First Published: 12/10/2022, updated 09/10/2025
Cyber Security is not just about implementing technical measures and controls to secure your data, a business should instil a culture of security awareness in all its staff. Data security should be seen as everyone’s responsibility.
Policies & Procedures
All businesses should have clear policies and procedures in place to address areas such data classification and handling, password and access control and Acceptable Use. This ensures your staff understand how data should be stored, accessed and shared and what they can do to reduce the risk of a security breach.
Security Awareness
According to the Governments 2025 Cyber Security Breaches Survey 43% of UK businesses and 30% of charities had identified a cyber-attack. Of the 43% of UK businesses who identified an attack, the most common threat vector was phishing attempts (85% of businesses and 86% of charities).
Phishing is where a fake email is sent out to look like it comes from a reputable source such as Microsoft, Google, your bank etc asking you to access a link to update information, change your password so that the cyber criminals capture your login details.
Unfortunately, these emails can look quite convincing, but there are some quick checks you can do to verify the email:
- Ignore the display name and double check the sending email address; often the domain being used is a different spelling variation that at first glance is not always noticed.
- Check spelling and grammar; these are often poor in phishing emails.
- Hover over hyperlinks to see the real URL the link will take you to, the display text of the link may look genuine, but the actual hyperlink could be completely different.
- Lastly, don’t click the link. If the email is notifying you of an issue with an account, asking you to change your password etc; login in directly to that account online as you normally would to check for any issues.
If you do receive a phishing email that you are suspicious of, make sure you report it and warn your colleagues of the risk. Don’t forward the email, take a screenshot and send that, then delete the email.
Engage IT partner with Kaseya to provide ongoing Security Awareness Training and Simulated Phishing for you and your staff, as part of our User Protect security package. This provides regular monthly online training and phishing simulations to check your staff’s security awareness and provide tailored training. Find out More
Physical Security
Physical security measures are just as important as technical measures. Having a secure complex password is great, but leaving it written down on a sticky note stuck to your monitor or in an easily accessible notebook is not so secure. Get in the habit of putting your screensaver/screen lock on when you leave your desk. Any hard copies of confidential/personal documents should be stored in lockable filing cabinets and those working with sensitive data should operate a clear desk policy.

