Resources
Cyber security guides for SMEs in the UK, BVI & USA.
How to pass Cyber Essentials. What to do in the first hour of a ransomware incident. How much an SME should actually spend on security. Plain-English guides for owners, MDs and finance directors — not IT specialists.
Foundational guides
Cyber Security for UK SMEs
The threats UK small businesses really face, and the controls that stop them.
Read guide GuideWhat is Cyber Essentials?
The UK government-backed certification, explained in plain English.
Read guide GuideHow Cyber Attacks Actually Happen
Phishing, ransomware, credentials and staff risk — how real incidents unfold.
Read guide GuideCyber Essentials Checklist for SMEs
A step-by-step readiness check across all five technical controls.
Read guideHow to protect your business from ransomware in 2026
The controls that actually stop modern ransomware attacks in UK SMEs — explained in plain English, in priority order.
Read guideHow phishing attacks actually happen (with real examples)
A non-technical walkthrough of how modern phishing lands in UK business inboxes, with real anonymised examples — and what stops them.
Read guideWhat is Cyber Essentials and do I need it?
A plain-English explainer of the UK's baseline cyber security certification — what it covers, who needs it, and how to know if it's right for your business.
Read guideWhat is ransomware? A plain-English guide for UK SMEs
How modern ransomware works, why it targets smaller businesses and what an attack actually looks like.
Read guideCyber Essentials vs Cyber Essentials Plus: which one do you need?
A clear side-by-side comparison of scope, evidence and cost — and how to pick the right level.
Read guideWhere to start with cyber security as an SME in 2026
A pragmatic 5-step roadmap for businesses with no dedicated security team.
Read guideFAQ
Resources FAQs
How to use our guides and where to start, whatever stage of the cyber security journey you're at.
What kind of resources are available on this page?
+
Plain-English guides, checklists and blog articles covering Cyber Essentials, phishing, ransomware, compliance and practical security decisions for SME owners and finance directors. They're written for people running a business, not IT specialists, and cover both foundational topics — like what Cyber Essentials actually involves — and specific incident scenarios, such as what to do in the first hour of a ransomware attack.
Where should someone new to cyber security start reading?
+
Start with the foundational guides: Cyber Security for UK SMEs for a broad overview of the threats small businesses actually face, What is Cyber Essentials? if certification is the immediate priority, and How Cyber Attacks Actually Happen to understand how incidents like phishing and ransomware unfold in practice. From there, the blog covers narrower topics such as costs, specific threats and compliance requirements in more depth.
How should an SME owner use these guides to make decisions?
+
Use them to get a working understanding of a topic before a conversation with a provider or an internal decision, not as a substitute for a proper assessment of your own business. If a guide raises a risk that sounds relevant — client-money fraud, ransomware downtime, a compliance deadline — that's the signal to book a free review so we can look at how it applies to your specific setup.
Are these resources relevant outside the UK, for BVI and USA readers?
+
Most of the underlying threats — phishing, ransomware, weak credentials, unpatched software — are identical regardless of jurisdiction, so the practical guidance applies broadly. Where content covers UK-specific schemes such as Cyber Essentials, BVI and US readers should treat it as a reference point for what good practice looks like, and we can advise separately on the equivalent local compliance expectations for their jurisdiction.
How often is this content updated, and can it be trusted as current?
+
Guides are reviewed and updated as threats, guidance and certification requirements change, and each blog post carries a publication date so you can judge its currency. For anything time-sensitive — current attack trends, scheme requirement changes — the most recent posts and a direct conversation with our team will always be more reliable than relying solely on any single article.
Two ways to get started
Not sure what you need? Speak to us. Want ongoing protection? Try it free.
Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

