Skip to content
Uncategorized

Cyber Security Risks Facing UK Small Businesses

Cyber Security Risks Facing UK Small Businesses
Get Lifetime Access

For a small business, cyber security can be easy to postpone. There are customers to serve, invoices to send, employees to manage and cash flow to monitor. Cybersecurity may appear to be something that matters primarily to banks, technology companies and large corporations with valuable databases.

Current evidence shows otherwise.

Understanding cyber security risks is increasingly important for smaller organisations because they rely on many of the same technologies as large businesses: email, online banking, cloud storage, websites, accounting platforms, payment systems and customer databases.

The Government’s cyber security risks Breaches Survey 2025/2026 found that 46% of small UK businesses identified a cyber breach or attack during the previous 12 months. That does not mean almost half suffered catastrophic damage, but it demonstrates that attacks against smaller organisations are far from unusual.

The most important risks include phishing, account takeover, ransomware, stolen passwords, unpatched systems, supplier weaknesses and accidental data breaches.

The encouraging news is that good SME security UK practice does not necessarily require a large internal security department. Some of the most effective protections involve basic controls implemented consistently: multi-factor authentication, secure accounts, software updates, reliable backups, sensible access permissions and staff who know how to recognise suspicious activity.

This guide examines the main threats facing UK small businesses and explains how organisations can reduce their exposure.

Why Are Small Businesses Targeted by Cyber Criminals?

cyber security risks criminals do not always select victims because of their size or fame. Many attacks are automated, meaning they are carried out systematically, repeatedly and at scale.

Attackers can send fraudulent emails to thousands of addresses, scan the internet for exposed systems or try stolen usernames and passwords across large numbers of online services.

A small company can therefore become a victim simply because:

  • an employee clicks a phishing link;
  • a password has already been stolen elsewhere;
  • software has not been updated;
  • an online account lacks multi-factor authentication;
  • a supplier is compromised;
  • a device is lost or stolen; or
  • an attacker discovers an exposed service.

The NCSC’s small-business guidance specifically warns organisations against assuming they are too small to attract cyber security risks crime. Small companies may also be attractive because attackers expect security controls to be less developed, weaker or less mature.

The Government’s latest survey found that only 41% of small businesses had undertaken a cyber security risk assessment, down from 48% in the previous survey. Only 52% had a formal policy covering cyber security risks, while 44% had a business continuity plan covering cyber security.

That leaves significant room for improvement in cyber protection, security preparedness and organisational resilience.

The Biggest Cyber Security Risks for UK Small Businesses

1. Phishing

Phishing remains the most widespread cyber threat encountered by businesses. Phishing is a form of online deception, fraud or social engineering designed to persuade someone to:

  • disclose a password;
  • enter credentials into a fake website;
  • open a malicious attachment;
  • transfer money;
  • provide confidential information; or
  • approve a fraudulent request.

The message might imitate:

  • Microsoft;
  • a bank;
  • HMRC;
  • a supplier;
  • a delivery company;
  • a senior manager; or
  • another employee.

The latest Government survey found phishing attacks were identified by 38% of businesses overall, while 40% of small businesses reported phishing.

Why Phishing Works

Modern phishing messages are not necessarily badly written emails promising impossible prizes. They may use:

  • copied logos;
  • convincing email addresses;
  • realistic invoices;
  • information gathered from social media;
  • compromised supplier accounts; and
  • AI-assisted language.

The NCSC has warned that threat actors are already using artificial intelligence to improve existing attack methods, including social engineering.

Employees therefore need to assess the context, legitimacy and authenticity of a message rather than relying on spelling mistakes as the main warning sign.

2. Business Email Compromise and Impersonation

One particularly damaging form of business hacking UK companies may encounter involves the compromise or imitation of business email.

An attacker may pretend to be:

  • the managing director;
  • a supplier;
  • a customer;
  • an accountant; or
  • another trusted contact.

The criminal then requests a payment, bank-detail change or confidential information.

Imagine a small construction company regularly paying a supplier £20,000. An attacker compromises an email account and sends:

“Our bank details have changed. Please use this account for this month’s invoice.”

If the business follows the instruction without independent verification, the money could be transferred directly to the criminal.

Reduce the Risk

Businesses can introduce procedures requiring employees to verify significant changes in payment information through a known contact method.

Do not verify a suspicious email by replying to the same message or calling a telephone number provided in it. Use contact details already held independently.

This simple verification process can reduce the risk of fraud, impersonation and unauthorised payments.

3. Weak and Reused Passwords

Passwords remain a major weakness because employees often have many online accounts.

Reusing the same password across several platforms creates particular risk. Suppose an employee uses the same password for:

  • personal shopping;
  • business email; and
  • cloud storage.

If the shopping service suffers a breach and those credentials become available to criminals, attackers may try the same email and password elsewhere. This is sometimes called credential stuffing.

Better Password Security

NCSC guidance supports strong account protection and encourages modern authentication measures.

Small businesses should consider:

  • unique passwords;
  • password managers;
  • multi-factor authentication;
  • removing accounts that are no longer required; and
  • promptly disabling access when employees leave.

Accounts with access to email, banking, payroll, cloud storage and administrative systems deserve particular protection.

4. Missing Multi-Factor Authentication

Multi-factor authentication, or MFA, requires an additional verification step beyond a password.

This might involve:

  • an authentication application;
  • a hardware security key;
  • a passkey; or
  • another approved factor.

A stolen password is therefore less likely to be enough for an attacker to gain access.

The Government’s latest survey found that 43% of micro businesses required two-factor authentication, up from 35% previously.

That is progress, but substantial numbers of smaller organisations remain without it.

Businesses should prioritise MFA for important accounts, particularly:

  • business email;
  • cloud storage;
  • banking;
  • payroll;
  • website administration;
  • social media; and
  • finance systems.

5. Ransomware

Ransomware UK incidents can be devastating because they can prevent a business from accessing its own systems or data.

Ransomware is malicious software that typically encrypts files or otherwise makes them unavailable. Criminals then demand money, sometimes alongside threats to publish stolen information.

Modern ransomware can therefore create two problems:

  1. loss of access to systems and files; and
  2. possible theft or disclosure of information.

The NCSC continues to describe ransomware as one of the most acute cyber threats facing UK organisations.

Although only around 1% of businesses in the latest Government survey reported identifying ransomware in the previous year, low prevalence does not mean low potential impact.

A single serious incident can interrupt:

  • invoicing;
  • customer orders;
  • email;
  • payroll;
  • appointments;
  • production; and
  • access to business records.

6. Poor Backups

Backups are one of the most important protections against data loss, disruption and recovery problems.

The NCSC recommends organisations keep copies of the data needed to operate, which might include:

  • customer records;
  • invoices;
  • emails;
  • contacts;
  • documents;
  • website information; and
  • business files.

A backup is useful only if it can actually be restored.

Businesses should therefore consider:

  • what needs backing up;
  • how frequently backups occur;
  • who controls them;
  • whether attackers could also access or delete them; and
  • whether restoration has been tested.

Simply synchronising every file to the same cloud environment may not provide sufficient protection if compromised credentials allow an attacker to delete both the working files and accessible copies.

Backups should form part of a wider recovery, continuity and resilience plan.

7. Unpatched Software

Software vulnerabilities are discovered regularly.

Developers release security updates to correct them.

If businesses delay installing those updates, criminals may exploit known weaknesses.

Affected technology can include:

  • operating systems;
  • browsers;
  • website software;
  • routers;
  • business applications;
  • smartphones;
  • plugins; and
  • other connected devices.

Automatic updates should be enabled where appropriate.

Businesses should also stop relying on software that no longer receives security support.

An old application may still work perfectly from an operational perspective while becoming increasingly unsafe.

8. Malware

Malware is malicious software designed to compromise systems or information.

It can include:

  • ransomware;
  • trojans;
  • spyware;
  • viruses; and
  • other malicious programs.

Malware can arrive through:

  • phishing attachments;
  • malicious downloads;
  • compromised websites;
  • infected devices; or
  • exploited software vulnerabilities.

Modern operating systems include substantial security protections, but those protections need to be enabled, maintained and updated.

Users should not routinely have more administrative privileges than they require.

9. Excessive User Access

Giving every employee access to everything may appear convenient.

It also increases risk.

A receptionist may not need access to payroll.

A marketing contractor may not need customer financial information.

A former employee should not retain access after leaving.

This principle is often described as least privilege: people receive the access required to perform their jobs rather than unrestricted access by default.

Good access management includes:

  • individual accounts;
  • appropriate permissions;
  • regular access reviews;
  • prompt leaver procedures;
  • controlled administrator privileges; and
  • avoiding shared logins where possible.

If one account is compromised, limiting its permissions can also limit the potential damage.

10. Lost and Stolen Devices

Laptops and phones contain or provide access to valuable business information.

If an unlocked laptop is stolen, criminals may obtain:

  • emails;
  • customer details;
  • saved passwords;
  • documents; and
  • access to online services.

NCSC guidance recommends protecting business devices and paying attention to personal devices used for business activity.

Measures can include:

  • screen locks;
  • full-device encryption;
  • strong authentication;
  • remote management where appropriate;
  • software updates; and
  • the ability to revoke account access quickly.

This becomes particularly important for organisations with remote and hybrid workers.

11. Remote Working and BYOD

Bring Your Own Device arrangements can save money and provide flexibility.

They can also blur the line between business hacking UK and personal security.

A personal laptop may:

  • be shared with family;
  • lack suitable security settings;
  • run unsupported software;
  • contain unapproved applications; or
  • have weak access controls.

Businesses allowing personal devices should establish clear minimum requirements.

That might include:

  • supported operating systems;
  • screen locking;
  • encryption;
  • appropriate security software;
  • rules on business data storage; and
  • procedures when a device is lost or an employee leaves.

12. Cloud Account Compromise

Small businesses increasingly use cloud services for:

  • email;
  • documents;
  • accounting;
  • CRM;
  • payroll;
  • project management; and
  • customer information.

Cloud services can provide excellent security, but the provider cannot protect an account whose credentials are stolen and whose MFA is disabled.

Businesses should secure cloud accounts with:

  • MFA;
  • strong access controls;
  • appropriate administrator roles;
  • regular user reviews; and
  • monitoring where available.

They should also understand what security responsibilities remain with the customer rather than assuming the cloud provider handles everything.

13. Supplier and Supply-Chain Attacks

Your own security may be strong while a supplier’s is weak.

Businesses increasingly share information and system access with:

  • accountants;
  • managed IT providers;
  • software companies;
  • payroll providers;
  • marketing agencies;
  • logistics partners; and
  • other suppliers.

Attackers may compromise one organisation to reach another.

The 2025/2026 Government survey found only 22% of small businesses reviewed cyber risks associated with their immediate suppliers.

Supplier security should therefore form part of wider SME security UK planning.

Businesses can consider:

  • what information suppliers receive;
  • what system access they have;
  • how incidents must be reported;
  • how access ends when contracts finish; and
  • whether suitable cyber standards are required.

14. Insider Risk and Human Error

Not every data breach involves an outside hacker.

Employees can accidentally:

  • email information to the wrong person;
  • upload sensitive documents publicly;
  • share passwords;
  • lose devices;
  • misconfigure cloud storage; or
  • fall for fraud.

Deliberate misuse is also possible.

Technical controls should therefore be combined with procedures, access restrictions and staff awareness.

The goal should not be to distrust every employee.

It is to design systems so that one ordinary mistake does not become a major incident.

Cyber Security UK: What Do the Latest Numbers Show?

The latest Government survey provides useful perspective on cyber security UK conditions.

MeasureLatest finding
UK businesses identifying a breach/attack43%
Small businesses identifying a breach/attack46%
Small businesses experiencing cyber crime24%
Businesses identifying phishing38%
Small businesses with a formal cyber policy52%
Small businesses with cyber business-continuity plans44%
Small businesses conducting cyber risk assessments41%

These are survey estimates rather than precise counts of every attack.

Government researchers explicitly warn that unknown or undetected incidents will not appear in the statistics.

This is particularly important for small organisations that may not have sophisticated monitoring systems.

Data Protection UK and Cyber Security

Cybersecurity and data protection UK requirements overlap when an organisation holds personal information.

The UK GDPR security principle requires organisations to use appropriate technical and organisational measures to protect personal data protection UK against risks such as:

  • unauthorised access;
  • unlawful processing;
  • accidental loss;
  • destruction; and
  • damage.

The ICO explains that appropriate security depends on factors including:

  • the information involved;
  • the risks to individuals;
  • available technology;
  • cost; and
  • the nature and scale of processing.

There is therefore no single cybersecurity checklist that automatically establishes legal compliance for every business hacking UK

Encryption

The ICO identifies encryption as an important potential security measure.

Encryption may be particularly appropriate for personal information:

  • stored on laptops;
  • stored on phones;
  • stored on removable media; or
  • transferred electronically.

However, encryption alone does not satisfy every security obligation.

Businesses also need organisational measures such as access control, staff training, risk assessment and incident procedures.

GDPR Compliance UK After the Data (Use and Access) Act

Businesses searching for GDPR compliance UK advice should be aware that the legal framework has changed since many older online guides were published.

The Data (Use and Access) Act 2025 amended parts of UK data protection UK aw.

The ICO confirmed that all its data-protection provisions were in force by 19 June 2026.

However, the Act did not abolish the UK GDPR or data protection UK Protection Act 2018.

The core obligation to protect personal information appropriately remains.

An attacker controlling a business hacking UK email account may be able to:

relying on old templates or compliance material should therefore check that their information reflects current law and ICO guidance.

When Does a Cyber Attack Become a Personal Data Breach?

Not every cyber attack creates a personal data protection UK breach.

For example, an attacker might temporarily disrupt a public website without accessing personal information.

However, if customer information is:

  • accessed without authorisation;
  • stolen;
  • disclosed;
  • changed;
  • destroyed; or
  • made unavailable,

a personal data protection UK may have occurred.

Businesses need to assess the possible consequences for affected individuals.

If the breach is likely to result in a risk to people’s rights and freedoms, it generally needs to be notified to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it.

Higher-risk cases may also require affected individuals to be informed.

A business should not wait until hour 71 to begin thinking about this.

Incident-response procedures should establish in advance who assesses potential data protection UK breaches and who can make reporting decisions.

How Small Businesses Can Reduce Cyber Security Risks

Secure Email First

Email is frequently the gateway to other systems.

An attacker controlling a business hacking UK email account may be able to:

  • reset passwords elsewhere;
  • read invoices;
  • impersonate staff;
  • contact customers; and
  • study payment patterns.

Enable MFA and protect email accounts carefully.

Use MFA on Important Accounts

Priority accounts include:

  • email;
  • finance;
  • payroll;
  • cloud storage;
  • social media;
  • website administration; and
  • business banking.

Update Devices and Software

Enable automatic updates where possible.

Remove or replace unsupported software.

Back Up Essential Data

Identify the data protection UK the business cannot operate without.

Maintain reliable backups and test restoration.

Train Employees to Recognise Phishing

Training should include realistic situations, such as:

  • unexpected payment requests;
  • urgent password-reset emails;
  • QR-code scams;
  • fake Microsoft logins;
  • supplier bank-detail changes; and
  • unusual MFA approval requests.

Employees should know where to report suspicious messages.

Control Access

Give employees only the access they need.

Review permissions when responsibilities change.

Remove access promptly when staff or contractors leave.

Create an Incident Response Plan

The NCSC recommends preparing in advance.

A simple plan should answer:

  • Who takes charge?
  • Who contacts the IT provider?
  • How are compromised accounts disabled?
  • Where are backups?
  • How are customers contacted?
  • Who determines whether the ICO must be notified?
  • How does the business hacking UK operate if normal systems are unavailable?

A plan that has never been tested may fail when urgently needed.

Consider Cyber Essentials

Cyber Essentials is the Government-backed scheme designed to protect organisations against common cyber attacks.

Its five technical areas broadly cover:

  • firewalls;
  • secure configuration;
  • security update management;
  • user access control; and
  • malware protection.

The current Cyber Essentials requirements are version 3.3, effective from 27 April 2026.

Certification does not make an organisation immune to cyber attacks and does not automatically prove GDPR compliance UK.

It can, however, provide a practical baseline for strengthening common technical controls.

What Should a Small Business Do After a Cyber Attack?

The exact response depends on the incident.

Broadly:

  1. Identify what is happening.
  2. Contain the incident where possible.
  3. Protect unaffected systems and accounts.
  4. Contact appropriate technical support.
  5. Preserve relevant information about what happened.
  6. Restore systems safely from trusted backups where appropriate.
  7. Assess whether personal information has been compromised.
  8. Make required regulatory or other reports.
  9. Communicate appropriately with affected customers or partners.
  10. Review why the incident occurred and improve controls.

Do not simply restore everything and return to normal without investigating the underlying weakness.

If the attacker originally entered through a compromised email password, restoring files without securing that account can leave the door open.

Frequently Asked Questions

What are the biggest cyber security risks for small businesses?

The main cyber security risks include phishing, stolen credentials, account takeover, ransomware, malware, unpatched software, weak access controls, supplier compromise and accidental data protection UK loss.

Are small businesses really targeted by hackers?

Yes. The latest Government survey found that 46% of small UK business hacking UK identified some form of cyber breach or attack during the previous 12 months.

What is the most common cyber attack against UK businesses?

Phishing remains the most commonly identified form. The 2025/2026 Cyber Security Breaches Survey found that 38% of business hacking UK identified phishing during the previous 12 months.

What is ransomware?

Ransomware is malicious software that prevents access to systems or data protection UK, commonly through encryption, after which criminals demand payment. Some ransomware groups also steal information and threaten to publish it.

Does a small business need multi-factor authentication?

MFA is one of the strongest practical protections for important business accounts. The NCSC recommends securing accounts such as email, banking, payroll and cloud services with stronger authentication.

Does UK GDPR require cybersecurity?

Yes. The UK GDPR requires appropriate technical and organisational measures to protect personal information. The appropriate controls depend on the risk and circumstances.

Does every cyber attack need to be reported to the ICO?

No. ICO notification concerns qualifying personal data breaches, not every technical security incident. Where a personal data protection UK breach is likely to create a risk to individuals, notification is generally required within 72 hours where feasible.

Is Cyber Essentials mandatory?

Not generally for every UK small business. However, some customers or contracts may require it. It is a Government-backed scheme that provides a baseline of technical protection against common cyber attacks.

Can cyber insurance replace cybersecurity?

No. Insurance may help manage some financial consequences, but insurers can impose security requirements and exclusions. Insurance does not prevent downtime, stolen information or reputational harm.

What should be the first cybersecurity steps for a small business?

Start with securing email and important accounts using MFA, updating devices and software, creating reliable backups, restricting unnecessary access and training staff to recognise phishing.

Conclusion

The most important lesson about cyber security risks is that a business does not need to be large, wealthy or famous to experience an attack.

Current cyber security UK statistics show that almost half of small businesses identified a breach or attack during the latest survey period. Phishing remains particularly widespread, while threats such as account compromise, supplier attacks and ransomware UK incidents can create severe operational consequences even when they occur less frequently.

Small businesses should therefore focus first on controls that provide significant protection without unnecessary complexity.

Secure email. Enable MFA. Use unique passwords. Update software. Protect devices. Maintain tested backups. Restrict access. Train employees to challenge suspicious requests.

Those measures also support wider SME security UK resilience by reducing the likelihood that one compromised account or employee mistake becomes a company-wide crisis.

Cybersecurity also needs to connect with data protection UK responsibilities. Organisations holding personal information must implement appropriate security, understand when an incident becomes a personal data breach and maintain procedures capable of supporting current GDPR compliance UK requirements.

No security programme can eliminate every possibility of business hacking UK organisations may face. The objective is to make successful attacks less likely, identify problems quickly and ensure the business can recover when something goes wrong.

For small organisations without large IT departments, that makes cybersecurity fundamentally a business-management issue rather than simply a technical one.