You have probably seen a website with "Not Secure" sitting next to its address, and you may have wondered whether a customer would ever see that on yours. If your store is on Shopify, or on a properly managed WooCommerce host, they will not. That particular problem was solved years ago and is now largely confined to neglected sites.
Which raises the more useful question. If the padlock is fine and the obvious box is ticked, what should a UK store owner be paying attention to?
The answer is less dramatic than the security industry would have you believe, and more administrative. Here is what matters most, who is responsible for what, and the one legal duty that arrived last month which most store owners have not heard about.
What really gets UK stores into trouble?
Start with a fact that reframes the whole subject. Looking at the Information Commissioner's Office enforcement record across 2025 and the first half of 2026, no UK online retailer was fined for a data breach. Not one.
What the ICO did issue, repeatedly, was fines to small companies and sole traders over marketing: unwanted emails, texts and calls, and cookie banners that did not give people a real choice. That is where UK businesses of your size are losing money to the regulator, and it has nothing to do with hackers.
That is worth knowing before you spend anything on security, because it tells you the real risk profile. For most established stores the genuine threats, in order, are a compromised account, out-of-date software, and marketing practices that quietly break rules nobody explained.
It does not mean breaches do not matter. The government's Cyber Security Breaches Survey 2025/2026, published in April 2026, found 43% of UK businesses identified a breach or attack in the previous twelve months, rising to 46% of small businesses, with phishing the most common by a distance at 38%. The point is that the thing most likely to hurt you is ordinary rather than exotic.
Which security basics matter most?
The measures that prevent most real incidents are unglamorous and largely free.
- Two-factor authentication on every account that can change your store. This single control prevents the majority of account compromises. It matters most on the accounts people forget: an old admin login, a developer's account, the email address your password resets go to.
- Remove access nobody needs. Former staff, former agencies, apps you trialled once. Every account that still works is a door that still opens.
- Keep things current. On Shopify the platform handles this for you. On self-hosted WooCommerce it is your responsibility, and an out-of-date plugin is the single most common way those stores are compromised.
- Know which apps can see your customer data. Every app you install is a supplier with access. Review the list occasionally and remove what you no longer use.
- Back up, and check the backup works. An untested backup is a promise nobody has verified.
The reason to take the first point seriously is a case worth knowing about. In April 2025 the ICO fined a Merseyside law firm £60,000 after a cyber attack. The route in was an infrequently used administrator account without two-factor authentication. The firm was a genuine victim of crime, and it was still fined, partly because it took 43 days to report the incident.
That is the useful lesson for any owner. Being attacked is not a defence in itself. What the regulator looks at is whether you had taken reasonable care beforehand and what you did afterwards.
Who is responsible for card payments?
This is the question owners are most often given a wrong answer to, in both directions.
Card security is governed by PCI DSS, currently version 4.0.1. Two things about it are commonly misunderstood. It is not UK law: it reaches you through your agreement with your payment provider, so it is contractual. But it is not irrelevant to the law either, because if card data is ever exposed, the ICO will consider how far you met it when deciding whether your security was appropriate.
What that means in practice depends on how your store takes payment.
| Setup | Handled for you | Still yours |
|---|---|---|
| Shopify with Shopify Payments | The checkout, card handling and the platform's own certification | Account access, staff permissions, apps, and never storing card details yourself |
| Self-hosted WooCommerce | Whatever your payment gateway covers | Hosting, security updates, access control, and regular scanning |
The fair summary for a Shopify store is that the platform does the heavy lifting at the checkout, while the account, your staff, your apps and your data hygiene remain yours. For a self-hosted WooCommerce store, materially more sits with you, which is worth knowing before choosing a platform rather than after.
One rule applies to everyone regardless of platform: never store card numbers yourself, in a spreadsheet, an email, a CRM note or anywhere else. If a customer emails you their card details, delete it rather than filing it.
What does UK law ask of you?
Three things, and the third one is new enough that most store owners have missed it.
Keep customer data secure and only keep what you need. UK GDPR still applies and still goes by that name. The Data (Use and Access) Act 2025 amended it rather than replacing it, so anyone telling you the rules have been swept away is mistaken.
Get cookies and marketing right. As established above, this is where small UK businesses get fined. Analytics cookies now have a limited exception, but only where people are given a simple way to object, and advertising cookies never qualify. Our guide to website legal requirements for UK businesses covers the detail.
Have a complaints process, which is a new duty since 19 June 2026. Every UK organisation must now give people a clear way to raise a data protection complaint, acknowledge it within 30 days, investigate it properly, and tell the person the outcome. ICO research found that more than two in three businesses aware of the Act either do not know or wrongly believe the change does not apply to them, which makes this the most widely missed obligation in the list.
For most stores, complying is a small job: a named route for complaints, a note of when each one arrives, and a habit of responding inside the month. It is far easier to set up now than to improvise while someone is already unhappy.
Worth adding, because the subject attracts alarmism: the ICO's own published position toward smaller organisations is supportive rather than punitive. As their Deputy Commissioner put it in May 2026, "we are not here to catch businesses out, we are here to help you get ready."
What should you do if something does go wrong?
Knowing this in advance is worth more than any tool, because the mistakes that make an incident worse are nearly always made in the first two days.
The clock is 72 hours, and it starts when you become aware. Not when the incident happened. If a personal data breach is likely to present a risk to the people affected, you must report it to the ICO within that window, and if you are late you have to explain why.
Telling your customers is a separate, higher test. You notify the ICO where there is a risk. You tell the affected individuals where there is a high risk to them. The two are not the same decision, and the ICO has a short self-assessment tool that will walk you through both.
There are three separate places to report, and one report does not cover the others. The ICO for the legal duty, Report Fraud for the crime, and the National Cyber Security Centre for significant incidents. Note that Action Fraud was replaced by Report Fraud, so older guidance you find online may send you to the wrong place.
One more thing that helps. The ICO treats proactive engagement with the NCSC as a mitigating factor, and it has explicitly reduced a fine on those grounds. Certification such as Cyber Essentials is also recognised. Doing the sensible thing is not merely virtuous, it counts in your favour.
Why this is an ongoing job rather than a one-off
Two figures make the argument better than any warning could.
The first is uncomfortable and comes from the government's own survey: UK small businesses went backwards on security during 2025. Businesses carrying out risk assessments fell from 48% to 41%, those with formal cyber security policies from 59% to 52%, and those with business continuity plans from 53% to 44%. Retail fares worse than average on governance, with only 20% of retail and wholesale businesses having board-level responsibility for cyber, against 31% across all businesses.
The second is what it costs when it goes badly. Marks and Spencer's audited full-year results, published in May 2026, put the costs of its cyber incident at £131.3 million, against £100.0 million recovered from insurance. You are not M&S, and your exposure is nothing like that, but the shape of the lesson holds: the disruption and the loss of trust cost more than the incident itself.
Trust is the part that touches revenue directly. Baymard Institute's research into checkout abandonment, drawn from fifty studies, found that 19% of shoppers who abandon a checkout do so because they did not trust the site with their card details. Security is not only a compliance subject. It is part of whether people buy from you.
None of this requires a large budget. It requires that somebody owns it: that two-factor is on, that updates happen, that access is reviewed when people leave, and that someone would know what to do in the first hour if it went wrong. For most stores that is a modest ongoing habit rather than a project, and it is the sort of thing our growth retainers exist to take off a business's plate.
A short checklist worth running this month
- Two-factor authentication on every account that can change the store, including the email behind it
- Access removed for anyone who has left, and every app you no longer use
- Software and plugins current, with someone named as responsible for keeping them so
- No card details stored anywhere in your business
- A written route for data protection complaints, acknowledged within 30 days
- A cookie banner that lets people refuse as easily as accept
- One person who knows the 72-hour rule and where to report
If most of those are already true, your store is in better shape than the survey averages suggest.
Building or replatforming a store?
Security is far cheaper to design in than to retrofit. If you are planning a new store or moving platform and want it set up properly from the start, get in touch, or see how we approach ecommerce web design and Shopify builds.
Sources
- DSIT: Cyber Security Breaches Survey 2025/2026
- ICO: New data protection complaints law now in force
- ICO: Personal data breaches, a guide
- ICO: Law firm fined £60,000 following cyber attack
- Marks and Spencer: Full year results, 52 weeks ended 28 March 2026
- Baymard Institute: Cart abandonment rate research
Get in touch - we're happy to chat.



