Blog · 3 August 2026

Free NCSC Cyber Consultations: What UK Small Businesses Should Do Before They Book

Free NCSC Cyber Consultations: What UK Small Businesses Should Do Before They Book

The National Cyber Security Centre has started pushing a very practical message for UK small businesses: cyber security does not have to begin with a huge project, a complex audit or a frightening bill.

On 15 July 2026, the NCSC highlighted that Cyber Advisors are now offering free 30-minute consultations to help small and medium-sized organisations get started with Cyber Essentials. The timing matters. The same NCSC guidance points out that in 2025, 46% of small organisations and 65% of medium organisations reported a cyber breach or attack.

For many business owners, the hardest part is not understanding that cyber security is important. It is knowing where to start without getting lost in jargon. A short consultation can help, but it works best when you bring the right questions and a clear picture of how your business uses technology.

Why this is useful for small businesses

Most small businesses do not have a dedicated security team. The same person may be dealing with clients, payroll, suppliers, laptops, Microsoft 365, card payments and the website. That makes cyber security feel like another job on an already full list.

The NCSC Cyber Advisor route is useful because it focuses on the Cyber Essentials controls. These are the practical foundations that reduce exposure to common internet-based attacks: secure configuration, access control, malware protection, security updates and firewalls.

That is a sensible place to begin. Most real-world incidents still involve familiar weaknesses: weak passwords, missing multi-factor authentication, unpatched devices, unmanaged admin accounts, exposed remote access or staff being tricked by phishing emails.

What to check before you book a consultation

A free 30-minute call will go quickly. You will get far more value if you spend a little time gathering the basics first.

  • List the systems you rely on every day, such as Microsoft 365, Google Workspace, Xero, Sage, CRM systems, line-of-business apps and website admin areas
  • Count the devices used for work, including laptops, desktops, mobiles, tablets and any personal devices that access business data
  • Check who has admin access to your email, website, cloud apps, router, firewall and backup systems
  • Confirm whether multi-factor authentication is enabled for all users, especially administrators
  • Find out how updates are managed on Windows, macOS, mobiles, browsers, plugins and firewall or VPN equipment
  • Check what is backed up, where it is backed up to, and when you last tested a restore
  • Note any cyber worries you already have, such as phishing emails, old accounts, remote workers, supplier access or staff using the same password in several places

You do not need perfect answers. A rough list is enough to make the conversation more useful and stop the advice becoming too generic.

The five areas that usually matter first

If your business has not reviewed cyber security for a while, start with the same areas that Cyber Essentials is built around.

1. User accounts and MFA

Every user should have their own account, leavers should be removed promptly, and admin rights should be limited. Multi-factor authentication should be switched on for email, cloud apps, finance systems and admin accounts. If MFA is optional in a system that holds business data, treat that as a risk.

2. Updates and patching

Attackers move quickly when vulnerabilities are public. Laptops, servers, firewalls, VPNs, WordPress plugins, browsers and mobile devices all need a predictable update process. The goal is not “update when someone remembers”; it is knowing who is responsible and how quickly important patches are applied.

3. Device protection

Business devices need managed antivirus or endpoint protection, disk encryption, screen locks and a way to remove access if a laptop or phone is lost. If staff use personal devices for work, you still need rules around email access, data storage and what happens when they leave.

4. Backups and recovery

Backups are not just for server failures. They are your route out of ransomware, accidental deletion and account compromise. Make sure your important files, emails and business systems are covered, then test that you can restore them. A backup that has never been tested is only a hope.

5. Email and phishing resilience

Phishing remains one of the most common types of cyber attack reported by UK businesses. Awareness training helps, but it should sit alongside technical controls: MFA, secure mail filtering, domain protection, monitoring for suspicious sign-ins, and clear reporting routes for staff.

Cyber Essentials is not just a badge

The government Cyber Security Breaches Survey 2025/2026 found that Cyber Essentials adoption has increased among UK businesses, including a rise among small businesses from 5% to 12% compared with the previous year. That is good progress, but it still means most small businesses do not yet hold the certification.

For many organisations, Cyber Essentials is becoming a useful way to prove basic resilience to customers, insurers and supply-chain partners. More importantly, the process forces a business to look at the controls that make common attacks less likely to succeed.

If you are a charity, school supplier, care provider, legal firm, contractor, manufacturer, ecommerce business or professional services firm, this is worth taking seriously. Your customers increasingly expect you to protect their data and keep operating when something goes wrong.

A practical next step

If the free NCSC Cyber Advisor consultation is relevant to you, use it. Go in with your systems list, your user list and your biggest concerns. Ask what would make the biggest difference in the next 30 days.

Then turn the advice into a short action plan. For many businesses, that first plan will include MFA cleanup, admin account review, patching, backup testing and email security improvements. None of those are glamorous, but they are exactly the controls that reduce everyday risk.

BM Technologies helps UK businesses put these foundations in place properly, from Microsoft 365 security and backup through to patching, monitoring, endpoint protection, Cyber Essentials preparation and staff guidance.

If you want a quick starting point before booking advice or beginning certification, run a simple cyber risk check and use the results to focus the conversation.

Sources

← Back to all articles

Want to talk through anything in this article? Contact us and we’ll help.