Free guide · 13 pages · 10 Minute Read

Cyber security tips for the person who signs off the budget

Most cyber security advice is written for the person who configures the firewall. This one is written for the person who pays for it. Six threats that actually reach UK businesses, what each one costs when it lands, and the control that answers it.

  • The six threats reaching UK SMEs — threat, risk and solution, one page each
  • What a realistic IT and security budget looks like as a percentage of turnover
  • Twelve questions to put to whoever runs your IT, and what a good answer sounds like
  • Where Cyber Essentials and cyber insurance genuinely fit — and where they do not
Written by our CTO No sales call required Instant download

Download the free guide

Add your details and the PDF opens straight away.

We use your details to send the guide and occasional cyber security tips for UK businesses. Unsubscribe in one click. See our privacy policy.

Why this guide exists

Nobody argues about seatbelts any more

In 1970, 7,499 people died on Britain's roads. Last year the figure was under 1,700, on far more traffic. That did not happen because drivers got better — it happened because every serious crash was investigated and the fix became standard. Cyber security works the same way, on a much shorter cycle. The difference is that the baseline moves every year rather than every decade.

Contents

What is in the guide

Thirteen pages. No product pitch, no configuration detail — the commercial case, in plain language.

01
Foreword · why the car industry is the right comparison
02
How standards move · fifty years of learning from every crash
03
Active and passive protection · brakes and airbags
04
Six threats, and what answers them · threat, risk, solution
05
The management layer · the service, not the showroom
06
Budget, certification and insurance · the MOT and the policy
07
Twelve questions to ask · what good looks like
08
Three things to take away · the summary for the board
Section four

The six threats that reach UK businesses

Each one comes with the business risk it creates and the control that answers it. Every control in the guide can be put in place and evidenced.

Threat 01

Phishing

A message asking one of your staff to hand over a credential, approve a payment or open a file. Cheap to send at volume, and now well written.

Threat 02

Ransomware

The one that stops you trading. Order processing, payroll and client records all become unavailable at once, for days rather than hours.

Threat 03

Social engineering

No software is exploited. The target is a person — a call to your service desk, or a supplier asking to update their bank details.

Threat 04

Spear phishing and AI voice spoofing

Voice cloning now makes a convincing phone call from a few seconds of recorded audio, aimed at the handful of people who can move money.

Threat 05

Business email compromise

An attacker sits quietly inside a mailbox and joins the thread with new bank details. After 24 hours the funds are rarely recoverable.

Threat 06

Guest and business Wi-Fi

A flat network where a visitor's phone, a CCTV camera and the finance PC all sit together. A route in that requires nobody to click anything.

43%

of UK businesses experienced a breach or attack in the previous twelve months

65%

the figure rises for medium-sized businesses, where the estate is larger and less reviewed

0.5–1.5%

of turnover is the indicative benchmark for total IT spend, security included

Source: UK Government Cyber Security Breaches Survey. Budget figures are indicative and set out in full in the guide.

Section seven

Twelve questions to put to whoever runs your IT

You should not need technical knowledge to assess your own exposure. You need the answers to be specific, evidenced and dated. Anything answered with “I think so” is a gap.

  • Is multi-factor authentication enforced on every account, including administrators?
  • When did we last restore from backup as a test, and how long did it take?
  • Is EDR on every endpoint, and who acts on its alerts at 3am?
  • What is our process for a supplier changing bank details, and is it written down?
  • If we lost everything tonight, what is the agreed recovery time, and who signed it off?

All twelve are in the guide, alongside the answer that should worry you.

Matthew Dodd

Chief Technology Officer and co-founder, entrustIT

Cyber security is a standing operating cost with a measurable return, and it should be budgeted like one. This guide sets out the threats that actually reach UK businesses, what each one costs when it lands, and the part most businesses get wrong — keeping those controls working after they are bought.

Recently recognised
ISO 27001 certified ISO 9001 certified MSP of the Year 2026 · Thames Valley Tech & Innovation Awards MSP of the Year 2025 · South Coast Tech & Innovation Awards Tech SME of the Year 2025 CloudTango MSP UK Select 2026
Common questions

Cyber security tips: the questions we get asked most

What are the most important cyber security tips for a UK business?

Enforce multi-factor authentication on every account without exception, hold immutable off-site backups that you have actually restored from, run endpoint detection and response with someone watching the alerts out of hours, configure SPF, DKIM and DMARC on every domain you send from, and put a written out-of-band verification step in front of any change to supplier bank details. Those five cover the large majority of incidents that reach businesses of this size.

Who is this guide written for?

Owners, finance directors and operations leads who sign off the IT budget and want the commercial case rather than the configuration detail. If you are looking for a technical implementation manual, this is not it.

Does Cyber Essentials make my business secure?

Not directly. Cyber Essentials is an independent statement that the basics are covered — patching, access control, MFA, malware protection and firewalls. Think of it as the MOT certificate rather than the car. Following Cyber Essentials standards will make your business more secure though. It is increasingly a condition of tender and of sitting in someone else's supply chain, which is a commercial reason to hold it in its own right.

How much should we be spending on cyber security?

The guide uses an indicative benchmark of 0.5% to 1.5% of turnover for the whole IT function — support, infrastructure, licensing, hardware refresh and security as one combined budget, rather than security as a line on top. Businesses holding sensitive data or running multiple sites sit at the upper end.

Will I be added to a sales sequence?

You will get the download link and occasional cyber security tips by email. You can unsubscribe in one click and we will not call you unless you ask us to.

Get the guide

Thirteen pages on what actually threatens a UK business, what it costs, and what to do about it. Free, and no call required.

Download the free guide

Would rather talk it through? Book a free cyber posture assessment.