Checklist · Security basics

Cyber security and resilience checklist

Small companies are real targets. Use this checklist to set practical controls before a lost laptop, compromised inbox, ransomware incident or supplier breach becomes a company-threatening problem.

Updated 22 May 2026 · Legal & IP · Check linked official sources before acting.

Why it matters

5.5mUAE small organisations

UAE SMEs form the backbone of the non-oil economy; use current UAE cyber-risk benchmarks from official sources.

1 in 2Small businesses face recurring cyber threats

UAE cybersecurity authorities consistently warn that SMEs are frequent targets of phishing, credential theft and ransomware campaigns.

The five controls to implement first

  1. Back up critical data. Back up accounts, documents, code, customer records, invoices and product data. Keep at least one backup separate from day-to-day devices and test restoration.
  2. Protect devices. Turn on automatic updates, screen locks, encryption where available, anti-malware protection and remote wipe for phones and laptops.
  3. Secure email. Use a reputable business email provider, turn on MFA, set SPF/DKIM/DMARC where possible, and limit who can change payment details or forward mail externally.
  4. Secure important accounts. Use password managers, unique passwords, MFA, admin-role limits, recovery-code storage and an offboarding process for founders, contractors and suppliers.
  5. Spot cyber attacks. Train the team to report phishing, fake invoices, account-reset emails, unusual login prompts and urgent payment-change requests.

Startup-specific risk areas

Founder inboxes

Investor decks, customer contracts, payroll, bank alerts and domain renewals often sit in founder email. Protect it like production infrastructure.

Source code and secrets

Remove API keys from repos, rotate shared passwords, use least privilege and protect deployment accounts with MFA.

Supplier access

Freelancers and agencies should have scoped accounts, not shared founder logins. Remove access when work ends.

Payment fraud

Verify bank detail changes by a second channel. Use two-person approval for large payments where possible.

Customer data

Map what personal data you hold, why you hold it, who can access it and how quickly you could notify if breached.

Incident response

Keep a short contact list: hosting, email provider, bank, insurer, legal adviser, key customers and NCSC reporting links.

Evidence customers and insurers may ask for

If you think you have been hacked

Do not quietly keep operating and hope it passes. Preserve evidence, secure accounts, contact your provider or security adviser, assess customer/data impact, and use NCSC response guidance and reporting routes where appropriate.