Most surveying practices operate without dedicated IT staff. Cyber security decisions often sit with directors, office managers or partners, alongside many other responsibilities. This is not a weakness in itself. The real risk arises when cyber security becomes implicit rather than intentional.
The Federation of Small Businesses notes that smaller organisations face particular challenges: “Small firms are often targeted because attackers know there is less time, money and expertise available to respond.”
For surveyors, that is not a reason for alarm. It is a reason for clarity.
What “Proportionate Security” Actually Looks Like
Effective cyber security in a small practice is not about complexity. It is about consistency.
For most firms, proportionate protection means focusing on a small number of fundamentals:
Secure access to email and cloud systems
Devices that update automatically
Reliable, tested backups
Staff who recognise suspicious emails
Multi factor authentication enabled by default
The National Cyber Security Centre states in its Small Business Guide: “You can reduce the likelihood and impact of a cyber incident by taking simple steps.”
That is the model. Simple, controlled, repeatable.
Where Firms Often Overcomplicate Things
Small practices are frequently sold tools designed for much larger organisations – platforms that are expensive, difficult to manage and ultimately underused.
Cyber security should fit the way surveyors work: mobile, deadline driven and client focused. If a system is too complex to maintain, it becomes a risk rather than a safeguard.
Under UK GDPR, responsibility cannot be outsourced. As the Information Commissioner’s Office makes clear in its guidance on controllers that i f you are a controller, you are responsible for ensuring your processing – including any processing carried out by a processor on your behalf.
Tools can support you. Accountability remains with you.
Why This Matters for Surveyors
Surveying practices depend on digital systems to deliver professional services. A cyber incident does not just affect IT. It affects:
Professional obligations
Client confidence
Pipeline continuity
Regulatory exposure
The goal is not perfection. It is resilience.
Small firms do not need enterprise security architecture. They need ownership, prioritisation and simple controls that work reliably.
Practical Steps to Review This Quarter
Identify your most critical systems and data
Confirm who is responsible for cyber oversight
Enable multi factor authentication and password management
Test backups rather than assuming they work
Make it easy for staff to report concerns early
Cyber security is not about technology spend. It is about leadership attention.
And in small practices, leadership attention makes all the difference.
Continue Reading
Browse more blog posts, features and practical guides covering industry developments, operational strategy and technology for surveyors.








