Skip to main content
Dig IT Solutions logo

Cyber Security

Cyber security for small businesses: why it matters and where to start

Why UK small businesses are attacked, what an incident really costs, whether yours would survive one, and the affordable controls that stop most attacks.

By Dig IT SolutionsUpdated 8 September 20267 min read

Short answer

Small businesses are attacked because automated tools do not care about company size and because SMEs are more likely to have MFA off, patching behind and untested backups. The affordable defence is the five Cyber Essentials controls plus tested backups, trained staff and a written incident plan.

If you run a business of up to 250 people, you have almost certainly been told that cyber security matters. What you may not have been told is why it applies to a firm your size, what an incident actually looks like when it happens to an accountancy practice in Hertford or a plant hire depot in Enfield, and what the sensible, affordable response is. This article covers all three, and ends with the questions that tell you whether your business would come through an attack.

Small businesses are targets because they are reachable

The most common objection is "nobody would bother attacking us". It misunderstands how attacks work. Very few attackers pick a target and study it. Most run automated tools: scanners that probe every internet address for open remote desktop ports, scripts that try millions of leaked email and password pairs against Microsoft 365, and phishing campaigns sent to every address in a purchased list. Your business is on those lists. Whether the attempt succeeds depends on whether the basics were in place.

The UK government's Cyber Security Breaches Survey has found for several consecutive years that a large share of UK businesses identify a cyber attack or breach in any twelve-month period, that phishing is by far the most common form, and that smaller businesses are less likely than large ones to have formal policies, risk assessments or staff training. That combination, high exposure and lower preparedness, is why SMEs make up a large share of successful attacks.

The four incidents that actually happen to SMEs

Ignore the exotic threats. In practice, four scenarios account for most of the damage we see in businesses across Hertfordshire, Essex and London.

Mailbox takeover leading to invoice fraud. A member of staff enters their password on a fake Microsoft page. The attacker logs in, creates a rule to hide their activity, reads six months of invoices and then emails your customers with "updated bank details". The first you hear of it is a customer asking why their payment has not been acknowledged. No malware, no alarm, and a bank that may not refund the loss.

Ransomware. An unpatched remote access system or a phished credential gives the attacker a foothold. They spend days quietly mapping your network and copying data, then encrypt every server and workstation at once, including any backups they can reach. You then face a choice between paying criminals and rebuilding from whatever survived. The NCSC's ransomware guidance sets out why paying is unreliable and how to prepare so you never have to consider it.

Credential stuffing. A staff member reused their work password on a shopping site that was breached. Without MFA, that password now opens your Microsoft 365, your remote access and possibly your accounts package.

The insider or ex-employee. Usually not malicious: a leaver whose accounts were never disabled, a shared password that never changed, company files that stayed on a personal phone. Occasionally it is deliberate. Either way it is a breach the business must explain. See our offboarding checklist.

What an incident costs a business your size

Survey data shows a skewed picture: most identified attacks cost nothing because they are blocked, and the minority that succeed cost a great deal. For an SME, the bill is made up of things that rarely appear in headline figures.

  • Downtime. Days, sometimes weeks, with no email, no files, no line-of-business system. Staff paid to wait.
  • Direct loss. A fraudulent payment of five figures is common, six is not unusual for firms handling client money.
  • Recovery. Rebuilding servers, resetting every account, forensic work, overtime.
  • Regulatory. If personal data was involved, a report to the ICO within 72 hours, possible investigation, and the obligation to tell affected individuals.
  • Commercial. Customers who receive fraudulent emails from your domain, contracts with security clauses you have now breached, insurers who decline a claim because the questionnaire was answered optimistically.
  • Management time. Directors spending a month on the incident instead of the business.

Set against that, the monthly cost of MFA (free with Microsoft 365), endpoint detection and response, managed patching and a backup with an offline copy is small. That is the whole argument for prevention, and it holds at any company size.

Would your business survive an attack? Ten questions

Answer these honestly. Each "no" is a gap that turns a contained incident into a serious one.

  1. Is multi-factor authentication enforced for every user on email, remote access and cloud systems, with no exceptions for directors?
  2. Are all accounts belonging to people who have left disabled, in every system?
  3. Is every device, server and firewall patched within 14 days of a critical update, and can someone show you a report?
  4. Is anything running Windows 10 or another unsupported operating system?
  5. Does every device run managed endpoint protection, with a person responsible for the alerts?
  6. Is remote desktop closed to the internet, with remote access via VPN or a secured gateway?
  7. Is there a backup copy that an attacker holding your administrator password could not delete or encrypt, including Microsoft 365 data?
  8. When did you last restore a whole server from backup, and how long did it take?
  9. Do staff know how to spot phishing, and is there a written rule that bank-detail changes are verified by phone?
  10. Is there a written incident plan naming who to call, what to preserve and who decides on ICO reporting?

Fewer than seven "yes" answers means the business is relying on luck. Our self-assessment guide walks through each area in detail.

The affordable defence: five controls plus three habits

The NCSC designed Cyber Essentials specifically so that organisations without security teams could stop the common attacks above. Its five technical controls are the right place for any SME to start.

ControlWhat it stopsTypical SME action
User access controlStolen passwords, ex-staff accessMFA enforced, named accounts, quarterly access review, leaver process
Security update managementExploited known flaws, ransomware entryManaged patching with reporting, unsupported systems replaced
Malware protectionMalicious attachments, ransomware executionEDR on every device, no local admin rights
Secure configurationDefault passwords, exposed servicesDevice baseline, Microsoft 365 hardening, encryption on
FirewallsDirect attacks, open remote desktopSupported firewall, nothing exposed, VPN with MFA

Then add the three things Cyber Essentials leaves out:

  • Tested backups following the 3-2-1 principle with an offline or immutable copy, covering servers and Microsoft 365. See backup and disaster recovery.
  • Trained people. Short, regular awareness sessions and simulated phishing, backed by a bank-detail verification rule. Our staff checklist is a starting point.
  • A written policy and incident plan, so that decisions are made in advance rather than at midnight.

Certification is worth pursuing once the controls are in place. It costs from a few hundred pounds, insurers and larger customers increasingly ask for it, and it is required for many public-sector contracts. Our guide to what Cyber Essentials is explains the process.

Cyber security as a business enabler

There is a positive side that is easy to miss. Businesses with the controls above can bid for contracts that require Cyber Essentials. They complete insurer questionnaires honestly and get cover at sensible premiums. They pass the supplier security reviews that larger customers now run. They adopt hybrid working, cloud systems and new tools without each one becoming a new hole. And when a client asks "how do you protect our data?", they have an answer.

For firms in regulated or trust-based sectors, such as law firms, accountants and healthcare practices, that answer is increasingly a condition of doing business at all.

Doing it with limited time and budget

Most SMEs do not have anyone whose job is security, and that is fine provided someone accountable is doing the work. The practical model for a business of up to 250 people is a managed IT partner who delivers the five controls as standard, monitors the alerts, tests the backups and prepares you for certification, with the directors owning the policy and the culture. Our Mr Plant Hire case study shows what that looks like across multiple depots: EDR on every device, managed patching, secure site-to-site links and local plus cloud backup, all run by one accountable team.

The sequence that works: assess against the five controls, fix MFA and leaver accounts in the first week, patching and exposed services in the first month, backups and EDR alongside, then training, policy and certification. Then keep it running, because security decays without maintenance.

What to do next

If you answered "no" or "not sure" to any of the ten questions above, find out for certain before an attacker does. An IT health check reviews accounts, patching, endpoint protection, firewalls and backups against the five controls and gives you a prioritised list in plain English.

Frequently asked questions

Why would attackers target a small business rather than a large one?
Mostly they do not choose. Attackers run automated tools that scan the internet for exposed services, try leaked passwords against every Microsoft 365 tenant and send phishing to any address they can buy. A small business is hit because it is reachable, and it is breached because the basics such as MFA, patching and offline backups were missing more often than in large firms.
What is the most common cyber attack on UK small businesses?
Phishing. The government's Cyber Security Breaches Survey finds it is the attack type reported by the large majority of businesses that experience any breach. It is usually the first step towards the more damaging outcomes: invoice fraud from a compromised mailbox, stolen credentials, and ransomware.
How much does a cyber attack cost a small business?
The survey data shows most incidents cost little because they are caught early, while the minority that succeed cost a great deal. For an SME the real figures are days of downtime, a fraudulent payment the bank may not refund, recovery work, possible ICO involvement and lost customers. Compare that with the modest monthly cost of MFA, EDR and proper backups.
How can I tell if my business has already been compromised?
Warning signs include sign-in alerts from unfamiliar locations, mailbox rules you did not create, customers or suppliers receiving odd emails from your domain, unexpected MFA prompts, accounts locked out, files renamed or inaccessible, and security software switched off. If you see any of these, disconnect the affected device and call your IT provider before doing anything else.
Is cyber security expensive for a small business?
The fundamentals are not. MFA is free with Microsoft 365, EDR and managed patching are priced per device, and a backup with an offline copy costs less than a day of downtime. Cyber Essentials certification starts from a few hundred pounds. The expensive part of cyber security is recovering from an incident you were not prepared for.
What is the first step a small business should take?
Find out where you stand. An assessment against the five Cyber Essentials controls (access control and MFA, patching, malware protection, secure configuration, firewalls) plus a backup restore test will show the gaps in an afternoon. Fix MFA and leaver accounts first, then patching and backups, then training and policy.

Next step

Not sure how exposed you are?

An IT health check reviews your security, backups, Microsoft 365 and network and gives you a prioritised list, whether or not you work with us afterwards.

WhatsApp us