TL;DR:

  • The NCSC launched a free cyber consultation programme on 15 July 2026, giving small businesses access to 30-minute sessions with qualified Cyber Advisors
  • The sessions are practical and impartial — not a sales pitch for a product, and not an audit designed to find problems to charge you for fixing
  • The timing coincides with a new joint NCSC advisory about Russian state actors targeting poorly configured routers and network devices — including the type used in small offices

If you’ve ever thought “we should probably get some proper advice on our security but I don’t know where to start and I’m not going to pay a consultant £200 an hour for something I can’t evaluate” — this is worth your attention.

The National Cyber Security Centre launched a free cyber consultation programme on 15 July 2026, specifically aimed at small businesses. The programme gives you access to 30-minute one-to-one sessions with NCSC-accredited Cyber Advisors who will help you understand your current security posture, identify the most significant gaps, and recommend practical first steps.

It’s free. It’s not a sales pitch. And the timing is good — the NCSC has simultaneously published a new advisory about state-sponsored actors actively targeting the kind of edge devices (routers, firewalls, VPN concentrators) that sit at the perimeter of small office networks right now.

What Happens in a Consultation

The session is a structured 30-minute conversation, not a technical audit. The advisor will ask about your business — how many staff you have, how they work (office, remote, hybrid), what systems and data you rely on — and use that to focus the conversation on the risks that are most relevant to you.

You don’t need to prepare a technical briefing. The advisors are accredited to work with non-technical business owners, and the best ones are good at translating security concerns into business language.

What tends to come out of these sessions is a short prioritised list: the two or three things that would make the biggest difference to your security posture if you addressed them. For most small businesses that haven’t had any professional security input before, that list tends to include: multi-factor authentication on email and cloud accounts, a proper backup strategy that’s actually been tested, and a review of who has admin access to what.

If you’re already doing those three things, the conversation gets more interesting — the advisor can dig into things like email authentication records, network segmentation, or whether your current IT provider is actually monitoring your systems or just reacting when things break.

Why the Timing Matters

The NCSC published a joint advisory on 13 July 2026 — two days before the consultation programme launched — warning that Russian state-sponsored cyber actors are actively exploiting poorly configured network devices. This isn’t theoretical. The advisory, co-published with CISA in the US, describes attackers targeting routers and firewalls with weak credentials, outdated firmware, and inadequate logging.

For small businesses, this matters in a specific way. Most of us have a router that was installed when we moved into the office, possibly by an IT company we no longer use, running firmware that hasn’t been updated in years, with a password that might still be the default. That’s not a hypothetical attack surface — it’s actively being targeted right now.

If you book a consultation, this is worth raising specifically. An advisor can help you understand whether your current network setup has obvious exposure and what to ask your IT provider to check.

How to Book

The consultation booking is through the NCSC website. You’ll need to register with your business details — NCSC uses this to match you with an advisor who has relevant experience in your sector if possible.

Sessions are currently available across multiple time zones during UK business hours, with some early morning and early evening slots to accommodate business owners who can’t easily take a call during the working day.

Demand is likely to be high given the publicity around the programme. Book sooner rather than later — the initiative has limited advisor capacity and a mid-2027 end date.

How to Prepare

You’ll get more out of 30 minutes if you’ve thought through a few things beforehand. None of this needs to be formal — just have the answers to hand:

Who manages your IT? Is it an internal person, an external IT company, or something in between? Do you know their name and contact number?

What cloud services do you rely on? Microsoft 365, Google Workspace, accounting software (Xero, QuickBooks), CRM, industry-specific tools. A rough list is fine.

When did you last test your backup? Not “when did you set up backups” — when did you last actually restore something from backup to check it works?

Who has admin access to your main systems? Could you list those people right now? Is anyone on that list who no longer works with you?

Have you had any security incidents? Even minor ones — suspicious emails that staff clicked on, unexpected password resets, anything that felt odd.

You don’t need polished answers to these. The point is to be able to have a real conversation rather than spending the first ten minutes just establishing the basics.

After the Consultation

Most businesses that go through this kind of session get a short written summary from the advisor with the recommended actions. The actions tend to be graded: some you can do yourself today (enable MFA, change that router password), some you’ll need to ask your IT provider to do, and some might require a proper security assessment before you can act on them.

Don’t let the longer-term stuff make you ignore the quick wins. Enabling MFA on your Microsoft 365 or Google Workspace accounts, for example, blocks the majority of account takeover attempts and takes about fifteen minutes per account to set up. If the advisor recommends it, do it this week.

The NCSC also has the Cyber Essentials certification scheme, which is a practical UK government-backed standard that many businesses use as a structured framework for basic security hygiene. The consultation often naturally leads to a conversation about whether Cyber Essentials is a sensible next step — and for businesses that do any work for UK public sector clients, it’s increasingly expected rather than optional.

The free consultation isn’t a complete solution, but for a business that’s never had proper security advice, it’s a genuinely useful way to get oriented. Thirty minutes of impartial expert time is more than most small businesses have ever had. Use it.