8 Practical Steps for UK Businesses – Daily Business

workers on laptops workers on laptops
Photo by Annie Spratt on Unsplash

Hybrid work no longer feels particularly new. For many businesses, it is simply how the working week now happens.

Someone may spend Monday at the office, work from home on Tuesday and meet a client somewhere else on Wednesday. Another employee might open company files from a train or check email while waiting at an airport.

That flexibility has obvious benefits. It has also changed what businesses need to protect.

When most work happened inside one office, security could be built around that location. Today, company data moves between laptops, home networks, cloud platforms and mobile devices every day.

For smaller businesses in particular, this can sound like a much bigger IT problem than it needs to be.

The basics still matter most: knowing who can access what, keeping devices updated, protecting accounts properly and making sure staff know what to do when something looks wrong.

Here are eight areas worth looking at.

1. Know who has access to what

Access tends to grow over time.

An employee joins and is given several accounts. Six months later, their role changes, but the old permissions remain. A contractor needs temporary access to a shared folder and nobody remembers to remove it once the project ends.

Individually, these things can seem harmless.

The problem is that they accumulate.

A useful starting point is simply to look at the systems the business relies on and ask who genuinely needs access to each one.

The finance system probably does not need to be open to the whole company. A freelance designer may need access to a brand folder without needing access to customer records. A former employee should not still be able to sign in because nobody got around to closing the account.

This becomes more important with hybrid teams because you can no longer use physical presence in the office as a rough indication of who belongs where.

Access has to follow the person and their role instead.

That may sound obvious, but regular permission reviews are one of those small jobs that are easy to postpone until there is a problem.

2. Stop treating passwords as an individual responsibility

Businesses often tell employees to use strong passwords and leave the rest to them.

That works until people have twenty different accounts to remember.

Then passwords get reused. A variation of the same password appears across several services. Someone stores login details in a document because it is easier than remembering them.

Daily Business has already looked at the shift towards stronger password management as companies deal with the risk of stolen and reused credentials.

A password manager can take much of that burden away. It gives staff somewhere to store unique credentials without expecting them to remember every one.

Individual accounts matter as well.

Shared logins may seem convenient in a small team, but they make it harder to know who did what and harder to remove access when someone leaves.

Passwords should also have some backup.

The UK’s National Cyber Security Centre recommends multi-factor authentication for corporate online services, especially where sensitive information is involved.

That extra step can feel slightly inconvenient when somebody signs in.

It feels considerably less inconvenient than dealing with a compromised account.

3. Think about the connection, not only the laptop

A company laptop can be properly configured and still connect through networks the business does not control.

That is now normal.

People work from home broadband, shared offices, hotels and other places that sit well outside the traditional office network.

Remote access therefore needs its own plan.

The NCSC describes Virtual Private Networks as a way for organisations to provide secure connectivity between devices in physically separate locations.

For teams regularly accessing business resources away from the office, a managed business vpn can provide an encrypted connection and become one part of that wider remote-access setup.

The important phrase there is one part.

A VPN is not a substitute for good passwords, multi-factor authentication, sensible permissions or secure devices.

Nor does every business have exactly the same remote-access requirements.

A five-person consultancy using cloud software all day will have different needs from a business running its own internal systems.

The NCSC’s guidance on network architectures also makes clear that VPN-based access and newer zero-trust approaches are not necessarily an either-or choice. They can sit alongside each other depending on how the organisation works.

So the more useful question is not simply whether the company “has a VPN”.

It is whether staff have a sensible and secure way to reach the systems they need when they are not in the office.

4. Decide what happens with personal devices

Bring-your-own-device policies do not always begin as policies.

Someone checks work email on their own phone.

Another employee opens a company document on a home laptop because they left the work machine at the office.

A director replies to messages from a personal tablet while travelling.

Little by little, personal devices become part of the company’s technology setup.

There is nothing automatically wrong with that.

The trouble starts when nobody has decided what the rules are.

If staff are allowed to use their own devices for work, the business should be clear about what that means.

Does the device need a screen lock?

Can company files be downloaded and stored locally?

What happens if the phone is lost?

Can business access be removed when an employee leaves without affecting their personal information?

The NCSC’s bring-your-own-device guidance recommends that organisations make these decisions deliberately rather than letting personal-device use develop without controls.

The answer does not have to be “no personal devices”.

It should at least be a conscious answer.

5. Keep updates dull and routine

Software updates are rarely anyone’s favourite job.

They interrupt work. They appear at inconvenient times. There is always a temptation to click “later”.

The result can be a business with one fully updated laptop, another several versions behind and an old piece of software that nobody wants to touch because nobody is quite sure what will happen if it changes.

That is not a great position to be in.

Updates often contain security fixes, not just new features.

The NCSC advises organisations to patch known vulnerabilities, particularly on systems exposed to the internet.

Where updates can happen automatically, let them.

Where they cannot, somebody should know they are responsible for checking them.

This is one area where boring is good.

A quiet update that installs overnight is far preferable to discovering months later that a system was left exposed because everyone assumed somebody else was looking after it.

6. Make suspicious emails easier to question

Most employees have heard the advice about not clicking strange links.

Phishing still works.

That is partly because the better attempts do not always look obviously strange.

A message may appear to come from a real supplier. It might use the name of a senior colleague. It may refer to an invoice, a delivery or a project that sounds entirely plausible.

The UK Government’s Cyber Security Breaches Survey 2025/26 found that phishing remained the most common type of cyber breach or attack identified by businesses, affecting 38% of businesses surveyed.

That is why staff training works better when it goes beyond telling people to “be careful”.

Show employees what suspicious requests can look like.

Make sure they know how changes to bank details are normally confirmed.

If an unexpected payment request appears to come from a director, give the employee permission to pick up the phone and check.

Most importantly, make reporting easy.

Someone who has clicked something suspicious should feel able to say so immediately rather than spending an hour hoping nothing happens.

The NCSC’s phishing guidance takes a layered approach for the same reason. Technical controls help, but businesses cannot reasonably expect one tool or one person to catch every attempt.

A workplace where people are comfortable asking, “Does this look right?” is generally safer than one where everybody is afraid of looking foolish.

7. Look for unusual access without watching every move

Hybrid work creates an odd management problem.

People are less visible physically, while their digital access matters more than ever.

Daily Business has previously examined how hybrid working changed everyday management processes, including something as routine as keeping track of staff availability when being in the office is no longer the default.

Security has a similar challenge.

A business does not need to watch every click an employee makes.

It does need enough visibility to notice when something clearly does not fit.

That could be repeated failed login attempts. It might be an account being accessed from an unexpected location. It could simply be someone who left the business last week still appearing as an active user.

This is where clear boundaries matter.

Security monitoring should be about protecting systems and spotting unusual access.

It should not quietly turn into unnecessary employee surveillance.

Staff are far more likely to accept security measures when they understand what is being monitored and why.

8. Work out what happens when prevention fails

Businesses naturally spend most of their security effort trying to stop something going wrong.

It is just as useful to think about what happens when something does.

Suppose an employee loses a laptop.

Who do they call?

If somebody enters their password into a phishing page, who can disable the account?

What happens if a supplier tells you that their systems have been breached and your company’s information may be involved?

These are fairly simple questions.

They become much harder at 9:15 on a Monday morning when everyone is trying to solve them at once.

The Cyber Security Breaches Survey 2025/26 found that only 25% of businesses had a formal incident-response plan, although larger organisations were more likely to have one.

A small company does not need a thick manual sitting untouched in a drawer.

A useful plan might only cover a few things:

who needs to know first, who can shut down access, where important contact details are kept and when outside help may be needed.

It is worth talking through the plan occasionally too.

Ask the team what they would do if company email suddenly stopped working tomorrow morning.

The answers tend to reveal gaps quite quickly.

Hybrid security should support the way people actually work

Good security should not make staff feel as though working from home is somehow risky by default.

Nor should every trip outside the office involve another complicated login process.

The aim is simply to make sure the security setup has kept pace with the way the business now operates.

That usually means several fairly ordinary measures working together.

People have access to the systems they actually need. Accounts use stronger authentication. Devices stay updated. Remote connections are protected. Staff know when to question something unusual, and the business knows what it will do if an incident still happens.

None of these steps solves everything.

They are not supposed to.

Cybersecurity is rarely one product, one policy or one piece of software. It is a collection of decisions that make it harder for a small mistake to become a much larger problem.

Hybrid work moved the workplace beyond the office.

The security around it needs to move with it.

#Practical #Steps #Businesses #Daily #Business

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注