GLOBAL BRIDGE LABS
← All posts/BPO & Operations

Cyber security without an IT department

Cyber security without an IT department: the five controls every small UK business can manage, what they cost in time, and when to bring in help.

By Dhanushka Pinto, Co-founder / DirectorPublished 7 min read
Cyber security without an it department: key takeaways infographic by Global Bridge Labs
Key takeaways from this article. Share it with the link and credit Global Bridge Labs.
On this page

Key takeaways

Cyber security without an IT department is manageable if someone owns it. The DSIT Cyber Security Breaches Survey 2025/2026 found 43% of UK businesses reported a breach or attack in the previous year. Five basic controls, set out by the National Cyber Security Centre, stop most common attacks, and none needs a specialist.

  • 43% of UK businesses reported a cyber breach or attack in the last year.
  • 5 controls: firewalls, secure settings, updates, access control, malware protection.
  • Phishing is the most common type of attack.
  • Name 1 owner and give them an hour a month.

Nobody owning security in your business? Message us on WhatsApp.

Chat on WhatsApp →

Who looks after security when there is no IT team?

When there is no IT team, security falls to whoever is most technical, on top of their real job, or to nobody. The business is still responsible. The first step is not a tool but a named owner with a short list and a regular slot to work through it.

What are the five basic controls?

The government-backed Cyber Essentials scheme sets out five technical controls that protect against the most common internet attacks.

  • Firewalls: protect your internet connection.
  • Secure configuration: remove default passwords and unused accounts.
  • Security updates: keep devices and software patched.
  • User access control: give people only the access they need.
  • Malware protection: use built-in or reputable antivirus tools.

What does a breach cost a small business?

A breach costs time first: days spent restoring systems, resetting accounts and reassuring customers. It can also cost lost work, regulatory reporting and, for payment fraud, the money itself. For a business doing everything in-house, the same few people who would fix the breach are the ones needed to keep trading.

What can you do in an hour a month?

An hour a month, spent consistently, covers the essentials.

  • Check updates are installing on every device.
  • Confirm backups ran and test restoring one file.
  • Review who has admin access.
  • Remove accounts for leavers.
  • Remind staff how to report a suspicious email.

When do you need outside help?

Bring in help to set things up properly, to achieve Cyber Essentials certification if customers require it, after any incident, and when you hold sensitive data. Ongoing basics can stay in-house with a named owner. Anyone handling your data on your behalf should meet the same standards.

What do attacks on small businesses look like?

Most attacks on small businesses are ordinary and automated.

  • Phishing emails that capture a login.
  • Fake invoices or requests to change bank details.
  • Reused passwords tried against email and cloud accounts.
  • Malware arriving through an attachment or download.
  • Outdated website software exploited by a scanner.

What does the basic setup cost?

The basics cost little. Automatic updates and built-in malware protection are free. Two-step verification is free on most services. A password manager and cloud backup together cost a few pounds per user per month. The real cost is attention: an hour a month from a named person. Cyber Essentials certification, if a customer requires it, has a modest assessment fee that depends on the size of the organisation.

What should staff know?

Staff need to know three things: how to recognise a suspicious message, who to tell, and that they will not be blamed for reporting a mistake quickly. Most successful attacks depend on someone clicking and then staying quiet. A ten-minute briefing twice a year, with real examples, does more than a long policy nobody reads.

What should you do in the first hour of an incident?

Change the affected passwords, sign out other sessions, and disconnect any infected device from the network. Tell your bank immediately if money or payment details are involved. Write down what happened and when. The National Cyber Security Centre's guidance on response and recovery sets out the steps for small organisations, and it is worth reading before you need it.

What does this look like in practice?

A pattern we see in small firms: laptops postpone updates for months because restarts are inconvenient, backups go to a drive in the same office, and the only administrator is the owner. Each is a ten-minute fix that nobody was asked to do.

Cyber security checklist

Start here.

  • Name a security owner.
  • Turn on automatic updates everywhere.
  • Enable two-step verification on email.
  • Set up backups stored separately.
  • Limit admin rights.
  • Brief staff on phishing.
  • Read the NCSC Small Business Guide.

Next step

If security is one of the reasons you keep work in-house, tell us your concerns. We will walk you through how access, devices and data are controlled in a managed team, in a 30-minute call.

Message us on WhatsApp with your security questions, or book a 30-minute consultation.

Chat on WhatsApp →

Sources and further reading

Frequently asked questions

Do small businesses really get hacked?

Yes. The DSIT Cyber Security Breaches Survey 2025/2026 found 43% of UK businesses reported a breach or attack in the previous year. Most attacks are automated and untargeted, so being small is no protection. Phishing is the most common type. Assume you are a target and cover the basics.

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme covering five basic technical controls. It is designed to be achievable for small organisations and is required for some government contracts. Many businesses use it as a practical checklist even without certifying. The NCSC website explains how to apply and what assessment involves.

Who should be responsible for cyber security in a small business?

A named person, usually the owner, operations lead or most technical member of staff, with a clear list of monthly checks. They do not need to be an expert, but they do need time and the authority to insist on basics such as updates. Write their name on the checklist.

Is outsourcing work a security risk?

It changes the risk. A provider with role-based access, managed devices, logging and a written data processing agreement can be more controlled than an informal in-house setup. Ask for evidence of their controls before sharing access. Ask before you sign.

Written by

Dhanushka Pinto
Dhanushka Pinto
Co-founder / Director

Global Bridge Labs (GBL) is a UK–Sri Lanka partner for social media, websites and BPO. Everything here comes from client delivery, not theory.

Share this article

Reading is good.
Fixing is better.

30 minutes with our team and you'll leave knowing which of the three problems to fix first.

Book a 30-Minute Consultation →
Keep reading