a phishing email includes a number of tell-tale signs that suggests the email might be suspicious.

If you have any doubts about a message, contact the organisation directly. Don’t use the numbers or links in the message – use the details from their official website. If you think you’ve clicked on a suspicious message, or you’ve been tricked into sharing your password (or other personal information), don’t panic. Read the NCSC’s phishing advice on steps to take to protect yourself, and follow the appropriate steps. You can also report suspicious messages to the NCSC.
Consider what information is on your organisation's website and social media pages. What do your website visitors need to know, and what detail is unnecessary (but could be useful for criminals). You can reduce the likelihood of receiving scam messages by removing any content that’s not essential to your business. This could include:
You and your staff should understand how sharing personal information can affect your organisation, and where necessary you should review your privacy settings within your social media accounts. Where possible, use separate business and personal accounts for social media. If you use personal social media for business, treat it like a business account, which means:
Learning to recognise the signs of an attack early - and knowing how to respond - can stop a small issue becoming a major one. If the worse happens and a cyber attack gets through, having a plan means you can act fast, stay in control, and recover quicker. Just like you know what to do if there’s a fire, your business should have a cyber attack plan in place that will define who does what (and when) if something goes wrong.


