Cyber Security Basics · Lesson 10 of 10
Quick answer: A practical four-week improvement plan that turns the mini-course into measurable cyber security actions for a small business.
Cyber security improves when actions have owners and deadlines. The final lesson in this mini-course turns the basics into a simple 30-day plan that a small business can work through without trying to change everything at once.
Week 1: Protect important accounts
- List Microsoft 365, email, banking, payroll, accounting, CRM, website, domain and backup administration accounts.
- Enable MFA or stronger sign-in methods.
- Remove dormant and unnecessary accounts.
- Separate administrator access from normal day-to-day use.
- Introduce an approved password manager where needed.
Week 2: Review devices and updates
- Create a basic device inventory.
- Confirm operating systems and important applications are supported.
- Enable and monitor security updates.
- Check antivirus or endpoint protection and firewalls.
- Identify unmanaged laptops, personal devices and forgotten network equipment.
Week 3: Verify backups and recovery
- List the systems and data being backed up.
- Confirm backup administration is protected with strong authentication.
- Check that a recovery copy is protected from normal device compromise.
- Perform a test restore.
- Record recovery time for a critical system.
Week 4: Train people and prepare for incidents
- Run a short phishing and payment-fraud awareness session.
- Define how suspicious messages are reported.
- Create a rule for independently verifying bank-detail changes.
- Write an incident contact sheet.
- Run a simple tabletop exercise: “What would we do if the managing director’s mailbox was compromised?”
Use Cyber Essentials as a baseline
Compare your progress with the five Cyber Essentials technical controls: firewalls, secure configuration, security update management, user access control and malware protection. This provides a useful structure for deciding what still needs improvement.
Measure progress
At the end of 30 days, record which actions are complete, which are in progress and who owns the remaining work. Cyber security is continuous, so repeat reviews when staff, devices, suppliers or systems change.
Continue beyond the basics
Once these foundations are in place, the next areas may include managed email security, MDR/EDR, vulnerability management, Microsoft 365 backup, firewall management, security awareness programmes, Cyber Essentials readiness and formal incident response planning.
Your next step
Use the free 39Security cyber security assessment to benchmark the current position, or attend a practical training day to work through phishing, Microsoft 365, devices, backup, ransomware and a 30/60/90-day improvement plan.
Frequently asked questions
Can a small business improve cyber security in 30 days?
Yes. A month is enough to make meaningful improvements to MFA, updates, backups, access control, staff awareness and incident planning.
What should be prioritised first?
Start with high-impact accounts, unsupported or unpatched devices, recoverability of critical data and processes involving money.
What should we do after the 30-day plan?
Turn the remaining actions into an ongoing security programme with owners, review dates, monitoring and regular testing.
Useful UK guidance
Put the lesson into practice
39Security helps small businesses turn cyber security guidance into practical controls and owned actions.
- Take the free cyber security assessment
- View practical cyber security training dates
- Explore Cyber Essentials readiness support
- See managed cyber security services
- Read the small business cyber security FAQ