How to carry out a cyber security risk assessment for a small business

A cyber security risk assessment does not need to begin with a long spreadsheet or a room full of technical language. For a small business, it begins with three useful questions: what do we rely on, what could stop it working or expose it, and what would that do to the business?
This guide gives owners and managers in Greater Manchester a practical way to answer those questions. It is deliberately different from a list of security products: the aim is to find the risks that matter to your operation and put limited time and budget in the right order.
What a cyber security risk assessment actually is
A risk assessment connects technology to business consequences. It records an important asset or process, a credible threat, any weakness that makes the threat more likely, the controls already protecting it, and the impact if those controls fail. The result is a short, owned action plan rather than a report that sits unread.
That approach follows the principles in the National Cyber Security Centre's risk management guidance. For smaller organisations, the NCSC also provides a free Small Business Guide covering backups, malware, devices, passwords and phishing. Those are strong baseline controls, but the assessment tells you where to start.
Why Greater Manchester SMEs should do this now
Small firms hold useful customer, payment and employee information, depend on email and cloud services, and often have less spare capacity to recover from disruption. Geography does not shield a business from automated phishing, password attacks or ransomware. A manufacturer in Trafford Park, a professional practice in Bury and a retailer in Stockport face different operational impacts, but all can be reached through the same internet-facing services.
The UK government's annual Cyber Security Breaches Survey tracks how businesses experience and manage cyber incidents. The useful lesson is not to copy a national percentage into your plan; it is that cyber risk is a normal business risk which needs an owner, a budget and regular review.
Step 1: list what the business cannot operate without
Start with business services, not device serial numbers. Ask each department what would hurt if it were unavailable tomorrow, altered without permission or disclosed. Your first list may include:
- Microsoft 365 email, Teams, SharePoint and OneDrive;
- finance, payroll, customer relationship and booking systems;
- customer, employee and supplier data;
- laptops, mobiles, servers, networking and internet connections;
- production equipment, CCTV or access control connected to the network;
- key suppliers whose outage would stop you trading; and
- the people who hold specialist knowledge or administrator access.
For each one, record an owner and where the data lives. If nobody knows whether a system is cloud-hosted, backed up or managed by a supplier, that uncertainty is itself an action.
Step 2: describe realistic threats and weaknesses
A threat is something that could happen; a weakness is what makes it easier or more damaging. Keep scenarios specific enough to act on. “Cyber attack” is too vague. “A criminal signs into the finance manager's mailbox using a phished password and changes supplier bank details” is assessable.
- Account takeover: weak or reused passwords, missing MFA, excessive administrator access or old accounts that were never disabled.
- Ransomware: unpatched devices, exposed remote access, weak endpoint protection or backups accessible through the same compromised account.
- Accidental loss: a mistaken deletion, an incorrect sharing link, a lost laptop or a poorly planned system change.
- Supplier failure: a critical cloud or IT provider suffers an outage, breach or business failure with no tested alternative.
- Physical disruption: theft, fire, flood, power loss or connectivity failure at a Greater Manchester site.
If ransomware and account compromise are unfamiliar, read our explainers on how ransomware reaches small businesses and why multi-factor authentication matters.
Step 3: score impact and likelihood simply
You do not need false precision. Give impact and likelihood a score from 1 to 5, agree what the scale means, and multiply the two numbers for an initial priority. Consider impact across money, downtime, safety, legal duties, customer trust and contractual commitments.
| Score | Impact example | Likelihood example |
|---|---|---|
| 1 — Low | Minor inconvenience with no meaningful data loss | Unlikely in the next few years |
| 3 — Medium | A working day lost, material cost or customer disruption | Could reasonably happen |
| 5 — Critical | Trading stops, sensitive data is exposed or survival is threatened | Expected or already happening |
Then look at the controls already in place and score the residual risk that remains. Evidence matters. “We have backups” is weaker than “the backup is separated, monitored and a mailbox restore was completed successfully last month.” Our business data backup guide explains what good evidence looks like.
Step 4: prioritise actions that reduce several risks
Deal with critical, plausible risks first, especially where one affordable control protects several systems. Common high-value actions for SMEs include:
- turning on MFA for every cloud account, starting with administrators and email;
- removing unsupported software and applying security updates promptly;
- using separate day-to-day and administrator accounts;
- protecting every laptop and desktop with centrally monitored endpoint security;
- maintaining separate backups and proving that important data can be restored;
- training staff to report suspicious messages quickly; and
- writing a short incident plan with supplier and insurer contact details available offline.
These measures also align closely with Cyber Essentials for Greater Manchester SMEs. Certification can provide useful assurance, but the risk assessment should still reflect your particular systems, suppliers and consequences.
Step 5: turn the assessment into an action register
Every action needs an owner, a deadline and a way to prove completion. “Improve email security” is not an action. “Operations manager to enable MFA for the remaining six Microsoft 365 accounts by 30 September and export the registration report” is.
Keep accepted risks visible too. A business may decide that fixing a low-impact legacy system costs more than the likely harm, but that should be a conscious, time-limited decision by someone with authority — not an accidental gap. Transfer through insurance or a supplier can help with cost, but it does not transfer every operational or reputational consequence.
Data protection and customer requirements
A cyber risk assessment can also support your UK GDPR security decisions. The Information Commissioner's Office explains that organisations should use security measures appropriate to their circumstances and risk in its UK GDPR security guidance. Record why important controls were chosen, not just which products were bought.
Customers, tender teams, insurers and auditors may ask for evidence too. A current assessment, an owned improvement plan, restore-test results and Cyber Essentials status are more convincing than a policy that cannot be connected to day-to-day practice.
How often should you review it?
Review the full assessment at least once a year, and sooner after a material change: a move, merger, new cloud platform, major supplier change, security incident or rapid recruitment. Review critical actions monthly until they are closed. A useful assessment changes as the business changes.
Also test the assumptions. Restore a file and mailbox. Check that a leaver's access is gone. Confirm who receives a security alert. Call the incident contact number. Testing turns paperwork into confidence.
A one-page assessment is enough to begin
For each risk, write down: the service or data affected; the scenario; existing controls; impact; likelihood; residual priority; the next action; its owner; and its due date. Start with the five services your business relies on most. A short assessment that drives action is more valuable than a perfect template that never gets finished.
How Tech Savvy Solutions helps
We help SMEs across Bury, Manchester and the wider region understand and reduce their cyber risk without turning the exercise into a product pitch. Start with our free cyber security self-assessment, explore our cyber security services, or book a no-obligation review for a prioritised view of your own environment.
Want a clear view of your cyber risk?
Book a free, no-obligation security review and we'll help you identify the gaps that matter most to your Greater Manchester business — then give you a practical order for fixing them.