NCSC: Small & Medium Organisations hub ↗
Plain-English advice from the UK's National Cyber Security Centre.
https://www.ncsc.gov.uk/section/information-for/small-medium-sized-organisations
Resources
A curated list of UK SME cyber and IT guidance. All free. No affiliate links.
NCSC: Small & Medium Organisations hub ↗
Plain-English advice from the UK's National Cyber Security Centre.
https://www.ncsc.gov.uk/section/information-for/small-medium-sized-organisations
NCSC: Cyber Essentials overview ↗
The UK government's baseline cyber standard.
https://www.ncsc.gov.uk/cyberessentials/overview
NCSC: Cyber Aware ↗
Six basic actions for individuals and small businesses.
https://www.ncsc.gov.uk/cyberaware
NCSC: 10 Steps to Cyber Security ↗
The full framework. Useful for mature SMEs.
https://www.ncsc.gov.uk/collection/10-steps
NCSC: report a phishing email ↗
Forward to report@phishing.gov.uk.
https://www.ncsc.gov.uk/collection/phishing-scams/report-scam-email
NCSC: Exercise in a Box ↗
Free table-top exercises.
https://www.ncsc.gov.uk/information/exercise-in-a-box
NCSC: Logging Made Easy ↗
Free, open-source logging stack.
https://www.ncsc.gov.uk/information/logging-made-easy
NCSC: Mobile device guidance ↗
Advice on phones and tablets at work.
https://www.ncsc.gov.uk/collection/mobile-device-guidance
ICO: Guide to Data Protection ↗
The UK regulator's plain-English GDPR guide.
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/
ICO: report a personal data breach ↗
Where to notify the regulator (72-hour clock).
https://ico.org.uk/for-organisations/report-a-breach/
ICO: SME web hub ↗
Plain-English data protection for small businesses.
https://ico.org.uk/for-organisations/sme-web-hub/
Action Fraud ↗
Where to report cyber crime in the UK. 0300 123 2040.
https://www.actionfraud.police.uk/
IASME Cyber Essentials self-assessment ↗
Read the questionnaire free.
https://iasme.co.uk/cyber-essentials/
NCSC: Cyber Action Plan ↗
Free online tool producing a personalised plan.
https://www.ncsc.gov.uk/cyberaware/actionplan
Microsoft Secure Score ↗
Benchmarks your M365 tenant against best practice.
https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-secure-score
ICO self-assessment toolkit ↗
Questionnaires that highlight data-protection gaps.
https://ico.org.uk/for-organisations/sme-web-hub/checklists/
Have I Been Pwned ↗
Type an email. See if it's in a known breach.
https://haveibeenpwned.com
Security Headers ↗
Free website security header check.
https://securityheaders.com
SSL Labs SSL Test ↗
Tests your website's TLS configuration.
https://www.ssllabs.com/ssltest/
UptimeRobot ↗
Free uptime monitoring.
https://uptimerobot.com
MXToolbox SPF / DKIM / DMARC checker ↗
Tests your domain's email authentication.
https://mxtoolbox.com/dmarc.aspx
NCSC Mail Check ↗
Free email security check.
https://www.mailcheck.service.ncsc.gov.uk
OWASP ZAP ↗
Free automated security scanner for websites.
https://www.zaproxy.org/
IASME ↗
Certification body for Cyber Essentials.
https://iasme.co.uk
BSI: ISO 27001 ↗
Heavier-weight information-security management standard.
https://www.bsigroup.com/en-GB/iso-27001-information-security/
CIS Controls v8 ↗
Free, prioritised list of cyber controls.
https://www.cisecurity.org/controls
OWASP: Top 10 ↗
The original web-application security risk list.
https://owasp.org/Top10/
OWASP: ASVS ↗
What to ask developers and pen-testers to check.
https://owasp.org/www-project-application-security-verification-standard/
NCSC weekly threat report ↗
Short, readable cyber digest.
https://www.ncsc.gov.uk/section/keep-up-to-date/threat-reports
Krebs on Security ↗
Independent cyber journalism.
https://krebsonsecurity.com
ICO e-newsletter ↗
Regulatory updates in plain English.
https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/