Cyber Security for Manchester Businesses: The Essential 2026 Checklist
Cyber security is no longer something only large organisations need to worry about.
Every business that uses email, Microsoft 365, cloud storage, online banking, connected devices or customer data faces a potential cyber security risk. For small and medium-sized businesses, a single compromised account, fraudulent payment request or failed backup can cause serious disruption.
The UK Government’s latest Cyber Security Breaches Survey found that 43% of businesses had identified a cyber security breach or attack within the previous 12 months. This increased to 46% of small businesses and 65% of medium-sized businesses.
Phishing remained the most common type of attack, affecting 38% of businesses.
For companies across Manchester and the North West, the question is no longer whether cyber security matters. The real question is whether the protection currently in place is strong enough.
What cyber security does a Manchester business need in 2026?
A secure business should have multiple layers of protection covering its people, devices, email accounts, business systems and data.
At a minimum, this should include:
Multi-factor authentication
Securely configured Microsoft 365 accounts
Email security and phishing protection
Endpoint Detection and Response
Regular software updates and security patching
Managed antivirus protection
Firewalls and properly secured networks
Reliable, monitored backups
Restricted administrator access
A clear plan for responding to a cyber incident
No single security product can protect an organisation from every threat. Effective business cyber security combines the right technology with secure configuration, regular monitoring and sensible working practices.
Here is the essential 2026 cyber security checklist for Manchester businesses.
1. Protect every important account with multi-factor authentication
A password alone is no longer enough to protect an important business account.
Multi-factor authentication, often shortened to MFA, requires an additional form of verification when somebody signs in. This might be a prompt from an authentication app, a physical security key or another approved verification method.
MFA should be enabled on:
Microsoft 365
Business email accounts
Cloud storage
Banking and finance systems
Customer relationship management platforms
Social media accounts
Website administration
Remote-access services
Any system holding confidential or commercially sensitive information
If a password is stolen through phishing, reused on another service or exposed in a data breach, MFA provides an additional barrier against unauthorised access.
Businesses should also review which MFA methods are being used. Authentication apps and properly configured security keys can provide stronger protection than relying entirely on text messages.
2. Review the security of Microsoft 365
Microsoft 365 is central to the daily operation of many Manchester businesses. It may hold company email, files, calendars, Teams conversations, SharePoint sites and important customer information.
However, simply purchasing Microsoft 365 does not mean every available security measure has automatically been configured correctly.
A Microsoft 365 security review should examine:
Multi-factor authentication
Administrator permissions
Suspicious sign-in alerts
Email forwarding rules
Legacy authentication
Sharing permissions
Inactive user accounts
Access from unmanaged devices
Security policies
Recovery information
Mailbox auditing
Licensing suitability
Former employees and unused accounts should be removed or disabled promptly. Administrator access should be limited to the people who genuinely need it, rather than being given to every user for convenience.
ShaeTec helps businesses configure and manage Microsoft 365 environments so that the platform is not only productive, but properly secured around the organisation using it.
3. Strengthen business email security
Email remains one of the most common routes into a business.
Phishing emails are designed to persuade employees to reveal passwords, open malicious attachments, follow fraudulent links or authorise payments. More sophisticated attacks may imitate a director, supplier or trusted customer.
Business email security should include:
Filtering for spam and malicious content
Protection against impersonation
Secure email-domain configuration
Suspicious-link and attachment detection
Multi-factor authentication
Monitoring for unusual logins
Controls over automatic email forwarding
A straightforward way for employees to report suspicious messages
Employees should be encouraged to question unexpected requests involving passwords, bank details, invoices or urgent payments—even when the message appears to come from somebody they know.
No genuine colleague or IT provider should make an employee feel foolish for checking a suspicious request.
4. Move beyond traditional antivirus
Traditional antivirus remains useful, but modern cyber threats require more than basic virus detection.
Endpoint Detection and Response, commonly known as EDR, continuously monitors computers and other endpoints for suspicious behaviour. It can help identify activity that may not resemble a traditional computer virus, including unusual processes, malicious scripts and attempts to gain control of a device.
EDR can provide:
Continuous endpoint monitoring
Behaviour-based threat detection
Faster investigation of suspicious activity
Greater visibility across company devices
The ability to isolate an affected endpoint
Support when responding to a security incident
For Manchester SMEs without an internal cyber security team, managed endpoint protection can provide valuable monitoring and technical oversight without the expense of building a specialist department in-house.
5. Keep devices and software properly patched
Cyber criminals regularly exploit known weaknesses in outdated operating systems, applications and network devices.
Security patches are released to close these vulnerabilities. Delaying updates can leave an organisation exposed to a problem for which a solution already exists.
Businesses should maintain an accurate record of:
Desktop computers
Laptops
Servers
Smartphones and tablets
Firewalls
Routers
Wireless access points
Operating systems
Business software
Internet-connected equipment
Unsupported systems should be identified and replaced or isolated. Automatic updates are helpful, but businesses also need a process for confirming that critical patches have installed successfully.
The National Cyber Security Centre advises organisations to keep software and devices updated to reduce the risk of known vulnerabilities being exploited.
6. Check that backups are working—and test the recovery
Having a backup and being able to recover from it are not always the same thing.
Backups can fail silently, become corrupted or prove incomplete when they are finally needed. A business may also discover too late that an important server, mailbox or cloud folder was never included.
A reliable backup strategy should answer five questions:
What information is being backed up?
How frequently does the backup run?
Where is the backup stored?
Who is alerted if it fails?
When was a full restoration last tested?
Backups should be separated appropriately from live business systems so that a ransomware attack cannot easily encrypt both the original data and every available copy.
Microsoft 365 retention and cloud synchronisation should not automatically be treated as complete business backup strategies. The correct arrangement depends on the organisation’s systems, data, recovery requirements and acceptable downtime.
7. Restrict administrator access
Administrator accounts can make significant changes to devices, networks and cloud environments. If one is compromised, an attacker may gain much broader access than they would through a standard user account.
Administrator privileges should be:
Given only when genuinely required
Separated from normal everyday accounts where practical
Protected with strong MFA
Reviewed regularly
Removed immediately when no longer needed
Monitored for suspicious activity
Employees should generally use standard accounts for email, web browsing and routine work.
Businesses should also know who controls their most important administrator credentials. These should not be known only to one employee, an outgoing member of staff or an external supplier without appropriate documentation and oversight.
8. Secure office, remote and guest networks
Business connectivity needs to be both reliable and secure.
Weak Wi-Fi passwords, outdated router firmware, incorrectly configured firewalls and unmanaged remote access can all create unnecessary vulnerabilities.
A network security review should cover:
Firewall configuration
Business Wi-Fi security
Separate guest networks
Router and access-point updates
Remote-access arrangements
Virtual private networks
Connected printers and smart devices
Access to servers and shared storage
Monitoring for unauthorised devices
Resilience of the internet connection
Guest devices should not automatically have access to the same network as business computers, servers or sensitive operational systems.
Companies moving premises, expanding into additional sites or adopting hybrid working should review their network design rather than simply extending an arrangement that was built for a smaller organisation.
9. Protect laptops, phones and remote workers
Hybrid and remote working have changed the boundaries of business IT.
Employees may access company information from home networks, mobile phones, shared spaces and portable devices. This flexibility needs to be supported by clear security controls.
Businesses should consider:
Device encryption
Secure screen locks
Remote device management
Approved software policies
Secure remote access
Protection for lost or stolen devices
Controls over local file storage
Rules for personal devices
Secure use of public Wi-Fi
Prompt reporting of lost equipment
A laptop used outside the office should receive the same level of monitoring, patching and endpoint protection as a desktop connected to the main business network.
10. Check who has access to company data
Access permissions often grow over time.
Employees change roles, temporary workers complete projects and external suppliers are given access to folders or systems. Unless permissions are reviewed, people may retain access long after they need it.
Businesses should regularly check:
Microsoft 365 users and groups
SharePoint permissions
Shared folders
Cloud applications
Finance platforms
Website accounts
Social media access
Supplier and contractor accounts
Former employee accounts
Shared passwords
Access should follow the principle of least privilege: people should have the access necessary to perform their role, but no more.
When somebody leaves the company, access should be removed through a consistent offboarding process rather than relying on somebody to remember every individual system.
11. Train employees to recognise cyber threats
Technology can block many threats, but employees remain an important part of business security.
Training should be practical, understandable and relevant to the situations staff actually encounter. It should cover:
Phishing emails
Fraudulent payment requests
Password security
Multi-factor authentication prompts
Suspicious attachments and links
Impersonation attempts
Safe handling of company data
Lost or stolen devices
Reporting potential incidents
Employees should know exactly who to contact when something looks wrong.
Quick reporting can make an enormous difference. A suspicious click reported immediately may be investigated and contained. The same incident left unnoticed could develop into a far more serious compromise.
12. Create a straightforward cyber incident plan
A cyber incident is not the time to decide who is responsible for making decisions.
Every business should have a clear, accessible response plan covering:
Who should be contacted first
How affected devices should be isolated
Who controls Microsoft 365 and network administration
How customers or suppliers may be affected
Where backups are held
How business-critical systems will be restored
Which incidents may need to be reported
How the company will communicate if email is unavailable
Contact details for the IT support provider
Responsibilities of directors and senior managers
The plan does not need to be unnecessarily complicated. It needs to be accurate, understood and available when normal systems may not be working.
13. Review suppliers and third-party access
A business can have strong internal protection and still be exposed through a poorly managed supplier account or third-party connection.
Review which external organisations can access:
Company systems
Microsoft 365
Shared data
Websites
Networks
Finance platforms
Remote-support tools
Customer information
Ask how that access is protected, who uses it and how it will be removed when the relationship ends.
Contracts and support arrangements should clearly explain responsibilities for data, security, backups and incident response.
14. Consider Cyber Essentials
Cyber Essentials is a UK Government-backed scheme designed to help organisations protect themselves against common cyber attacks.
It focuses on five important areas:
Firewalls
Secure configuration
Security update management
User access control
Malware protection
Certification can help a business demonstrate that fundamental protections are in place. It may also be requested by customers, supply chains or organisations awarding certain contracts.
Cyber Essentials Plus includes independent technical verification of the controls.
ShaeTec can help organisations understand the requirements, identify potential gaps and prepare their technology environment for Cyber Essentials assessment.
15. Arrange regular professional security reviews
Cyber security is not a one-time project.
Businesses change constantly. New employees join, equipment is replaced, software is introduced, permissions are altered and new threats emerge. A system that was secure two years ago may no longer reflect the organisation using it today.
A professional IT and cyber security review can examine:
Current devices and operating systems
Microsoft 365 configuration
User and administrator access
Email security
Endpoint protection and EDR
Firewalls and business networks
Software patching
Backup and recovery
Licensing
Remote working
Documentation
Incident readiness
The aim should not be to frighten businesses or sell unnecessary technology. It should be to identify genuine risks, prioritise the most important improvements and create a realistic plan.
Is antivirus enough for a small business?
No. Antivirus is only one part of business cyber security.
A small business should also consider email protection, MFA, secure Microsoft 365 configuration, patching, EDR, firewalls, reliable backups, user-access controls and employee awareness.
The correct combination depends on the company’s size, systems, industry and risk profile.
Does Microsoft 365 include cyber security?
Microsoft 365 includes a range of security capabilities, but the features available depend on the licence being used and how the environment has been configured.
Microsoft 365 should be reviewed and managed rather than assumed to be secure by default. Important settings include MFA, administrator privileges, security policies, external sharing and suspicious sign-in monitoring.
How often should a business cyber security review take place?
A full review should normally take place at least annually and whenever the business undergoes a significant change.
Additional reviews may be appropriate after:
Moving premises
Changing IT providers
Recruiting or restructuring
Introducing new cloud systems
Expanding remote working
Experiencing a security incident
Acquiring another business
Preparing for Cyber Essentials
Critical security alerts, patches, backups and suspicious activity require ongoing monitoring rather than an annual check.
Do small businesses really get targeted by cyber criminals?
Yes. Cyber criminals do not only target famous brands or large corporations.
Automated attacks can scan huge numbers of organisations for weak passwords, unpatched systems and exposed accounts. Smaller businesses may also be targeted through phishing, invoice fraud, compromised suppliers and stolen Microsoft 365 credentials.
The Government’s 2025/2026 survey found that 46% of small businesses identified a cyber breach or attack during the previous 12 months.
What should a business do after a suspected cyber attack?
The immediate priorities are to report the incident, limit further access, preserve relevant information and obtain expert assistance.
Do not automatically delete evidence or continue using a device that may be compromised. The correct response will depend on whether the incident involves email, malware, stolen credentials, ransomware, financial fraud or unauthorised access.
Every employee should know how to report a suspected incident quickly.
Cyber security support for businesses across Manchester
ShaeTec provides business IT support and cyber security services across Manchester, Greater Manchester and the wider North West.
Our services include:
Managed IT support
Cyber security
Endpoint Detection and Response
Managed antivirus protection
Microsoft 365 management
Email security
Patching and security configuration
Firewalls and network security
Backup solutions
Cyber Essentials consulting
Business hardware and software licensing
Connectivity and infrastructure
With more than 30 years of technology industry experience, we help businesses understand their current risks and make practical improvements without unnecessary jargon or unsuitable, one-size-fits-all packages.
Whether you operate in Manchester city centre, Trafford, Salford, Stockport, Tameside, Oldham, Rochdale, Bury, Bolton or elsewhere across the North West, ShaeTec can help you build a safer, more resilient technology environment.
Is your business properly protected?
If you are unsure when your Microsoft 365 security, backups, endpoint protection, user access or network configuration were last reviewed, now is the time to check.
ShaeTec can review your current IT and cyber security arrangements, identify potential weaknesses and recommend practical improvements based on the way your business actually operates.
Modern Technology. Zero Hassle.
Contact us for a no obligation chat, to see how we can help support and grow your business.
Telephone: 07570 055677
Email: info@shaetec.com
Website: www.shaetec.com





Comments