The UK National Cyber Security Centre released a major update to its Small Business Guide in October 2024. The previous edition was from 2019 — a lifetime in cybersecurity terms. The new guidance reflects changes in the threat landscape, the regulatory environment, and the technology that small businesses use.
At Metaluxo we review NCSC guidance as part of our advisory work for UK-based SMEs. The 2024 update contains several important shifts.
What changed
Cloud-first assumptions. The 2019 guide assumed on-premise servers and local networks. The 2024 guide assumes cloud-based email, file storage, and applications. The controls have been reordered to reflect this reality.
Supply chain emphasis. The new guide dedicates a full section to third-party risk — vendor assessment, cloud provider security, and software supply chain. This reflects lessons from SolarWinds, MOVEit, and the CrowdStrike outage.
AI and deepfakes. The 2024 guide includes warnings about AI-generated phishing and deepfake fraud — threats that barely existed in 2019.
Incident reporting. The guide now explicitly recommends reporting incidents to Action Fraud and the NCSC, and notes that GDPR requires breach notification to the ICO within 72 hours.
The five actions the NCSC prioritises
-
Turn on two-factor authentication. The NCSC’s top recommendation for every account that supports it.
-
Keep software updated. Automatic updates where possible, prompt patching for critical vulnerabilities.
-
Back up your data. The 3-2-1 rule: three copies, two media types, one offsite.
-
Use passwords properly. A password manager for all business accounts, unique passwords for each service.
-
Protect against phishing. Email filtering, staff training, and clear reporting procedures.
These are the same five actions we recommend to every SME client. The NCSC and Metaluxo are aligned on the fundamentals.
What the NCSC does not cover
The guide is intentionally high-level. It does not cover:
- ISO 27001 implementation specifics
- Customer security questionnaire responses
- Contractual data protection obligations
- Industry-specific requirements (healthcare, fintech)
- Regulatory frameworks (NIS2, DORA, MiCA)
For SMEs that need to go beyond the basics — whether for compliance, customer requirements, or insurance — the NCSC guide is a starting point, not a complete programme.
At Metaluxo we help SMEs implement the NCSC guidance and extend it to meet specific compliance and commercial requirements. If you have read the guide and are unsure how to apply it to your business, book a free 30-minute consultation and we will build a tailored plan.