5 IT Compliance Mistakes That Get UK SMBs Fined

Aug 26, 2026By Emanuele Acierno

EA

For small businesses in regulated sectors (law firms, healthcare practices, recruitment agencies )an IT compliance gap isn't just a security risk, it's a fine waiting to happen. The ICO has shown it doesn't discriminate by company size. Here are five mistakes that show up again and again in enforcement notices, and how to fix them.

1. No Multi-Factor Authentication (MFA)

The ICO now treats MFA as a baseline expectation under UK GDPR's "appropriate technical measures" requirement (Article 32). If an account is breached and MFA wasn't enabled, that alone can be cited as a failure, regardless of how the attacker got in.

Fix: Enable MFA on email, VPN, and any system holding personal data. It's free on most Microsoft 365 and Google Workspace plans.

2. Running Unsupported or End-of-Life Software

Windows 7 machines, outdated servers, unpatched line-of-business apps, once a vendor stops issuing security updates, every known vulnerability stays open permanently. Regulators view this as a foreseeable, avoidable risk.

Fix: Keep an inventory of what's running and its support end date. Budget for replacement before it goes end-of-life, not after.

3. No Data Processing Agreements With Third Parties

If a cloud CRM, payroll provider, or backup service processes personal data on your behalf, UK GDPR requires a signed Data Processing Agreement (DPA) in place. Many SMBs never ask their vendors for one.

Fix: Audit every third-party tool that touches client or staff data, and request a DPA from each provider.

4. No Documented Incident Response Plan

UK GDPR requires notifiable breaches to be reported to the ICO within 72 hours. Without a plan, most businesses miss that window simply because nobody knew who was responsible for what.

Fix: Write down who does what in a breach: who investigates, who notifies the ICO, who tells affected clients. A one-page plan is enough, as long as it exists.

5. No Staff Cybersecurity Training

Human error ( a clicked phishing link, a password reused across systems ) is behind the majority of breaches the ICO investigates. "We didn't train our staff" is not a defence.

Fix: Run basic phishing-awareness training annually, at minimum. Even a 30-minute session measurably reduces click-through rates.


None of these fixes require a large budget,they require someone to own them. If you're not sure where your business stands on any of the five, Blackgate Tech offers a free IT compliance check for London SMBs. [Get in touch to book one.]