ChecklistApproved
Basic cybersecurity for SMEs
Ten low-cost steps that stop most common attacks.
16 Aug 20264 minValid until 3 Oct 2027
Basics
Offline backups, two-factor sign-in, system updates and phishing awareness for staff.
Suggested actions
- Enable two-factor sign-in for email and finance systems
- Set up weekly offline backups and test restoring them
- Train staff to recognise phishing emails
Possible causes
- Weak or reused passwords
- No offline backup
- Unpatched software
Required documents
- List of key systems and accounts
Warnings
- In a ransomware attack, disconnect infected systems and do not delete evidence