Skip to main content
Guidance

Small organisations guide to cyber security

Protect your business with the NCSC’s cyber security tips on backups, protecting your devices and accounts, and spotting scams.

Page 6 of 6

Spotting cyber attacks

Cyber attacks often start quietly, and might include:

  • unusual emails in your inbox
  • customers receiving emails from you that you’ve not sent 
  • a login alert you don’t recognise
  • a device behaving slowly or unexpectedly
  • unauthorised payments leaving your account

Spotting phishing scams

85%

of cyber attacks against businesses start with a scam email

Phishing is when scammers use fake emails, texts or calls to trick people into handing over sensitive information or transferring money. Phishing is often the means by which cyber criminals access your accounts or devices, and they might try to get:

  • login or bank details
  • access to sensitive business details, or your customers' details
  • access to your email (from which they can gain control of all your other accounts)

Many phishing messages look convincing. They might pretend to be from someone you know or trust (like a bank, or a part of government), and pressure you into acting fast. They will often contain links to websites controlled by criminals, which may download a virus onto your computer, or steal your login/bank details.

The following example of a phishing email includes a number of tell-tale signs that suggests the email might be suspicious.

a screenshot of a new tax calculation letter
  1. Misspelled email addresses
  2. Unexpected attachments
  3. Generic greetings like ‘Dear valued customer’
  4. Links that direct you to unknown sites
  5. Spelling and grammar mistakes
  6. Poor quality or strange-looking logos

If you have any doubts about a message, contact the organisation directly. Don’t use the numbers or links in the message – use the details from their official website. If you think you’ve clicked on a suspicious message, or you’ve been tricked into sharing your password (or other personal information), don’t panic. Read the NCSC’s phishing advice on steps to take to protect yourself, and follow the appropriate steps. You can also report suspicious messages to the NCSC

Think about what you share online

Consider what information is on your organisation's website and social media pages. What do your website visitors need to know, and what detail is unnecessary (but could be useful for criminals). You can reduce the likelihood of receiving scam messages by removing any content that’s not essential to your business. This could include:

  • staff profiles or biographies
  • blogs that reveal personal information
  • finance contents or details about any third party you use
  • social media posts or links to outdated connections on platforms such as LinkedIn

You and your staff should understand how sharing personal information can affect your organisation, and where necessary you should review your privacy settings within your social media accounts. Where possible, use separate business and personal accounts for social media. If you use personal social media for business, treat it like a business account, which means:

  • review what it reveals publicly
  • apply the same caution you would for business channels
  • control who is allowed to post on your behalf
  • ensure that staff who leave (or change roles) no longer have access

Plan for cyber attacks

Learning to recognise the signs of an attack early - and knowing how to respond - can stop a small issue becoming a major one. If the worse happens and a cyber attack gets through, having a plan means you can act fast, stay in control, and recover quicker. Just like you know what to do if there’s a fire, your business should have a cyber attack plan in place that will define who does what (and when) if something goes wrong. 

Published

Reviewed