If your business runs on Microsoft 365 — and most UK small businesses do — your Microsoft sign-in page is your front door. Email, files, invoices, payroll, client records: all of it sits one password away.
Attackers know this, which is why they rarely bother with your firewall. They send a convincing email, someone on your team clicks it, types their password into a page that looks exactly like the real one, and that's the whole attack. Credential phishing is popular because it's cheap and it works. No technical wizardry needed. Just one tired person on a Friday afternoon.
The encouraging part: most of what stops it is already included in the licences you're paying for. Nothing below needs new hardware or a security team. It needs someone to switch things on, set sensible defaults and keep an eye on them. Here's the list, in the order we'd tackle it.

1. Turn on MFA everywhere
MFA — multi-factor authentication — is the prompt on your phone that confirms it's really you signing in. With it switched on, a stolen password on its own is useless. That single change defeats the most common attack aimed at small businesses.
The word that matters is everywhere. MFA on most accounts is a locked front door with a window open. And the accounts that get skipped are usually the worst ones to skip: the director who found the prompts irritating, the shared finance mailbox nobody owns. Those are exactly the inboxes attackers want, because that's where the invoices are.
Expect a week of grumbling. It passes. Our clients reach better than 98% MFA adoption, grumblers included, and it's the best return on effort in this whole article.
2. Sort out sharing links and guest access
Microsoft 365 makes sharing easy — sometimes too easy. Out of the box, many tenancies let staff create "anyone with the link" shares, which means a folder of client contracts can be forwarded to the entire world without anyone noticing.
Then there are guests: the freelancer from an old project, the accountant you've since replaced. Guest accounts don't tidy themselves up when the work ends. The access just sits there until someone revokes it.
The fix is unglamorous. Change the default so links go to specific, named people. Review who your guests actually are. Put expiry dates on shares that don't need to live forever. It's an hour of settings work, and your files stop drifting.
3. Patching and updates
Most successful attacks aren't clever. They use known holes in software — holes the vendor already fixed, on machines where nobody installed the fix. Postponed updates are how small businesses stay exposed: the reboot is always inconvenient, so "remind me tomorrow" quietly becomes six months.
The answer is to take the decision away from busy people. Managed patching — part of our cyber security service — pushes updates out of hours, checks they landed and chases the machines that missed them. Nobody loses a morning to a progress bar, and the known holes stay closed.
4. Phishing training that isn't a tick-box
An annual slideshow with a quiz at the end is compliance, not training. The email that catches someone out won't look like the examples in the slides. It'll look like a delivery notification, or a document request from a supplier, sent at 4:55 on a Friday.
What changes behaviour is practice. We run quarterly phishing simulations — realistic but harmless fake emails sent to your own team — and share the results without naming and shaming. Click-through rates typically halve within three to six months. The goal isn't to catch people out. It's to build the two-second pause before the click, and a culture where reporting a suspicious email takes seconds and nobody feels daft doing it.
5. Backup isn't automatic
A common and expensive assumption: "it's in the cloud, so it's backed up." Microsoft keeps the service running. It doesn't promise to put your data back the way it was after a mistake or an attack.
Retention is not backup. Deleted items eventually purge for good. Retention policies exist to hold data for legal reasons, not to restore the whole finance folder as it looked last Tuesday. If a leaver's mailbox is removed, or ransomware encrypts files that then sync to the cloud, retention settings won't rescue you.
So if losing it would hurt, back it up separately, with versions going back far enough to matter. It's part of what we build into every managed cloud setup, and one of the first gaps we find in tenancies that have grown organically.
6. Know what you'd do if a laptop walked off
Laptops get left on trains and in taxis. The question isn't whether it'll happen to your team eventually. It's what happens next.
If the machine is enrolled in Intune — Microsoft's device management, included in many business licences — and its disk is encrypted, the answer is calm: block sign-ins, wipe it remotely, order a replacement. You've lost hardware, not data.
If it isn't, you've potentially lost client files, saved passwords and a logged-in mailbox, and you may have a data breach to report. Same laptop, very different week.
Enrolment happens naturally when joiners and leavers are handled properly, which is why our helpdesk treats onboarding and offboarding as a managed process rather than a favour squeezed in when there's time.
Where to start
None of this needs a security budget or an in-house IT person. It needs someone to check the settings, close the gaps and keep them closed. That checklist — MFA coverage, sharing defaults, patch status, training, backup, device management — is exactly what our free security audit runs through, in plain English, with no obligation at the end of it.
Find out where your tenancy stands
Book a free security audit and we'll check every item on this list against your actual Microsoft 365 setup — then hand you a plain-English report of what's solid and what needs fixing.
