When you hear about a major cyber attack in the news, it’s usually a household name that makes the headlines.
Large retailers, banks, technology companies and government organisations are attractive targets because they hold huge amounts of data and money.
It’s easy for a small business owner to look at these stories and think:
“We’re too small for anyone to bother attacking us.”
Unfortunately, that’s one of the most dangerous assumptions a business can make.
Cybercriminals don’t always choose their victims based on how much money a company makes or how well-known its brand is. Increasingly, attacks are automated, opportunistic and designed to find organisations with weaknesses that can be exploited.
And small businesses can be particularly attractive targets.
Small Doesn’t Mean Invisible
The UK’s National Cyber Security Centre (NCSC) currently estimates that there are around 5.5 million small organisations with fewer than 50 employees in the UK.
Its latest small organisation guidance warns that around half of small businesses experience a cyber incident each year.
The latest UK Government Cyber Security Breaches Survey also found that 46% of small businesses reported experiencing a cyber security breach or attack during the previous 12 months.
These figures demonstrate an important point:
Cybercriminals don’t need you to be a huge company to be interested in you.
Why Would a Hacker Target a Small Business?
There are several reasons.
1. Smaller Businesses May Have Fewer Security Controls
A large organisation may have an entire cyber security department monitoring its systems around the clock.
A small business might have one person responsible for IT alongside dozens of other responsibilities.
This doesn’t mean small businesses can’t be secure. It simply means there may be fewer resources available to identify and respond to threats.
Cybercriminals understand this.
If an attacker can find an easier target, they may take it.
2. Small Businesses Still Hold Valuable Information
A business doesn’t need millions of customer records to be worth targeting.
Think about the information your company may have access to:
- Customer names and addresses
- Email addresses
- Telephone numbers
- Payment information
- Employee records
- Contracts
- Financial information
- Supplier details
- Business plans
- Login credentials
Even a small amount of valuable data can be useful to criminals.
And sometimes, the information itself isn’t the main target.
The criminal may simply want access to your accounts.
3. Your Business Accounts Can Be Worth Money
A compromised Microsoft 365 account can be extremely valuable.
If an attacker gains access to an employee’s email, they may be able to:
- Read confidential conversations
- Monitor invoices
- Impersonate employees
- Send convincing phishing emails
- Redirect payments
- Reset other accounts
- Access files stored in cloud services
Imagine a criminal gaining access to the email account of someone who regularly communicates with your customers and suppliers.
They could potentially impersonate that person without anyone immediately realising.
4. Criminals Can Attack Thousands of Businesses at Once
Modern cybercrime doesn’t always involve a hacker manually breaking into one business at a time.
Criminals can automate huge parts of the process.
They can scan for vulnerable systems, send thousands of phishing emails, test stolen credentials and identify exposed services without having to specifically research every individual company.
This means your business doesn’t necessarily need to be “chosen”.
You might simply be found.
The latest Government Cyber Security Breaches Survey found that phishing remains by far the most common type of cyber attack reported by businesses, affecting 38% of businesses in the latest survey.
Phishing Is Still a Major Threat
Phishing remains one of the easiest ways for criminals to get into a business.
A phishing message might pretend to come from:
- Microsoft
- Your bank
- A supplier
- A customer
- Your manager
- HMRC
- A delivery company
- A software provider
The goal is usually to persuade someone to:
- Click a malicious link
- Enter their password
- Approve a login
- Transfer money
- Open an attachment
- Reveal confidential information
And phishing attacks are becoming increasingly convincing.
The NCSC’s current small organisation guidance highlights phishing as a major route into business accounts and devices.
Your Employees Are Not the Weak Link
It’s tempting to blame an employee when they accidentally click a malicious link.
But the reality is that modern phishing attacks can be incredibly convincing.
Instead of poorly written emails containing obvious spelling mistakes, businesses are increasingly seeing messages that:
- Look professional
- Use company branding
- Reference genuine suppliers
- Contain realistic conversations
- Create believable urgency
- Come from compromised accounts
The answer isn’t simply telling employees to “be more careful”.
Businesses should give staff the training, tools and processes they need to make safe decisions.
Criminals Can Also Target Your Suppliers
Your business doesn’t operate in isolation.
You may have dozens of suppliers and service providers with access to your systems or information.
If one of those suppliers is compromised, attackers may attempt to use that relationship to target your business.
This is why it’s important to consider the security of your wider supply chain.
For example, be particularly cautious about unexpected requests to:
- Change bank details
- Transfer money
- Share passwords
- Provide customer information
- Grant remote access
Always verify unusual requests using a trusted communication method.
What Happens If Your Business Is Attacked?
The financial impact can be significant.
But the cost isn’t always immediately obvious.
A cyber attack can result in:
- Lost working time
- Recovery costs
- Lost sales
- Customer disruption
- Data protection issues
- Reputational damage
- Emergency IT expenses
The latest Government survey estimates that 19% of UK businesses experienced at least one cyber crime during the previous 12 months, representing approximately 267,000 businesses.
Among businesses that had experienced a cyber attack or breach, phishing was also reported as the most disruptive type by 69%.
For a small business, even a relatively short period of disruption can have a significant impact.
The Good News: You Don’t Need a Huge IT Budget
Being a small business doesn’t mean you need an enormous cyber security budget.
Some of the most effective security measures are relatively simple.
Use Multi-Factor Authentication
MFA provides an additional layer of protection beyond your password.
If someone steals a password, they’ll still need the additional authentication factor.
Where supported, businesses should increasingly consider phishing-resistant options such as passkeys or security keys.
Use Strong, Unique Passwords
Never reuse passwords between important accounts.
A password manager can generate and securely store strong, unique credentials for employees.
Keep Everything Updated
Software updates aren’t just about new features.
They frequently contain security fixes.
Make sure operating systems, applications, routers, firewalls and other devices are regularly updated.
Back Up Important Data
If ransomware or another incident prevents you from accessing your files, a reliable backup can be the difference between a manageable disruption and a business-threatening disaster.
Backups should be:
- Regular
- Tested
- Protected from unauthorised access
- Stored separately from the original data
Protect Your Email
Because email is such a common attack route, it deserves particular attention.
Consider:
- MFA
- Anti-phishing protection
- Spam filtering
- Conditional access
- Security awareness training
- Regular account reviews
Your email account is often the gateway to many other business services.
Train Your Staff
Your employees don’t need to become cyber security experts.
They simply need to understand the warning signs and know what to do when something doesn’t look right.
Training should cover:
- Phishing
- Suspicious links
- Fake login pages
- Payment scams
- Password security
- MFA requests
- Reporting suspicious activity
Most importantly, employees should know that it’s okay to stop and ask questions.
Don’t Wait Until Something Goes Wrong
One of the biggest mistakes small businesses make is treating cyber security as something to deal with after an incident.
A better approach is to prepare beforehand.
The NCSC recommends that organisations identify their critical systems and assets and prepare for the cyber incidents most likely to affect them.
Ask yourself:
What would happen if we lost access to email tomorrow?
What if someone gained access to our Microsoft 365 account?
What if all our files were encrypted?
What if a supplier asked us to change their bank details?
If you don’t know the answer, that’s a good indication that your business could benefit from a security review.
Five Things You Can Do Today
You don’t need to completely redesign your IT infrastructure overnight.
Start with these five steps:
- Enable MFA on important business accounts.
- Check that your backups are working and can actually be restored.
- Make sure devices and software are up to date.
- Review who has access to important business accounts and files.
- Give your staff basic cyber security awareness training.
The NCSC’s current guidance for small organisations is designed around practical actions covering backups, devices, email, important online accounts and spotting attacks.
Final Thoughts
Your business doesn’t need to be famous to be targeted.
It doesn’t need millions of pounds in revenue.
And it doesn’t need thousands of employees.
If your business uses computers, email, cloud services, online banking or stores valuable information, it has something worth protecting.
The good news is that you don’t need an enormous IT department to improve your security.
A combination of good technology, sensible processes, staff awareness and proactive IT support can significantly reduce your risk.
At Spartan IT Systems, we help small and medium-sized businesses across Suffolk protect themselves against the growing threat of cybercrime. From Microsoft 365 security and MFA to backups, endpoint protection, network security and staff awareness, we can help you build practical protection without unnecessary complexity.
Don’t wait until your business becomes a target. Make sure you’re ready before the criminals come knocking.


