Cyber Security
Cyber security for small businesses: why it matters and where to start
Why UK small businesses are attacked, what an incident really costs, whether yours would survive one, and the affordable controls that stop most attacks.
By Dig IT SolutionsUpdated 8 September 20267 min read
Short answer
Small businesses are attacked because automated tools do not care about company size and because SMEs are more likely to have MFA off, patching behind and untested backups. The affordable defence is the five Cyber Essentials controls plus tested backups, trained staff and a written incident plan.
If you run a business of up to 250 people, you have almost certainly been told that cyber security matters. What you may not have been told is why it applies to a firm your size, what an incident actually looks like when it happens to an accountancy practice in Hertford or a plant hire depot in Enfield, and what the sensible, affordable response is. This article covers all three, and ends with the questions that tell you whether your business would come through an attack.
Small businesses are targets because they are reachable
The most common objection is "nobody would bother attacking us". It misunderstands how attacks work. Very few attackers pick a target and study it. Most run automated tools: scanners that probe every internet address for open remote desktop ports, scripts that try millions of leaked email and password pairs against Microsoft 365, and phishing campaigns sent to every address in a purchased list. Your business is on those lists. Whether the attempt succeeds depends on whether the basics were in place.
The UK government's Cyber Security Breaches Survey has found for several consecutive years that a large share of UK businesses identify a cyber attack or breach in any twelve-month period, that phishing is by far the most common form, and that smaller businesses are less likely than large ones to have formal policies, risk assessments or staff training. That combination, high exposure and lower preparedness, is why SMEs make up a large share of successful attacks.
The four incidents that actually happen to SMEs
Ignore the exotic threats. In practice, four scenarios account for most of the damage we see in businesses across Hertfordshire, Essex and London.
Mailbox takeover leading to invoice fraud. A member of staff enters their password on a fake Microsoft page. The attacker logs in, creates a rule to hide their activity, reads six months of invoices and then emails your customers with "updated bank details". The first you hear of it is a customer asking why their payment has not been acknowledged. No malware, no alarm, and a bank that may not refund the loss.
Ransomware. An unpatched remote access system or a phished credential gives the attacker a foothold. They spend days quietly mapping your network and copying data, then encrypt every server and workstation at once, including any backups they can reach. You then face a choice between paying criminals and rebuilding from whatever survived. The NCSC's ransomware guidance sets out why paying is unreliable and how to prepare so you never have to consider it.
Credential stuffing. A staff member reused their work password on a shopping site that was breached. Without MFA, that password now opens your Microsoft 365, your remote access and possibly your accounts package.
The insider or ex-employee. Usually not malicious: a leaver whose accounts were never disabled, a shared password that never changed, company files that stayed on a personal phone. Occasionally it is deliberate. Either way it is a breach the business must explain. See our offboarding checklist.
What an incident costs a business your size
Survey data shows a skewed picture: most identified attacks cost nothing because they are blocked, and the minority that succeed cost a great deal. For an SME, the bill is made up of things that rarely appear in headline figures.
- Downtime. Days, sometimes weeks, with no email, no files, no line-of-business system. Staff paid to wait.
- Direct loss. A fraudulent payment of five figures is common, six is not unusual for firms handling client money.
- Recovery. Rebuilding servers, resetting every account, forensic work, overtime.
- Regulatory. If personal data was involved, a report to the ICO within 72 hours, possible investigation, and the obligation to tell affected individuals.
- Commercial. Customers who receive fraudulent emails from your domain, contracts with security clauses you have now breached, insurers who decline a claim because the questionnaire was answered optimistically.
- Management time. Directors spending a month on the incident instead of the business.
Set against that, the monthly cost of MFA (free with Microsoft 365), endpoint detection and response, managed patching and a backup with an offline copy is small. That is the whole argument for prevention, and it holds at any company size.
Would your business survive an attack? Ten questions
Answer these honestly. Each "no" is a gap that turns a contained incident into a serious one.
- Is multi-factor authentication enforced for every user on email, remote access and cloud systems, with no exceptions for directors?
- Are all accounts belonging to people who have left disabled, in every system?
- Is every device, server and firewall patched within 14 days of a critical update, and can someone show you a report?
- Is anything running Windows 10 or another unsupported operating system?
- Does every device run managed endpoint protection, with a person responsible for the alerts?
- Is remote desktop closed to the internet, with remote access via VPN or a secured gateway?
- Is there a backup copy that an attacker holding your administrator password could not delete or encrypt, including Microsoft 365 data?
- When did you last restore a whole server from backup, and how long did it take?
- Do staff know how to spot phishing, and is there a written rule that bank-detail changes are verified by phone?
- Is there a written incident plan naming who to call, what to preserve and who decides on ICO reporting?
Fewer than seven "yes" answers means the business is relying on luck. Our self-assessment guide walks through each area in detail.
The affordable defence: five controls plus three habits
The NCSC designed Cyber Essentials specifically so that organisations without security teams could stop the common attacks above. Its five technical controls are the right place for any SME to start.
| Control | What it stops | Typical SME action |
|---|---|---|
| User access control | Stolen passwords, ex-staff access | MFA enforced, named accounts, quarterly access review, leaver process |
| Security update management | Exploited known flaws, ransomware entry | Managed patching with reporting, unsupported systems replaced |
| Malware protection | Malicious attachments, ransomware execution | EDR on every device, no local admin rights |
| Secure configuration | Default passwords, exposed services | Device baseline, Microsoft 365 hardening, encryption on |
| Firewalls | Direct attacks, open remote desktop | Supported firewall, nothing exposed, VPN with MFA |
Then add the three things Cyber Essentials leaves out:
- Tested backups following the 3-2-1 principle with an offline or immutable copy, covering servers and Microsoft 365. See backup and disaster recovery.
- Trained people. Short, regular awareness sessions and simulated phishing, backed by a bank-detail verification rule. Our staff checklist is a starting point.
- A written policy and incident plan, so that decisions are made in advance rather than at midnight.
Certification is worth pursuing once the controls are in place. It costs from a few hundred pounds, insurers and larger customers increasingly ask for it, and it is required for many public-sector contracts. Our guide to what Cyber Essentials is explains the process.
Cyber security as a business enabler
There is a positive side that is easy to miss. Businesses with the controls above can bid for contracts that require Cyber Essentials. They complete insurer questionnaires honestly and get cover at sensible premiums. They pass the supplier security reviews that larger customers now run. They adopt hybrid working, cloud systems and new tools without each one becoming a new hole. And when a client asks "how do you protect our data?", they have an answer.
For firms in regulated or trust-based sectors, such as law firms, accountants and healthcare practices, that answer is increasingly a condition of doing business at all.
Doing it with limited time and budget
Most SMEs do not have anyone whose job is security, and that is fine provided someone accountable is doing the work. The practical model for a business of up to 250 people is a managed IT partner who delivers the five controls as standard, monitors the alerts, tests the backups and prepares you for certification, with the directors owning the policy and the culture. Our Mr Plant Hire case study shows what that looks like across multiple depots: EDR on every device, managed patching, secure site-to-site links and local plus cloud backup, all run by one accountable team.
The sequence that works: assess against the five controls, fix MFA and leaver accounts in the first week, patching and exposed services in the first month, backups and EDR alongside, then training, policy and certification. Then keep it running, because security decays without maintenance.
What to do next
If you answered "no" or "not sure" to any of the ten questions above, find out for certain before an attacker does. An IT health check reviews accounts, patching, endpoint protection, firewalls and backups against the five controls and gives you a prioritised list in plain English.

