Skip to content
Back to blogcybersecurity

The 2026 SME Cybersecurity Checklist

Wanzo Team·2026-03-01·5 min read

Attackers go after small and medium businesses more than 65% of the time. They're counting on those organisations having weaker controls. Work through this checklist to see which protections you already have and which still need attention.

1. Identity and Access

Most incidents begin with a stolen login rather than a hole in the network. Treat accounts as the first control you lock down.

  • Multi-factor authentication (MFA) on every cloud application, including Microsoft 365, CRM and accounting software. The extra step at sign-in stops most account takeovers.
  • No shared passwords. Each person has their own credentials for each system.
  • Privileged access management. Admin accounts stay separate from day-to-day logins. Staff don't open email with domain admin credentials.
  • Offboarding process. When someone leaves, every account is disabled within 24 hours.

2. Endpoint Security

Any laptop, phone or tablet that reaches your network or cloud apps is a way in.

  • Endpoint Detection and Response (EDR) on every device. Signature-based antivirus misses attacks it has never seen. Behavioural detection picks up that activity on the machine.
  • Mobile Device Management (MDM). Encryption, PIN locks and remote wipe on every mobile device that holds company data.
  • Full disk encryption. A lost or stolen laptop leaves the data unreadable.
  • USB control. Blocking USB mass storage reduces the chance of files leaving on a stick.

3. Email Security

Phishing, malware and business email compromise still arrive through the inbox more often than through any other channel.

  • Advanced anti-phishing. Detection that catches impersonation attempts ordinary filters miss.
  • DMARC, DKIM and SPF on your domain. These records stop attackers sending mail that looks as if it came from you.
  • Attachment sandboxing. Suspicious files run in an isolated environment before they reach the recipient.
  • Link rewriting. URLs are checked at the moment someone clicks, not only when the message arrives.

4. Patching

Unpatched software remains the vulnerability class attackers exploit most often worldwide.

  • Operating system patches. Windows, macOS and Linux updates applied within 14 days of release.
  • Third-party software. Browsers, PDF readers, Java and Zoom follow the same cadence.
  • Critical patches. Anything marked critical or actively exploited goes on within 72 hours.
  • Firmware updates. Firewalls, switches and access points sit inside the same patch cycle.

5. Backup and Recovery

Ransomware only fails if you can restore clean data. Copies you have never restored will not help you when you need them.

  • The 3-2-1 rule. Three copies of your data, on two different media types, with one copy offsite.
  • Quarterly tests. Restore a sample on a set schedule so you know the process works.
  • Offline copy. At least one backup the live network can't reach, held in air-gapped or immutable storage.
  • Defined RTO and RPO. You know how quickly you can recover and how much data you would lose.

6. Network Security

Once an attacker is on the network, every system attached to it is exposed. Build these controls into your cybersecurity service.

  • Managed firewall. Next-generation hardware with live threat intelligence. A domestic broadband router does not meet this standard.
  • VPN or ZTNA for remote access. Remote Desktop Protocol must not face the public internet.
  • Network segmentation. Guest Wi-Fi, IoT devices and point-of-sale systems sit on separate VLANs from the business network.
  • DNS filtering. Known malicious domains are blocked before a user can open them.

7. User Training

Staff who handle email and files every day will see attacks first. They need regular practice and a clear way to raise a concern.

  • Phishing simulations. Quarterly tests that show who clicked and who reported, then follow with coaching.
  • Annual security training. Mandatory for everyone, covering current threats and your company policies.
  • Incident reporting. Make it simple to flag suspicious activity without fear of blame.
  • Written policies. Acceptable use, passwords, remote working and BYOD, documented and given to staff.

8. Compliance

A certificate doesn't replace the controls above. Use it as a recognised baseline.

  • Cyber Essentials as a minimum. It's the UK government's baseline security standard and a requirement for many government contracts.
  • GDPR data mapping. You know what personal data you hold, where it lives and who can see it.
  • ISO 27001. Worth pursuing if you handle sensitive client data or operate in a regulated sector.

Predictive monitoring

Once the controls above are running, they still need watching. Predictive monitoring flags emerging technology problems before they cause wider disruption. It belongs with managed IT, because the team that patches and restores your systems also needs to see those warnings.

What to do next

Work through the list and mark what you already run. Wanzo offers a free security assessment across these areas. We'll tell you what to fix first. Write to us to arrange it.

Twice a month, nothing more

What we automated recently, what it saved, and what didn’t work.

Unsubscribe in one click, any time.

Working on cybersecurity?

Tell us what's slowing your team down and we'll set out what we'd automate first.

No commitment. No sales pressure. Just honest advice.