top of page

Cyber Security for Manchester Businesses: The Essential 2026 Checklist

Aug 19
10 min read

Cyber security is no longer something only large organisations need to worry about.


Every business that uses email, Microsoft 365, cloud storage, online banking, connected devices or customer data faces a potential cyber security risk. For small and medium-sized businesses, a single compromised account, fraudulent payment request or failed backup can cause serious disruption.


The UK Government’s latest Cyber Security Breaches Survey found that 43% of businesses had identified a cyber security breach or attack within the previous 12 months. This increased to 46% of small businesses and 65% of medium-sized businesses.


Phishing remained the most common type of attack, affecting 38% of businesses.


For companies across Manchester and the North West, the question is no longer whether cyber security matters. The real question is whether the protection currently in place is strong enough.


What cyber security does a Manchester business need in 2026?


A secure business should have multiple layers of protection covering its people, devices, email accounts, business systems and data.


At a minimum, this should include:


  • Multi-factor authentication

  • Securely configured Microsoft 365 accounts

  • Email security and phishing protection

  • Endpoint Detection and Response

  • Regular software updates and security patching

  • Managed antivirus protection

  • Firewalls and properly secured networks

  • Reliable, monitored backups

  • Restricted administrator access

  • A clear plan for responding to a cyber incident


No single security product can protect an organisation from every threat. Effective business cyber security combines the right technology with secure configuration, regular monitoring and sensible working practices.


Here is the essential 2026 cyber security checklist for Manchester businesses.


1. Protect every important account with multi-factor authentication


A password alone is no longer enough to protect an important business account.


Multi-factor authentication, often shortened to MFA, requires an additional form of verification when somebody signs in. This might be a prompt from an authentication app, a physical security key or another approved verification method.


MFA should be enabled on:


  • Microsoft 365

  • Business email accounts

  • Cloud storage

  • Banking and finance systems

  • Customer relationship management platforms

  • Social media accounts

  • Website administration

  • Remote-access services

  • Any system holding confidential or commercially sensitive information


If a password is stolen through phishing, reused on another service or exposed in a data breach, MFA provides an additional barrier against unauthorised access.


Businesses should also review which MFA methods are being used. Authentication apps and properly configured security keys can provide stronger protection than relying entirely on text messages.


2. Review the security of Microsoft 365


Microsoft 365 is central to the daily operation of many Manchester businesses. It may hold company email, files, calendars, Teams conversations, SharePoint sites and important customer information.


However, simply purchasing Microsoft 365 does not mean every available security measure has automatically been configured correctly.


A Microsoft 365 security review should examine:


  • Multi-factor authentication

  • Administrator permissions

  • Suspicious sign-in alerts

  • Email forwarding rules

  • Legacy authentication

  • Sharing permissions

  • Inactive user accounts

  • Access from unmanaged devices

  • Security policies

  • Recovery information

  • Mailbox auditing

  • Licensing suitability


Former employees and unused accounts should be removed or disabled promptly. Administrator access should be limited to the people who genuinely need it, rather than being given to every user for convenience.


ShaeTec helps businesses configure and manage Microsoft 365 environments so that the platform is not only productive, but properly secured around the organisation using it.


3. Strengthen business email security


Email remains one of the most common routes into a business.


Phishing emails are designed to persuade employees to reveal passwords, open malicious attachments, follow fraudulent links or authorise payments. More sophisticated attacks may imitate a director, supplier or trusted customer.


Business email security should include:


  • Filtering for spam and malicious content

  • Protection against impersonation

  • Secure email-domain configuration

  • Suspicious-link and attachment detection

  • Multi-factor authentication

  • Monitoring for unusual logins

  • Controls over automatic email forwarding

  • A straightforward way for employees to report suspicious messages


Employees should be encouraged to question unexpected requests involving passwords, bank details, invoices or urgent payments—even when the message appears to come from somebody they know.


No genuine colleague or IT provider should make an employee feel foolish for checking a suspicious request.


4. Move beyond traditional antivirus


Traditional antivirus remains useful, but modern cyber threats require more than basic virus detection.


Endpoint Detection and Response, commonly known as EDR, continuously monitors computers and other endpoints for suspicious behaviour. It can help identify activity that may not resemble a traditional computer virus, including unusual processes, malicious scripts and attempts to gain control of a device.


EDR can provide:


  • Continuous endpoint monitoring

  • Behaviour-based threat detection

  • Faster investigation of suspicious activity

  • Greater visibility across company devices

  • The ability to isolate an affected endpoint

  • Support when responding to a security incident


For Manchester SMEs without an internal cyber security team, managed endpoint protection can provide valuable monitoring and technical oversight without the expense of building a specialist department in-house.


5. Keep devices and software properly patched


Cyber criminals regularly exploit known weaknesses in outdated operating systems, applications and network devices.


Security patches are released to close these vulnerabilities. Delaying updates can leave an organisation exposed to a problem for which a solution already exists.


Businesses should maintain an accurate record of:


  • Desktop computers

  • Laptops

  • Servers

  • Smartphones and tablets

  • Firewalls

  • Routers

  • Wireless access points

  • Operating systems

  • Business software

  • Internet-connected equipment


Unsupported systems should be identified and replaced or isolated. Automatic updates are helpful, but businesses also need a process for confirming that critical patches have installed successfully.


The National Cyber Security Centre advises organisations to keep software and devices updated to reduce the risk of known vulnerabilities being exploited.


6. Check that backups are working—and test the recovery


Having a backup and being able to recover from it are not always the same thing.


Backups can fail silently, become corrupted or prove incomplete when they are finally needed. A business may also discover too late that an important server, mailbox or cloud folder was never included.


A reliable backup strategy should answer five questions:


What information is being backed up?

How frequently does the backup run?

Where is the backup stored?

Who is alerted if it fails?

When was a full restoration last tested?


Backups should be separated appropriately from live business systems so that a ransomware attack cannot easily encrypt both the original data and every available copy.


Microsoft 365 retention and cloud synchronisation should not automatically be treated as complete business backup strategies. The correct arrangement depends on the organisation’s systems, data, recovery requirements and acceptable downtime.


7. Restrict administrator access


Administrator accounts can make significant changes to devices, networks and cloud environments. If one is compromised, an attacker may gain much broader access than they would through a standard user account.


Administrator privileges should be:


  • Given only when genuinely required

  • Separated from normal everyday accounts where practical

  • Protected with strong MFA

  • Reviewed regularly

  • Removed immediately when no longer needed

  • Monitored for suspicious activity

  • Employees should generally use standard accounts for email, web browsing and routine work.


Businesses should also know who controls their most important administrator credentials. These should not be known only to one employee, an outgoing member of staff or an external supplier without appropriate documentation and oversight.


8. Secure office, remote and guest networks


Business connectivity needs to be both reliable and secure.


Weak Wi-Fi passwords, outdated router firmware, incorrectly configured firewalls and unmanaged remote access can all create unnecessary vulnerabilities.


A network security review should cover:


  • Firewall configuration

  • Business Wi-Fi security

  • Separate guest networks

  • Router and access-point updates

  • Remote-access arrangements

  • Virtual private networks

  • Connected printers and smart devices

  • Access to servers and shared storage

  • Monitoring for unauthorised devices

  • Resilience of the internet connection


Guest devices should not automatically have access to the same network as business computers, servers or sensitive operational systems.


Companies moving premises, expanding into additional sites or adopting hybrid working should review their network design rather than simply extending an arrangement that was built for a smaller organisation.


9. Protect laptops, phones and remote workers


Hybrid and remote working have changed the boundaries of business IT.


Employees may access company information from home networks, mobile phones, shared spaces and portable devices. This flexibility needs to be supported by clear security controls.


Businesses should consider:


  • Device encryption

  • Secure screen locks

  • Remote device management

  • Approved software policies

  • Secure remote access

  • Protection for lost or stolen devices

  • Controls over local file storage

  • Rules for personal devices

  • Secure use of public Wi-Fi

  • Prompt reporting of lost equipment


A laptop used outside the office should receive the same level of monitoring, patching and endpoint protection as a desktop connected to the main business network.


10. Check who has access to company data


Access permissions often grow over time.


Employees change roles, temporary workers complete projects and external suppliers are given access to folders or systems. Unless permissions are reviewed, people may retain access long after they need it.


Businesses should regularly check:


  • Microsoft 365 users and groups

  • SharePoint permissions

  • Shared folders

  • Cloud applications

  • Finance platforms

  • Website accounts

  • Social media access

  • Supplier and contractor accounts

  • Former employee accounts

  • Shared passwords


Access should follow the principle of least privilege: people should have the access necessary to perform their role, but no more.


When somebody leaves the company, access should be removed through a consistent offboarding process rather than relying on somebody to remember every individual system.


11. Train employees to recognise cyber threats


Technology can block many threats, but employees remain an important part of business security.


Training should be practical, understandable and relevant to the situations staff actually encounter. It should cover:


  • Phishing emails

  • Fraudulent payment requests

  • Password security

  • Multi-factor authentication prompts

  • Suspicious attachments and links

  • Impersonation attempts

  • Safe handling of company data

  • Lost or stolen devices

  • Reporting potential incidents


Employees should know exactly who to contact when something looks wrong.


Quick reporting can make an enormous difference. A suspicious click reported immediately may be investigated and contained. The same incident left unnoticed could develop into a far more serious compromise.


12. Create a straightforward cyber incident plan


A cyber incident is not the time to decide who is responsible for making decisions.


Every business should have a clear, accessible response plan covering:


  • Who should be contacted first

  • How affected devices should be isolated

  • Who controls Microsoft 365 and network administration

  • How customers or suppliers may be affected

  • Where backups are held

  • How business-critical systems will be restored

  • Which incidents may need to be reported

  • How the company will communicate if email is unavailable

  • Contact details for the IT support provider

  • Responsibilities of directors and senior managers


The plan does not need to be unnecessarily complicated. It needs to be accurate, understood and available when normal systems may not be working.


13. Review suppliers and third-party access


A business can have strong internal protection and still be exposed through a poorly managed supplier account or third-party connection.


Review which external organisations can access:


  • Company systems

  • Microsoft 365

  • Shared data

  • Websites

  • Networks

  • Finance platforms

  • Remote-support tools

  • Customer information


Ask how that access is protected, who uses it and how it will be removed when the relationship ends.


Contracts and support arrangements should clearly explain responsibilities for data, security, backups and incident response.


14. Consider Cyber Essentials


Cyber Essentials is a UK Government-backed scheme designed to help organisations protect themselves against common cyber attacks.


It focuses on five important areas:


  • Firewalls

  • Secure configuration

  • Security update management

  • User access control

  • Malware protection


Certification can help a business demonstrate that fundamental protections are in place. It may also be requested by customers, supply chains or organisations awarding certain contracts.


Cyber Essentials Plus includes independent technical verification of the controls.


ShaeTec can help organisations understand the requirements, identify potential gaps and prepare their technology environment for Cyber Essentials assessment.


15. Arrange regular professional security reviews


Cyber security is not a one-time project.


Businesses change constantly. New employees join, equipment is replaced, software is introduced, permissions are altered and new threats emerge. A system that was secure two years ago may no longer reflect the organisation using it today.


A professional IT and cyber security review can examine:


  • Current devices and operating systems

  • Microsoft 365 configuration

  • User and administrator access

  • Email security

  • Endpoint protection and EDR

  • Firewalls and business networks

  • Software patching

  • Backup and recovery

  • Licensing

  • Remote working

  • Documentation

  • Incident readiness


The aim should not be to frighten businesses or sell unnecessary technology. It should be to identify genuine risks, prioritise the most important improvements and create a realistic plan.


Is antivirus enough for a small business?


No. Antivirus is only one part of business cyber security.


A small business should also consider email protection, MFA, secure Microsoft 365 configuration, patching, EDR, firewalls, reliable backups, user-access controls and employee awareness.


The correct combination depends on the company’s size, systems, industry and risk profile.


Does Microsoft 365 include cyber security?


Microsoft 365 includes a range of security capabilities, but the features available depend on the licence being used and how the environment has been configured.


Microsoft 365 should be reviewed and managed rather than assumed to be secure by default. Important settings include MFA, administrator privileges, security policies, external sharing and suspicious sign-in monitoring.


How often should a business cyber security review take place?


A full review should normally take place at least annually and whenever the business undergoes a significant change.


Additional reviews may be appropriate after:


  • Moving premises

  • Changing IT providers

  • Recruiting or restructuring

  • Introducing new cloud systems

  • Expanding remote working

  • Experiencing a security incident

  • Acquiring another business

  • Preparing for Cyber Essentials


Critical security alerts, patches, backups and suspicious activity require ongoing monitoring rather than an annual check.


Do small businesses really get targeted by cyber criminals?


Yes. Cyber criminals do not only target famous brands or large corporations.


Automated attacks can scan huge numbers of organisations for weak passwords, unpatched systems and exposed accounts. Smaller businesses may also be targeted through phishing, invoice fraud, compromised suppliers and stolen Microsoft 365 credentials.


The Government’s 2025/2026 survey found that 46% of small businesses identified a cyber breach or attack during the previous 12 months.


What should a business do after a suspected cyber attack?


The immediate priorities are to report the incident, limit further access, preserve relevant information and obtain expert assistance.


Do not automatically delete evidence or continue using a device that may be compromised. The correct response will depend on whether the incident involves email, malware, stolen credentials, ransomware, financial fraud or unauthorised access.


Every employee should know how to report a suspected incident quickly.


Cyber security support for businesses across Manchester


ShaeTec provides business IT support and cyber security services across Manchester, Greater Manchester and the wider North West.


Our services include:


  • Managed IT support

  • Cyber security

  • Endpoint Detection and Response

  • Managed antivirus protection

  • Microsoft 365 management

  • Email security

  • Patching and security configuration

  • Firewalls and network security

  • Backup solutions

  • Cyber Essentials consulting

  • Business hardware and software licensing

  • Connectivity and infrastructure


With more than 30 years of technology industry experience, we help businesses understand their current risks and make practical improvements without unnecessary jargon or unsuitable, one-size-fits-all packages.


Whether you operate in Manchester city centre, Trafford, Salford, Stockport, Tameside, Oldham, Rochdale, Bury, Bolton or elsewhere across the North West, ShaeTec can help you build a safer, more resilient technology environment.


Is your business properly protected?


If you are unsure when your Microsoft 365 security, backups, endpoint protection, user access or network configuration were last reviewed, now is the time to check.


ShaeTec can review your current IT and cyber security arrangements, identify potential weaknesses and recommend practical improvements based on the way your business actually operates.


Modern Technology. Zero Hassle.


Contact us for a no obligation chat, to see how we can help support and grow your business.


Telephone: 07570 055677


cyber security for Manchester businesses, small business cyber security Manchester, business IT security Manchester, Microsoft 365 security Manchester, Cyber Essentials Manchester

 
 
 

Comments


bottom of page