• Cyber security awareness

  • Do you create regular backups of important files and data?

    This could be using cloud storage (Google Drive, OneDrive, DropBox etc.) or physical backups like on hard drives or printed copies.
  • Do you create regular backups of important files and data?*
  • Do you postpone software or system updates?

    Even if you install updates eventually, if you postpone or 'snooze' updates when they first become available, answer 'yes'. Updates can apply to operating systems on laptops/PCs, software updates or mobile app updates.
  • Do you postpone software or system updates?*
  • Do you use a dedicated security monitoring software?

    This refers to software like Norton 360, Avast or McAfee that can automatically scan devices for malicious activity or software.
  • Do you use a dedicated security monitoring software?*
  • Do you use best practices for good password security?

    This refers to best practices like: using complex passwords (combination of uppercase, lowercase, numbers, special characters) or multi-phrase passwords. Answer 'no' if you use personal information (birth dates, names, place names etc.), use the same password across multiple accounts or store them somewhere easily accessible (in a notes app or writing in a notepad).
  • Do you use best practices for good password security?*
  • Is two-factor authentication (2FA) enabled on all or most of your accounts?

    This includes authenticator apps, number pins, passkeys, email 2FA or biometrics (fingerprints or face recognition) on portable devices.
  • Is two-factor authentication (2FA) enabled on all or most of your accounts?*
  • Do you have a clear understanding of what risks your business might face?

    This includes risks relating to suppliers, clients & agencies, physical devices, networks (e.g. Wi-Fi, cloud services) and the digital service providers you use (e.g. WordPress, Spotify, Canva, Adobe, Facebook, TikTok etc.).
  • Do you have a clear understanding of what risks your business might face?*
  • Do you know what to do in the event of a cyber incident?

    This can include knowing who to report different types of attacks to, how to manage the incident and who you can get advice from.
  • Do you know what to do in the event of a cyber incident?*
  • Do you have insurance that covers cyber incidents?

    This can be cover that's included under a general business insurance policy or a dedicated 'cyber liability' policy. Refers to cover such as business interruption, reputation management and data recovery.
  • Do you have insurance that covers cyber incidents?*
  • Do you know how to properly identify a scam email?

    This refers to phishing emails where scammers may pretend to be a trustworthy sender and knowing what they are and how to spot them.
  • Do you know how to properly identify a scam email?*
  • Would you say you know what common cyber incidents are, like DDoS, phishing, ransomware or malware?

    This refers to having knowledge of what each type of attack involves and how to identify them.
  • Would you say you know what common cyber incidents are, like DDoS, phishing, ransomware or malware?*
  • Do you take steps to keep portable devices safe?

    This can include using screen locks (pins, passwords & biometrics), using a VPN and keeping software up-to-date.
  • Do you take steps to keep portable devices safe?*
  • You have completed cyber security awareness

    Please provide us with your email address so that we can share your result report with you. Your email will not be stored or used in any other capacity.
  • Fair Processing Notice.

  • Your result

    Based on the answers you’ve provided, we’ve identified the following actions that we strongly recommend to protect your business online. Click on the button below to have your score emailed to you. We'll also send a list of useful tips to keep on top of your cyber security.
  • Further reading

    Based on your score, we've put together some tips to help you with your cyber security awareness:
  • Backing up data

    • Identify what needs backing up.

    • Choose a suitable way to store backups (physcial storage or cloud storage).

    • Make it routine - either set reminders for manual backups or use 'automatic backup' features in the software you use.
  • Protecting from malware

    • Keep equipment and software updated - remember your portable devices (phones and tablets).

    • Enable automatic updates if available - you can sometimes set these to only install outside of working hours so they're not disruptive.

  • Security monitoring

    • Install and/or turn on antivirus software.

    • Use a firewall (most computer operating systems include a built-in firewall, simply switch it on).

  • Using passwords to protect data

    • Avoid predictable passwords (personal information, common words or phrases). Consider the "three random word" method to create a pass phrase.

    • Don't use the same password across multiple accounts.

    • Consider using a password manager to help you cope with multiple complex passwords.
  • Avoiding phishing attacks

    • Enable two-factor authentication (2FA) on accounts where available (this will make access harder even if someone gets your login details).

    • Try to use multi-device authentication e.g. use your phone (authenticator app or SMS) to authenticate logins on your desktop. Try not to rely on email authentication.

  • Understanding risks - risk assessments

    • Conduct a risk assesment for your business - think about the systems you use, how you work, who you work with and the associated risks.

    • Consider what third-party systems and software you use. Research the digital service providers who run them and what security they integrate into the services you use.

    • Have a plan in place to manage risks - you could implement technical security controls, deprioritise a risk or share the liability with an insurance provider.

    • Use the National Cyber Security Centre (NCSC) tool to check your cyber security.

  • What to do in the event of a cyber attack

    • Have a ready-to-go action plan, so you can get straight to defending your business in the event of a cyber attack.

    • Know who to report which incidents to - like Action Fraud, National Cyber Security Centre (NCSC) or the police. We've put together a helpful guide on how to report cyber crime.

    • Have insurance in place for financial support and expert guidance.
  • Cyber insurance

    • Check any existing business insurance you have - does it include cyber risks like data breaches, reputational damage or costs related to data recovery?

    • Consider dedicated cyber liability insurance - this will likely offer more comprehensive cover in the event of a cyber incident.

    • Research insurance providers and consider one that also includes extra support like a cyber helpline so you can get reliable guidance when you need it.
  • Avoiding phishing attacks

    • Educate yourself on how to identify a phishing email, message or call.

    • Report anything suspicious. This will help authorities track down the senders and stop more attacks.

    • Monitor systems and accounts for suspicious activity so you're aware if a phishing attack has been successful.
  • Understanding risks - educating on types of attacks

    • Research the tyes of cyber attacks and understand what they are and the vulnerabilities they exploit.

    • Make use of free online courses to learn about cyber security - like the National Cyber Security Centre (NCSC) Cyber Security Tips training.

    • Consider a full certification course like Cyber Essentials - the certification also shows clients you take cyber security seriously.
  • Keeping portable devices safe

    • Don’t connect to unknown Wi-Fi networks or hotspots.

    • Use device security like pins, passwords or biometrics (fingerprint or facial recognition). Also look up other security features your devices might have.

    • Keep apps up-to-date, install device updates when available.
  • Wow, you're a cyber superstar!

    Well done! Looks like you're on top of your cyber security.

    However, with technology the world is evolving quickly so here are some resources to bookmark to make sure you stay up-to-date:

    • Use the National Cyber Security Centre (NCSC) tool to check your cyber security.

    • Helpful guides on how to report cyber crime and what to do if you're a cyber attack victim in case the worse happens.

    • Brush up on how to identify a phishing email, message or call.

    • Make use of free online courses to learn about cyber security - like the National Cyber Security Centre (NCSC) Cyber Security Tips training.

    • Consider a full certification course like Cyber Essentials - the certification also shows clients you take cyber security seriously.

    • Brush up on Cyber security best practices for small businesses
  • Should be Empty: