Blog/Security basics

The First 30 Days of a Small Business Security Programme

A realistic week-by-week plan to get a small business from 'we should do something' to solid basics in a month: accounts, payments, devices, backups and people.

CyberWatch AI4 October 2026 · 2 min read
A calendar marked with red pins

Security programmes stall when they try to do everything at once. This plan spreads the essentials over four weeks, so a small business can make real progress without stopping work.

Week 1: accounts

  • List all business accounts: email, banking, website, social media, key software.
  • Turn on two-step verification everywhere. See enforcing two-step verification.
  • Reduce admin access to the people who need it. See admin accounts.

Week 2: money

Week 3: devices and data

  • Automatic updates and screen locks on every device. See device updates.
  • Set up backups and test one restore. See backup strategy.

Week 4: people and plans

  • Share a one-page policy. See one-page policy.
  • Name a reporting contact and run a 15-minute briefing.
  • Write a one-page incident plan. See incident response plan.

Track progress with a few simple measures. See measuring progress.

For more, see our complete guide to small business cybersecurity.

Frequently asked questions

How much time does this take each week?

A few hours for the person leading it, plus short actions from each staff member.

Do we need an IT provider for this?

Not necessarily. Many steps are settings you can change yourself. A provider can help with devices and backups.

What comes after 30 days?

Regular habits: monthly checks, quarterly access reviews and backup tests, and short training.

Sources

  1. Small organisations guide to cyber security, UK National Cyber Security Centre
  2. Cyber Essentials, US Cybersecurity and Infrastructure Security Agency
  3. 10 Steps to Cyber Security, UK National Cyber Security Centre
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.