Cybersecurity does not begin with an expensive product. It begins with knowing what the business relies on, reducing obvious weaknesses and preparing for the possibility that something will go wrong.

Use this as a starting point

This guide supports an initial self-review. It is not a substitute for an assessment tailored to your systems, information and risks.

01

Protect every important account

Business email, banking, social media and cloud accounts can provide access to valuable information and trusted relationships.

  • Use a different strong passphrase for every important account.
  • Enable multi-factor authentication wherever it is available.
  • Give each employee an individual account.
  • Remove access promptly when someone leaves or changes duties.
02

Keep devices and software current

Unsupported or unpatched systems give attackers opportunities that can often be avoided.

  • Install operating-system, browser and application updates.
  • Remove unsupported or unnecessary software.
  • Use reputable endpoint protection and confirm that it remains active.
  • Encrypt laptops and mobile devices holding business information.
03

Secure business email

Email is a common entry point for fraud and account compromise. Train employees to pause before opening unexpected links, attachments or payment instructions.

Verification rule

Requests involving money, bank-detail changes or sensitive information should be verified using a trusted contact method—not the contact details supplied in the request.

04

Back up important information

  • Identify which information the business could not operate without.
  • Maintain more than one protected copy.
  • Do not leave every backup permanently connected to the same device or network.
  • Test restoration instead of assuming the backup works.
05

Secure Wi-Fi and networks

  • Change default router and administrator credentials.
  • Use modern Wi-Fi encryption and a strong passphrase.
  • Separate guest access from business devices where possible.
  • Keep network equipment updated and replace unsupported hardware.
06

Prepare for incidents

Decide who should be contacted if an account is compromised, a device is lost, ransomware is suspected or information is sent to the wrong person.

Preserve evidence, avoid uncontrolled changes and obtain qualified assistance when necessary.

07

Review risk regularly

Technology, employees and threats change. Review accounts, devices, backups, suppliers and security controls periodically and after significant business changes.

Your next step

Need a structured view of your business risk?

STS can help examine your current environment, prioritise practical improvements and explain the findings clearly.

Explore Cybersecurity Assessments