Is Your Business Cyber-Safe? 8-Question Security Check for UK Small Businesses
43% of UK businesses reported a cyber attack in the past year, and 96% of those targeted SMEs. This traffic light assessment checks 8 critical areas of your cyber security and shows you exactly where you are protected, where you have gaps, and where you are at risk.
How to use
For each of the 8 questions, select the green, amber, or red answer that most honestly describes your current situation. At the end, you will see your overall score, a breakdown by category, and specific action items for any red or amber areas.
Understanding Your Cyber Security Score
Your score reflects how well-protected your business is across 8 key areas. A green rating means that area is well-covered. Amber means you have partial protection but gaps remain. Red means that area is unprotected and represents a genuine vulnerability. The good news is that most cyber security improvements for small businesses are low-cost and straightforward to implement.
Frequently Asked Questions
How much does a cyber attack cost a small business?
The average cost of a cyber attack on a UK small business is 8,170 pounds according to the UK Government Cyber Security Breaches Survey. This includes direct costs (ransom payments, system recovery, lost revenue) and indirect costs (reputational damage, customer loss, regulatory fines). For businesses that hold customer data, GDPR fines can add significantly to this figure.
What is the most common type of cyber attack on small businesses?
Phishing emails are by far the most common attack vector, responsible for around 83% of incidents. These are fraudulent emails designed to trick recipients into clicking malicious links, downloading malware, or revealing login credentials. Training staff to recognise phishing attempts is the single most effective defence.
Do I need cyber insurance?
If your business stores customer data, processes payments, or relies on computer systems to operate, cyber insurance is strongly recommended. Standard business insurance rarely covers cyber incidents. A standalone cyber policy typically covers incident response, forensic investigation, legal fees, customer notification, and business interruption.
What is two-factor authentication and why does it matter?
Two-factor authentication (2FA) adds a second verification step when logging in, such as a code from an app or text message. Even if an attacker steals your password, they cannot access your account without the second factor. Enabling 2FA on email, banking, and accounting software is one of the most effective security measures you can take.
How often should I back up my business data?
Critical business data should be backed up daily. Backups should be automatic (not relying on someone remembering), stored separately from your main systems (cloud or external drive), and tested regularly to ensure they can actually be restored. A backup that has never been tested is a backup that might not work when you need it.
Related Tools
Business Financial Health Check
Assess your overall business health across 10 key areas.
Financial Visibility Score
How much visibility do you have over your financial position?
Growth Readiness Scorecard
Score your readiness to scale across operations, finance, and people.
Year-End Tax Checklist
Personalised checklist to make sure nothing is missed at year-end.
Need help with this?
Book a free 30-minute discovery call and we will give you straightforward, jargon-free advice on your specific situation.
Book a Free Discovery Call© Imperial Consulting Limited, trading as Grosvenor.Solutions. Registered in England. This tool is for educational and illustrative purposes only. It does not constitute financial, tax, or legal advice. Consult a qualified professional for decisions affecting your business.