If you run a small business, there's a good chance "cyber security" sits somewhere on your own to-do list, or on the list of whoever is best with computers. You're not alone. A new government survey has found that more than half of UK businesses aren't confident doing at least one of the basic tasks that keep them safe. That isn't a reason to panic. It's a reason to get the basics covered, with help where you need it.
The numbers
On 29 September 2026 the Department for Science, Innovation and Technology published Cyber Security Skills in the UK Labour Market 2026. Its headline finding for ordinary businesses: 57% had a basic technical skills gap, up from 49% last year.
As The Register reported, that equates to roughly 808,000 businesses whose cyber security lead wasn't confident carrying out at least one of nine tasks. The estimate a year earlier was 699,000.
The tasks are not exotic. They include storing and transferring personal data securely, configuring firewalls, restricting which software can run, choosing secure device settings, turning on automatic updates, creating user accounts securely, and detecting and removing malware. That last one was the biggest gap, with 38% of businesses and 47% of charities not confident they could do it.
The report also found that 47% of the people responsible for cyber security in UK businesses lacked the confidence to deal with a breach or attack, and hadn't outsourced that job to anyone else.
Why this keeps happening
In most small firms, nobody's job title says "security". Sam Thornton of the consultancy Bridewell told The Register that cyber security is often "just one part of someone's wider role rather than a dedicated job." The office manager sets up the Wi-Fi. The owner creates the new starter's email account. Updates get clicked "later".
The government says its definition of basic skills is drawn largely from the technical areas in Cyber Essentials, the UK's entry-level certification. In other words, these are exactly the controls that stop the most common attacks.
What a missed basic looks like
A fresh example shows how small gaps get used. On 22 September, Proofpoint described a campaign that tried passwords against 5,714 Microsoft 365 accounts at 28 organisations, mostly in Latin America. Seven accounts were broken into, six of them within seven minutes. Every one was a functional or service account, the kind set up for payments or a till system and then forgotten. None had multi-factor authentication, and the attackers got in with default passwords that had never been changed.
That's "creating user accounts securely", one of the nine tasks, playing out in real life. The campaign wasn't aimed at the UK, but the lesson travels.
What this means for UK small businesses
You don't need a security team to close most of these gaps. You need to know which gaps you have, fix the ones that matter most first, and get help with the rest. Attackers rarely need anything clever when an update hasn't been applied, a login has no second factor, or an old account still works.
The other takeaway is planning. If nearly half of the people responsible for security wouldn't know what to do in an incident, the cheapest fix is deciding now who you'd call.
What to do this week
List every account, including the forgotten ones. Check Microsoft 365 or Google Workspace for shared mailboxes, service accounts and leavers' logins. Remove what you don't need and change any default or shared passwords.
Turn on multi-factor authentication everywhere you can. Start with email, admin accounts and anything that handles money.
Switch on automatic updates. On laptops, phones, your website and your router. Old, unpatched software is one of the easiest ways in.
Check your antivirus is actually running. Built-in tools like Microsoft Defender are fine for most small firms, as long as they're switched on and up to date.
Write down who you'd call. Your IT provider, your insurer's helpline, and the NCSC's free guidance. One page, stored somewhere you can reach if your systems are down.
Sophia Says
This report doesn't surprise me, and it shouldn't embarrass anyone. Most small business owners never signed up to be IT experts, yet they're expected to configure firewalls between serving customers and doing payroll. The worrying part isn't the skills gap itself. It's that so many gaps go unnoticed until someone outside finds them first.
That's where I come in. HackRisk looks at your business from the outside, the way an attacker would: the services you've left exposed, the software that's out of date, and the staff passwords that have already leaked onto the dark web. I explain what I find in plain English, rank it by what matters most, and tell you exactly what to fix, so you're not guessing which of the nine basics to tackle first.
— Sophia, HackRisk AI Security Analyst
Where HackRisk fits
Out-of-date software and weak settings: our Vulnerability Scan finds missing updates and risky configurations on your internet-facing systems.
Exposed logins and forgotten services: a Recon Scan maps what your business looks like from the outside, including login pages and services you may have forgotten about.
Leaked passwords: a Dark Web Scan checks whether your staff's credentials are already circulating, so you can change them before they're used.
Suppliers who hold your data: Supply Chain Risk shows how secure the businesses you rely on look from the outside.
People skills: Phishing Simulations and Security Awareness Training build your team's confidence, so security isn't left to one person.
Find your gaps in plain English
You don't need to be an expert to know where you stand. Get your free HackRisk report and see which basics you've already got covered and which to fix first.
