The First 30 Days of a Small Business Security Programme
A realistic week-by-week plan to get a small business from 'we should do something' to solid basics in a month: accounts, payments, devices, backups and people.

Security programmes stall when they try to do everything at once. This plan spreads the essentials over four weeks, so a small business can make real progress without stopping work.
Week 1: accounts
- List all business accounts: email, banking, website, social media, key software.
- Turn on two-step verification everywhere. See enforcing two-step verification.
- Reduce admin access to the people who need it. See admin accounts.
Week 2: money
- Write and share a payment verification rule. See payment verification.
- Set up dual approval in your banking. See dual approval.
- Turn on bank alerts. See alerts and limits.
Week 3: devices and data
- Automatic updates and screen locks on every device. See device updates.
- Set up backups and test one restore. See backup strategy.
Week 4: people and plans
- Share a one-page policy. See one-page policy.
- Name a reporting contact and run a 15-minute briefing.
- Write a one-page incident plan. See incident response plan.
Track progress with a few simple measures. See measuring progress.
For more, see our complete guide to small business cybersecurity.
Frequently asked questions
How much time does this take each week?
A few hours for the person leading it, plus short actions from each staff member.
Do we need an IT provider for this?
Not necessarily. Many steps are settings you can change yourself. A provider can help with devices and backups.
What comes after 30 days?
Regular habits: monthly checks, quarterly access reviews and backup tests, and short training.
Sources
- Small organisations guide to cyber security, UK National Cyber Security Centre
- Cyber Essentials, US Cybersecurity and Infrastructure Security Agency
- 10 Steps to Cyber Security, UK National Cyber Security Centre


