If you don't have a dedicated security team — and most UK SMEs don't — the cyber security market can feel overwhelming. Hundreds of vendors, dozens of acronyms, contradictory advice. Here's the pragmatic version, in five steps.
Step 1 — Know what you're protecting
List your crown jewels: customer data, financial systems, intellectual property, the email account that approves payments. You can't defend what you haven't named.
Step 2 — Get identity right
Identity is the new perimeter. MFA on every account, Conditional Access policies, no shared logins, prompt deactivation of leavers. This single area prevents more breaches than any other.
Step 3 — Modernise the endpoint
Replace legacy antivirus with EDR. Make sure laptops are managed (MDM), patched within 14 days, and don't run as local admin day-to-day.
Step 4 — Add eyes on the alerts
EDR generates alerts. Alerts only matter if a human acts on them — at 2am on a Sunday as well as 10am on a Tuesday. That's what MDR (managed detection and response) provides. For most SMEs, an MDR subscription is dramatically cheaper than hiring.
Step 5 — Practice the bad day
Write a one-page incident plan. Run a 60-minute tabletop with the leadership team once a year. The first time you discuss a breach should never be during one.
What to skip (for now)
- Buying a SIEM you have no one to operate.
- Penetration tests before you have basic hygiene in place.
- Long policy documents no one reads.
Next step
Want this turned into a plan for your business? Book a free 30-minute review — we'll walk through these five steps against your reality and give you a one-page roadmap.

