The NCSC announced on 15 July 2026 that UK small businesses can now book free 30-minute cyber security consultations with accredited Cyber Advisors. No catch, no sales pitch, no obligation to buy anything. The aim is to give small business owners practical, personalised guidance on the basics — the stuff that actually prevents most attacks — from someone who knows what they’re talking about.

If you’ve been meaning to get a proper look at your business’s security posture but never quite got round to it (and honestly, who has?), this is a low-effort way to do exactly that.

What the Consultations Actually Cover

The sessions are delivered by NCSC-accredited Cyber Advisors — independent consultants and IT professionals who’ve been vetted and trained by the NCSC to deliver guidance aligned with the Cyber Essentials framework. They’re not there to sell you a product or an ongoing contract. The conversation covers your specific situation.

Based on the NCSC’s published scope, topics include: password management practices across the business, software update habits, backup configurations, how staff recognise phishing attempts, and basic access control (who has admin rights, how accounts are managed when staff leave). These are consistently the areas where small businesses have gaps, and where fixing them prevents the majority of incidents.

The sessions aren’t a full security audit — you won’t walk away with a penetration test report or a 50-page risk assessment. What you do get is an expert set of eyes on your current setup and specific, prioritised actions you can take without needing a dedicated IT team.

Why the Timing Matters

The launch coincides with a notable shift in the threat landscape affecting UK SMEs. Research published the same week showed that identity-based attacks — credential theft and phishing rather than software vulnerabilities — have overtaken unpatched software as the most common way ransomware gets into small businesses. That’s a meaningful shift, because it means the defences matter most are behavioural and configuration-based, not about buying expensive security tools.

The NCSC’s guidance on this is consistent with what the free consultations address. Good password management, phishing-resistant MFA where it’s supported, regular backups to offline or immutable storage, and making sure staff know what a phishing attempt looks like — these aren’t glamorous controls, but they’re the ones that would have prevented a significant proportion of the ransomware incidents the NCSC handled in 2025.

There’s also the router targeting issue worth knowing about. The NCSC issued a warning earlier this month about a Russian state-linked group (APT28) actively exploiting routers in small office environments — the kind of consumer-grade routers many small businesses run without giving them much thought. The free consultations are a good opportunity to get eyes on whether your network setup has obvious gaps there.

How to Access a Consultation

The consultations are accessed through the NCSC’s Cyber Advisor scheme. You can find the scheme and book through the NCSC website (ncsc.gov.uk). Advisors are geographically spread across the UK, and sessions can be delivered virtually, which means location isn’t a barrier.

Availability is limited — demand has been high since the announcement — so if you want a session, it’s worth booking sooner rather than assuming you can slot one in whenever. The scheme is designed for businesses with no in-house security expertise, which in practice covers most sole traders, partnerships, and small limited companies. If you have a dedicated IT provider or a security team, you’re probably not the target audience.

For businesses that want to go beyond the free consultation, the Cyber Advisor can talk you through what a Cyber Essentials certification involves and whether it makes sense for your situation. Cyber Essentials costs less than £500 for the self-assessment route and gives you a certification badge, cyber insurance cover (up to £25,000 for qualifying businesses), and eligibility for UK government contracts.

Don’t Wait for a Perfect Time

Here’s the honest version: small businesses consistently put security off because it feels like something that doesn’t need doing until something goes wrong. The NCSC offering free advice doesn’t change the underlying reality of the threats, but it does remove the cost barrier that often stops people from getting started.

The 30-minute format is deliberately low-commitment. You don’t need to prepare anything elaborate. Turn up, describe how your business works and what technology you use, and ask the questions you’ve been meaning to ask. The Cyber Advisor will give you a sense of where you’re exposed and what matters most to fix first.

That prioritisation is actually the hard part of small business security — knowing which of the fifteen things you could do actually prevents the most risk. Getting that answer from someone qualified to give it, for free, in half an hour, is a reasonable use of a lunchtime.

The scheme is aimed at smaller organisations in all sectors — retail, hospitality, professional services, construction, tradespeople, charities. If you’re reading this and you’re not sure whether your business is “technical enough” to benefit, that uncertainty is itself a reason to book. That’s exactly the situation the consultations are designed for.