Security Controls Insurers Require
Cyber Security Risk Assessment: A Step-by-Step Guide for SMBs
A cyber security risk assessment is not a compliance ritual, and it is not a document you buy. It is the piece of work that tells you which of your systems, if it failed tomorrow morning, would stop you trading, and what you are going to do about it. For a UK small business it is also increasingly the thing you have to produce on demand: cyber insurers ask for it at renewal, larger clients ask for it in procurement, and Cyber Essentials assumes you have already done the thinking.
This guide walks through it the way a small business can actually complete it, in an afternoon or two, with no consultant and no software.
What a risk assessment is meant to produce
By the end you should be able to hand someone a single document that answers four questions:
- What information and systems does the business depend on?
- What could realistically go wrong with each of them?
- How bad would that be, and how likely is it?
- What are we doing about the ones that matter, by when, and who owns it?
That last column is the one people leave off, and it is the one an underwriter or an auditor reads first. A list of risks with no owner and no date is a list of excuses.
Step 1: Build the asset inventory
You cannot assess what you have not listed. Write down, in a spreadsheet:
- Devices: every laptop, desktop, phone and tablet used for work, including personal devices if staff check email on them.
- Cloud services: Microsoft 365 or Google Workspace, accounting software, CRM, file storage, payroll, e-commerce platform, website host.
- Data: what personal data you hold, on whom, and where it physically sits. Customer records, staff records, payment data, anything special category.
- People: who has administrator rights on each of the above.
- Suppliers: anyone with access to your systems or your data, including your IT provider and your bookkeeper.
Two things almost always surface here. The first is a cloud service nobody remembered signing up for, still holding live data. The second is that admin rights have quietly accumulated on someone who left, or on a shared login. Both are findings in their own right.
Step 2: Identify what could go wrong
Skip the threat-actor taxonomy. For a small business, the realistic scenarios are a short list:
- Phishing leading to a compromised email account, followed by invoice fraud. This is the most common expensive incident for UK SMEs by some distance, and it is the one our business email compromise guide covers in detail.
- Ransomware encrypting file storage and backups that were connected to the same network.
- A lost or stolen laptop that was not encrypted.
- A supplier breach exposing your data held on their systems.
- Accidental disclosure, such as a mis-addressed email or an open cloud folder.
- Loss of a critical cloud service for several days.
Against each asset from step 1, note which of these apply. Most will attract two or three.
Step 3: Score impact and likelihood
Keep the scoring crude, because false precision helps nobody. Rate each risk 1 to 5 for impact and 1 to 5 for likelihood, then multiply.
For impact, think in concrete terms rather than adjectives: how many days of trading would we lose, what would it cost to rebuild, would we have to notify the ICO within 72 hours, would we lose a contract. Personal data breaches carry a regulatory dimension that a pure IT outage does not, which is worth understanding through our explainer on who enforces UK GDPR.
For likelihood, be honest about controls you have today, not the ones you intend to buy. If multi-factor authentication is not switched on for email, the likelihood of an account compromise is not low.
Anything scoring 15 or above goes on the action plan. Anything below 6 gets recorded and accepted in writing, which is a legitimate outcome as long as somebody senior has actually accepted it.
Step 4: Map the risks to the five controls
There is no point inventing a control framework. The NCSC’s five Cyber Essentials controls map cleanly onto almost every risk a small business will identify:
- Firewalls and internet gateways
- Secure configuration
- User access control
- Malware protection
- Security update management
Work through your high-scoring risks and note which control addresses each one. The NCSC Cyber Essentials overview sets out what each control requires, and applying them properly is estimated to stop around four fifths of common internet-based attacks.
One update matters for 2026: the scheme moved to a tighter technical standard from late April 2026, and multi-factor authentication is now mandatory on cloud services wherever it is available. If your assessment predates that, it is out of date. We cover what changed in our guide to Cyber Essentials cost and the new MFA rule.
Step 5: Write the action plan and set a review date
For each risk above your threshold, record the treatment, the owner and the deadline. Treatments fall into four categories: fix it, reduce it, transfer it (which is where cyber insurance sits), or accept it.
Cyber insurance is a transfer mechanism, not a substitute for the first three. Underwriters increasingly decline or load risks where MFA, offline backups and endpoint protection are absent, and some policies carry conditions precedent that can void a claim if the stated controls were not actually in place. If insurance is part of your plan, read our guides on what cyber insurance covers and excludes and how to read a cyber insurance policy before you rely on it.
Set a review date twelve months out, and an event trigger: reassess after any significant system change, any incident, or any new major client contract.
What insurers and clients actually want to see
Having reviewed what gets asked for at renewal, the evidence that carries weight is narrow and specific:
- A dated assessment with a named owner.
- Confirmation that MFA is enforced on email and remote access, not merely available.
- Evidence that backups exist, are held offline or in immutable storage, and have been restored from at least once in a test.
- A patching regime with a stated timescale for critical updates.
- An incident response plan naming who is called first, out of hours.
- Current Cyber Essentials certification, which several insurers now treat as a condition or a discount trigger.
A polished twenty-page report without those six things is worth less than a two-page assessment that has them.
Common mistakes
Assessing the IT and ignoring the people. Most incidents start with someone clicking something. Awareness training and a payment verification process belong in the assessment.
Treating backup as a solved problem. An untested backup is a hypothesis. A backup connected to the same network as the thing it protects is a liability.
Scoping out personal devices. If work email is on a personal phone, that phone is in scope, for the assessment and for Cyber Essentials.
Doing it once. An assessment that is three years old tells an underwriter more about your management than about your risk.
Frequently asked questions
What is a cyber security risk assessment? It is a structured review of the systems and data a business depends on, the things that could realistically go wrong with them, how serious each would be, and what is being done to reduce the ones that matter. It produces a dated, owned action plan rather than a general opinion.
How often should a small business do one? Annually as a baseline, plus after any material change: a new cloud platform, an office move, a merger, a significant supplier change, or any actual incident. Insurers generally expect the assessment to be no older than the current policy year.
Do I need a consultant to do a cyber security risk assessment? Not for a typical small business. The NCSC publishes free guidance and a readiness tool, and the assessment questions for Cyber Essentials are available at no cost from IASME. External help is worth paying for when you have complex infrastructure, regulated data, or a contract that demands independent assurance.
Is a risk assessment the same as an audit? No. An assessment identifies and prioritises risk looking forward; an audit tests whether stated controls are genuinely operating. Cyber Essentials is a verified self-assessment, while Cyber Essentials Plus adds hands-on technical testing by an assessor.
Will a risk assessment reduce my cyber insurance premium? Not by itself, but the controls it drives usually will. Underwriters price on MFA coverage, backup resilience, endpoint protection and patching discipline, and several treat Cyber Essentials certification as a rating factor.
What should the finished document look like? A spreadsheet is fine. One row per risk, with columns for asset, scenario, impact, likelihood, score, existing control, treatment, owner and due date, plus a short covering page giving the scope, the date and who signed it off.