Cyberattacks are a constant threat to UK organisations. According to the Government’s latest Cyber Security Breaches Survey, 43% of UK businesses identified a cyber breach or attack in the last 12 months. This rises to 65% of medium-sized businesses and 69% of large businesses.
No organisation is immune to cyberattacks
You may remember that Marks & Spencer suffered a major cyber incident in April 2025 that disrupted its online and operational systems. By the end of its 2025/26 financial year, the company reported £131.3 million in costs directly associated with the incident.
Local authorities are particularly exposed. Research based on Freedom of Information requests found that 27 UK councils recorded more than 2,400 suspected data breaches during 2024, ranging from misdirected emails and lost information to unauthorised access and disclosure.
More recently, a November 2025 cyberattack affected shared IT systems used by Westminster City Council, the Royal Borough of Kensington and Chelsea, and Hammersmith & Fulham Council. Systems had to be isolated while specialist teams investigated and contained the attack, disrupting a range of council services for months.
By the way, did you know billions of stolen login details are available online?
In 2025, cybersecurity researchers uncovered around 16 billion login records within dozens of exposed datasets. Contrary to some headlines at the time, this was not one enormous breach; it was actually credentials collected over many years by previous breaches.
If you take anything away from this article, let it be this: once your login details are exposed, attackers will use them on other websites and services for years afterwards. You might want to update your passwords for critical or sensitive services!
What exactly ARE cyberattacks? How do they affect me personally?
In simple terms, a cyberattack is when someone targets a computer, smartphone, online account, network, or data. This could be to steal information or money, gain unauthorised access, disrupt services, or cause damage. Below are some of the main types you might run into.
Phishing and social engineering – This involves an attacker pretending to be someone trustworthy so they can trick you into revealing information. For example, entering your password into a fake website, clicking a malicious link, downloading a malicious file, or sending money. Phishing is the most common type of cyberattack, and these attacks are becoming harder to spot. Criminals can now use AI to create convincing emails and messages, imitate writing styles, and assist with targeted scams.
Ransomware and extortion – Ransomware is malicious software used to disrupt access to systems or data, usually involving an attacker encrypting your files and then demanding a ransom to unlock them. Increasingly, criminals are also stealing sensitive information and threatening to publish or sell it unless they are paid. Some groups now skip the encryption entirely and rely solely on stolen data and extortion.
Credential theft, credential stuffing and account takeover – As mentioned above, attackers often take usernames and passwords exposed in previous breaches and try them on other websites. The only reason this works is because many people reuse the same password across multiple accounts.
Malware and trojans – Malware is a broad term for malicious software designed to compromise a device or system. It can steal information, record and monitor everything you do, install additional malicious software, give an attacker remote access, or spread to other systems. “Trojans” disguise themselves as legitimate files or applications to trick you into installing them. A particularly common modern threat is “infostealer” malware, which targets information stored in web browsers and applications, such as passwords, login cookies and other credentials.
Okay, I’m very scared now! How do I protect myself from cyberattacks?!
The good news is that you don’t need to be a tech expert to improve your cybersecurity. A handful of basic precautions can significantly reduce your risk.
1) ALWAYS use strong, unique passwords (start looking into passkeys as well)
Make sure your passwords are strong and unique for every account. Do not rely on predictable tricks like replacing an “o” with a zero, or adding an exclamation mark at the end. The length of a password is generally more secure than unnecessary complexity, such as combining three random words to create a long and memorable password.
Yes, it IS annoying having to remember lots of passwords, but reusing passwords makes life much easier for attackers. It only takes one website suffering a breach for criminals to get ahold of your logins details, which they can then use to break into other accounts you have elsewhere. To make things easier, use a reputable password manager or credential manager to generate and securely store strong, unique passwords. Reputable password managers encrypt the information you store within it, significantly reducing the risk of your passwords being exposed in a breach. Some browsers and password managers can also warn you when credentials associated with your accounts appear in a known data breach. You can use services such as Have I Been Pwned to check whether your email address has appeared in known compromised datasets. If a password has been exposed, change it immediately anywhere you have used it, and don’t reuse it again!
In addition, if a website or app supports passkeys, consider using one instead of a traditional password. Passkeys use the security already built into your device (Face ID, fingerprint, device PIN, etc), and are designed to resist phishing and password theft. Modern credential managers can also store and synchronise passkeys across your devices, so you don’t have to remember dozens of separate logins. You can read more about passkeys on NCSC by clicking here.
2) ALWAYS enable multi-factor authentication (MFA)
It feels like MFA is pushed on you everywhere you go now, adding yet another hoop you have to jump through just to log into your account. What a pain!
Naturally, it’s also a pain for attackers. MFA adds an additional check when you sign in, making it much harder for somebody to access your account with a stolen password alone. There are several types of MFA (SMS, email, app, etc). Authenticator apps such as Microsoft/Google Authenticator are preferable to SMS verification, though having any kind of MFA still provides a major security improvement over passwords alone. MFA isn’t completely foolproof, however. Some phishing attacks can trick users into handing over both their password and temporary authentication code, while malware can sometimes steal an already authenticated browser session.
This is where passkeys hold an advantage over MFA. Passkeys are much more resistant to phishing because authentication is tied to the actual website or service itself, meaning an attacker cannot just trick you into entering the credential on a fake login page.
3) ALWAYS keep your software up-to-date
Attackers are constantly looking for vulnerabilities they can exploit, while software and security operatives are continually finding and fixing them. Even after a vulnerability is fixed in a released security update, attackers will keep targeting devices that haven’t been patched. By keeping your systems up to date, you minimise the number of known vulnerabilities an attacker can exploit.
It’s not just your Windows, macOS, Android or iOS operating systems you have to worry about. Your web browser, browser extensions, apps and other installed software also need to stay updated. Enable automatic security updates wherever possible. For most users, the small risk of an update temporarily causing a software issue is far lower than the risk of leaving known vulnerabilities exposed for weeks or months. Keep in mind that some updates still require you to restart your device, free up storage space, reopen an application, or manually approve installation.
You should also check whether your devices and software are still officially supported. Once a device or piece of software reaches the end of its supported life, newly discovered security vulnerabilities may no longer be fixed. If something you use no longer receives security updates, you should consider upgrading or replacing it where practical.
4) ALWAYS be careful with emails, links, attachments, and communications
Be suspicious of unexpected or unusual messages. If you receive something out of the blue (especially if it asks you to log in, send money, or act quickly), your first instinct should be to verify it. If your Nan is asking for your credit card information, her accounts or devices might be compromised! Phishing and social engineering attackers work because they exploit trust, authority, curiosity and urgency.
Verifying the sender should be at the top of your checklist. Check the full email address carefully, not just the display name. Attackers may use lookalike domains, hijack genuine accounts, or impersonate someone you know. If a message asks you to do something unusual, verify it from a separate channel. Call the person using a number you already know, or start a new email or message rather than replying to the dodgy one.
Be especially wary with links and QR codes. On a computer, you can hover over a link with your mouse pointer to check where it really goes. Be careful on a phone; the destination can be harder to inspect! If you’re not sure, don’t click the link. Open the organisation’s official app or type its known website address into your browser instead. Be especially wary with QR codes, as these hide the destination until you scan it, making it useful for directing people to malicious pages.
Attachments are another common attack vector. An attachment such as an invoice, Word document, ZIP file or PDF can look harmless, but it may contain malicious content or direct you towards malware. If an attachment asks you to enable macros, install software, open another file, enter login details, or bypass a security warning, stay alert. Verify the attachment with the sender before opening it.
Attackers want you to think and act quickly – don’t fall for it! Slow down and ask yourself what the message is actually asking you to do. Warning signs include urgency, threats, payment requests, asking to bypass normal procedures, login prompts, or pressure to keep something secret. While spelling mistakes and awkward wording are often warning signs, do not assume that a professionally written message is genuine. AI tools now make it much easier for criminals to produce convincing, personalised messages with perfect spelling and grammar.
Never disclose passwords, codes, banking details, or other sensitive information over the phone. If you’re unsure, hang up and contact the organisation yourself via their official channels. Just because the caller sounds convincing or claims to be from a trusted organisation doesn’t mean they are legitimate. Voice cloning and AI-generated audio mean that recognising someone’s voice is no longer enough to prove who they are. The same applies increasingly to video. If a family member, colleague or manager suddenly asks for money or sensitive information, verify the request before acting.
Never send your login credentials via email, chat, SMS, or over the phone. Even if a request appears to come from someone you trust (your boss, a colleague, even your Nan), their account could already be hijacked.
5) ALWAYS use secure Wi-Fi
Be careful when connecting to public networks in airports, cafés, hotels, libraries, trains, etc. While modern websites normally protect your traffic using HTTPS encryption, public networks are still outside your control. Where practical, using your mobile data or a personal hotspot removes many of these risks.
If you have to use public Wi-Fi, make sure you’re connecting to the right network. Attackers can create fake Wi-Fi hotspots with names that resemble legitimate networks. If you’re unsure, ask staff for the correct network name rather than simply connecting to whichever open network appears first.
A VPN can provide an additional layer of protection, particularly when accessing work systems or services. A VPN creates an encrypted connection between your device and the VPN provider or your organisation’s network. However, a VPN is not a general purpose “make me safe online” button. It does not stop phishing, malware, fake websites, stolen passwords, or scams. It also means you’re choosing to trust the VPN provider with your network traffic, so avoid unknown providers and services that are unclear about how they handle your data.
6) ALWAYS use antivirus software and enable your firewall
Modern computers already include strong built-in protection against malware. Windows and macOS both include antivirus or anti-malware technology, while built-in firewalls help block unwanted network connections. Make sure these protections are enabled and kept up to date.
On Windows, Microsoft Defender provides built-in antivirus protection and is suitable for most users. Third-party security products can provide additional features, but they aren’t automatically more secure, and running multiple antivirus products at the same time can cause performance issues.
On smartphones, Android includes protections such as Google Play Protect, while iOS uses application sandboxing and other platform security controls. For most users, keeping the phone updated, installing apps only from trusted sources, and reviewing app permissions are more important than installing a separate antivirus product. If you install apps from outside official stores or from unknown sources, you significantly increase the risk of malware.
7) ALWAYS back up your data regularly
Since you’re reading this, you must be a responsible person who always keeps regular backups of their data.
But let’s say, hypothetically, you haven’t backed up your data recently. Now let’s say, hypothetically, your computer or smartphone explodes, or you become a victim of ransomware, and you lose access to all of your logins and passwords and files and contacts and apps. What do you do?
You should back up your data – properly! At a minimum, keep regular copies of anything you couldn’t easily replace, such as documents, photos and other important files.
A useful rule of thumb is 3-2-1. Keep at least three copies of important data, across two different devices or storage types, with one copy stored separately or offline. An external drive that you disconnect when you’re not using it can provide useful protection, while reputable cloud backup services can protect you against loss or hardware failure. However, simply synchronising files to the cloud isn’t necessarily the same as having a proper offline backup. Accidental terms of service violations, file deletions, corruption or ransomware can disrupt your cloud backups, or lock you out of them entirely!
A backup only counts if you can actually restore from it. Test your backups now and then to make sure the files are intact and you know how to recover them. If ransomware encrypts or destroys your files, a good backup can allow you to recover without relying on the attacker. Just remember that backups cannot undo the theft of sensitive information if an attacker has already copied it.
8) ALWAYS limit the amount of personal information you display online
Be careful about how much personal information you make publicly available online. Criminals can use information from social media, company websites and other public sources to make phishing messages more convincing, impersonate people you know, or answer identity verification questions.
Think twice before publicly sharing details such as your contact details, date of birth, travel plans, workplace information, or answers to common security questions. Every time you come across a seemingly harmless viral post asking people to share their first pet, mother’s maiden name, first car or favourite colour, assume it’s an attacker gathering information. AI also makes it easier for criminals to combine scattered pieces of public information into highly personalised scams, so information that seems insignificant on its own can become much more useful when combined with other sources. Review the privacy settings on your social media accounts and limit personal information to people who genuinely need to see it. Remember that information about you may also be posted online by friends, family members or colleagues!
9) ALWAYS clean up junk apps, extensions and permissions
“I downloaded an app from the Apple/Google Play store that allows me to view PDF files on my phone. It’s from the official store, so it must be safe to use!”
Wrong! Downloading apps from official stores significantly reduces the risk, but it doesn’t guarantee that every app is trustworthy. Malicious or overly intrusive applications can occasionally pass review processes before later being identified and removed.
Go through the apps on your phone regularly. If you no longer use an app, uninstall it. For the apps you keep, review permissions such as access to your camera, microphone, location, contacts, photos and files. Ask yourself whether the app genuinely needs each permission to do its job. Do the same on your computer by removing browser extensions you no longer need, because extensions can sometimes read or modify information on websites you visit. Also review third-party applications connected to important accounts such as Google, Microsoft, Apple or social media services, and revoke access you no longer recognise or use.
10) ALWAYS use trusted websites
There are all kinds of websites on the internet, and not all of them are trustworthy.
Check where you are before entering sensitive information. Pay close attention to the actual domain name, particularly when logging in, shopping, or making a payment. Attackers frequently create websites that closely imitate genuine services but use slightly altered or misleading addresses.
HTTPS encrypts the connection between your browser and the website, but it does not prove that the website is legitimate. Scam and phishing websites can use HTTPS too, so don’t rely on a padlock or “secure connection” indicator. For important services such as online banking, government services or your main email account, use the organisation’s official app, a saved bookmark, or type the known address yourself rather than following links in unexpected messages or adverts. Modern browsers can also warn you if you are about to access an unencrypted site. Your browser’s built-in security features can help detect known phishing and malicious websites as well. Just remember to avoid installing lots of “security” browser extensions, as extensions can have extensive access to your browsing data. Always make sure browser extensions are from a reputable developer, review its permissions, keep it updated and remove it when you no longer need it.
Remember – staying cyber safe starts with you!
For further information, the ICO has a wealth of information individuals can use to improve their cyber security.




