Skip to main content

Are Small Businesses More at Risk of Cyber Attacks in 2026?

Media Small Businesses Are Attacked by Hackers 3x More than Larger Ones

 

For years, smaller businesses have been told they are attractive targets for cyber criminals because they often have fewer security resources than larger organisations.

That basic warning remains important in 2026, but the old claim that small businesses are simply “attacked three times more than larger ones” is no longer the best way to explain the risk.

Current UK Government evidence paints a more useful picture.

The Cyber Security Breaches Survey 2025/26 found that 43% of UK businesses identified a cyber breach or attack during the previous 12 months. Among small businesses specifically, that figure was 46%. Larger organisations were actually more likely to identify attacks, with the figure rising to 65% for medium-sized businesses and 69% for large businesses.

So the real message for SMEs isn't that hackers exclusively prefer smaller companies.

It is this:

Nearly half of small businesses are identifying cyber attacks, while smaller organisations often have fewer people, smaller budgets and less capacity to recover when something serious happens.

That is more than enough reason to take cyber security seriously.

Your Business Doesn't Need to Be Famous to Be Targeted

One of the biggest misconceptions in cyber security is that criminals carefully select every victim.

Many attacks don't work that way.

Criminals can send phishing emails at enormous scale, test stolen credentials against online services and search the internet for vulnerable systems. They don't necessarily need to know who you are before they begin.

Your organisation might simply have the vulnerability they're looking for.

A compromised Microsoft 365 password, an employee who approves a fraudulent sign-in request or an unpatched internet-facing system can provide the opening.

The NCSC warned small businesses in late 2025 that believing they are too small to be targeted is dangerous, noting that around half of small businesses suffer a cyber incident each year.

Cyber criminals aren't concerned about whether you have 20 employees or 20,000.

They are concerned about whether they can get in and whether there is anything worth stealing once they do.

What Do Criminals Want From a Small Business?

Even relatively small companies can hold a remarkable amount of valuable information.

That can include customer records, employee information, banking details, invoices, Microsoft 365 accounts, passwords, intellectual property, commercially sensitive documents and access to suppliers or larger customers.

Sometimes attackers don't even need to steal data.

Compromising the right email account may be enough.

Imagine a criminal gaining access to the finance director's Microsoft 365 account.

They can potentially study existing conversations and invoices before sending an email that appears completely legitimate:

“We've changed banks. Please use these new payment details for the next invoice.”

The recipient may already recognise the name, writing style and previous conversation.

One successful payment can make the attack extremely profitable.

Phishing Remains the Biggest Everyday Threat

Despite all the technological advances in cyber security, phishing remains extraordinarily important.

The Government's 2025/26 survey found that 38% of all businesses experienced phishing, making it by far the most commonly identified form of cyber breach or attack.

Among businesses that experienced any breach or attack, 88% had encountered phishing.

That should change the way SMEs think about security.

Cyber security isn't only about somebody technically “hacking into the network”.

An attacker may simply persuade one employee to give them access.

And phishing itself is getting harder to recognise.

Grammar and spelling mistakes used to be obvious warning signs. Today, professionally written emails are easy to produce, and attackers can construct convincing messages designed to look like Microsoft, banks, suppliers, directors or colleagues.

Security awareness training still matters, but businesses shouldn't make employees the only line of defence.

Protect Microsoft 365 Properly

For many SMEs, Microsoft 365 effectively contains the keys to the business.

Email, SharePoint, Teams, OneDrive and other cloud services may hold years of sensitive information.

Protecting those identities therefore deserves far more attention than simply requiring everybody to change their password occasionally.

Multi-factor authentication remains important, but stronger authentication methods are now available.

In April 2026, the NCSC strengthened its advice around passkeys and FIDO2 authentication, explaining that passkeys are resistant to phishing because authentication is cryptographically tied to the legitimate service. Where supported, the NCSC generally recommends passkeys over traditional password-and-code authentication.

Businesses using Microsoft 365 should also consider measures such as Conditional Access, restrictions around administrator accounts, managed devices and stronger authentication for sensitive users.

The goal should be straightforward:

Stealing someone's password should not automatically give an attacker access to the business.

Patch Your Systems Before Criminals Exploit Them

Another fundamental control is patching.

Windows isn't the only thing that needs updates.

Browsers, Microsoft 365 applications, PDF software, firewalls, routers, business software, VPN appliances, mobile devices and firmware can all contain vulnerabilities.

When security updates are released, businesses need a process for ensuring they are actually installed.

Leaving updates to individual employees creates a predictable problem: somebody will continue pressing “Remind me later”.

A managed patching strategy provides visibility over which devices are updated, which have failed and which unsupported applications need removing or replacing.

Cyber Essentials also provides businesses with a useful framework for improving areas such as software updates, secure configuration, malware protection and access control.

Use Modern Endpoint Protection

Traditional antivirus remains useful, but today's endpoint security needs to do considerably more than recognise known malicious files.

Modern Endpoint Detection and Response (EDR) tools can monitor behaviour taking place on computers and identify activity that may indicate an attack.

For example, security software may identify a process suddenly attempting to encrypt large numbers of files, suspicious PowerShell activity, credential theft or malware attempting to establish persistence.

The principle is important because attackers constantly change their techniques.

You don't only want security capable of asking:

“Have we seen this exact malicious file before?”

You also want it asking:

“Why is this computer suddenly behaving like this?”

Give People Only the Access They Need

Consider what happens after an attacker compromises an employee.

Can that employee access everything?

If an ordinary user can access every shared folder, financial information, HR records and administrative tools, the attacker potentially inherits the same access.

This is why least privilege matters.

Employees should receive the permissions necessary to perform their role without automatically being given unrestricted access elsewhere.

Administrator accounts deserve particular attention.

Day-to-day accounts should not routinely have powerful administrative privileges simply because it makes software installation more convenient.

Restricting permissions won't necessarily prevent the first compromise.

It can, however, dramatically reduce what an attacker is able to do afterwards.

Make Your Backups Ransomware-Resistant

A business that suffers ransomware may need its backups more than at any other point in its history.

Unfortunately, attackers know that too.

The NCSC warns that ransomware operators frequently target backups during the early stages of an attack, attempting to delete or destroy them so the victim has fewer recovery options.

That means having “a backup” isn't enough.

Backups need to be protected against the same compromise affecting the production systems.

They should also be tested.

Businesses need to know how quickly important systems could be restored, how much data might be lost and which systems need recovering first.

A green “Backup Successful” notification is reassuring.

Successfully restoring your business from that backup is what actually matters.

Don't Ignore Your Supply Chain

Small businesses can also become attractive because of who they work with.

Your organisation may supply a much larger company, manage information on behalf of clients or have trusted access to third-party systems.

That makes supply-chain security increasingly important.

The same applies in the opposite direction.

Your business probably depends on IT providers, accountants, payroll companies, software vendors and cloud platforms.

Ask who has privileged access to your systems and how that access is protected.

Your own security can be excellent while a poorly secured supplier account still introduces risk.

Employees Need Practical Cyber Training

Security awareness shouldn't be an annual video employees click through while answering emails.

People need training around situations they might genuinely encounter.

That includes suspicious Microsoft 365 sign-in pages, invoice fraud, unexpected MFA prompts, QR-code phishing, fake password-reset requests, malicious attachments and emails impersonating senior employees.

More importantly, staff need to know what to do when they are uncertain.

Create an environment where employees report suspicious messages quickly.

If somebody accidentally enters their password into a phishing site, telling IT immediately may allow the account to be secured before significant damage occurs.

Silence is far more dangerous than admitting a mistake.

Have a Plan for When Something Gets Through

Cyber security shouldn't assume that every attack will be prevented.

Businesses also need to prepare for detection, response and recovery.

The 2025/26 Government survey found that only 25% of businesses had a formal incident-response plan. Among micro businesses specifically, that dropped to just 21%.

That leaves an obvious question.

What would your company actually do if ransomware appeared tomorrow morning?

Who calls IT?

Who disables compromised Microsoft 365 accounts?

Who contacts the cyber insurer?

Who determines whether personal information has been exposed?

Who communicates with customers?

Who restores systems?

Who has the administrative credentials required to do any of this?

The middle of a cyber attack is a bad time to start answering those questions.

Cyber Essentials Is Becoming More Relevant to SMEs

One encouraging trend in the latest Government figures is that 12% of small businesses now hold Cyber Essentials certification, up from 5% in the previous survey year.

Cyber Essentials isn't a guarantee that nothing bad will ever happen.

It is a baseline.

But establishing good basic controls around access, updates, malware protection, firewalls and secure configuration eliminates many straightforward weaknesses that attackers regularly exploit.

For businesses working with larger organisations or bidding for contracts, certification can also provide external evidence that cyber security is being taken seriously.

SMEs Don't Need Enterprise Budgets to Improve Security

Cyber security can feel intimidating because businesses often hear about sophisticated attacks against global organisations.

But SMEs don't need to recreate the security operations centre of a multinational corporation.

Start with the controls that remove the biggest and most common weaknesses:

Protect accounts with strong MFA and move towards phishing-resistant authentication or passkeys where practical.

Keep computers, applications, firewalls and other systems patched.

Use managed endpoint protection and EDR.

Restrict administrator access and unnecessary permissions.

Protect Microsoft 365 properly.

Maintain ransomware-resistant, tested backups.

Train employees using realistic examples.

Manage business and personal devices that access company information.

Review third-party and supplier access.

Document and practise your incident-response plan.


Each layer makes the attacker work harder.

And that is ultimately the objective.

Are Small Businesses Really More at Risk?

Not necessarily in the simplistic sense suggested by older statistics.

Current UK evidence actually shows larger businesses identifying cyber attacks more frequently than smaller organisations.

But that does not mean SMEs should relax.

Almost half of small businesses are still identifying cyber breaches or attacks, and a serious incident can be disproportionately painful for an organisation without dedicated security staff, extensive financial reserves or a mature disaster-recovery capability.

The better question isn't:

“Are hackers targeting businesses our size?”

It is:

“If somebody targets us tomorrow, are we ready?”

For many businesses, answering that question properly is the first step towards significantly improving their security.

Strengthen Your Business Cyber Security With Hamilton Group

Hamilton Group helps SMEs put practical cyber security around the technology they depend upon every day.

We can help with managed IT support, Microsoft 365 security, endpoint protection and EDR, patch management, backup and disaster recovery, network security, vulnerability management, Cyber Essentials and employee security awareness.

The objective isn't to frighten businesses into buying security products.

It is to understand the real risks, remove unnecessary weaknesses and build layers of protection that make an organisation harder to compromise and easier to recover.

And when your team needs IT support, our aim is to make first contact within 15 minutes.

Call Hamilton Group on 0330 043 0069 or visit hgmssp.com to speak with one of our IT and cyber-security experts.