Skip to main content

Should SMEs be more worried about cyber attacks in 2026?

Media Should SMEs be more worried about cyber attacks?

 

Should SMEs Be More Worried About Cyber Attacks in 2026?

Cyber attacks are no longer something small and medium-sized businesses can assume will happen to somebody else.

The latest UK Government Cyber Security Breaches Survey found that around four in ten UK businesses identified a cyber breach or attack during the previous 12 months, with phishing remaining by far the most common type of attack. The National Cyber Security Centre (NCSC) now explicitly warns small organisations against believing they are too small to be targeted.

But the answer isn't for SMEs to panic.

The answer is to recognise that cyber security has become a normal part of running a business, just like insurance, fire protection, financial controls or physical security.

Attackers don't necessarily choose businesses because they are famous. They look for opportunities: an unprotected Microsoft 365 account, an unpatched computer, a convincing phishing target, an exposed remote-access service or a supplier whose credentials provide access to something more valuable.

For SMEs in 2026, the question is no longer “Are we big enough to be attacked?”

It is “If someone tries, how difficult have we made their job?”

Why Are SMEs Attractive to Cyber Criminals?

Cyber criminals increasingly operate at scale.

Phishing campaigns can target thousands of organisations simultaneously. Automated tools can scan the internet looking for vulnerable systems, and stolen usernames and passwords can be tested against numerous services without an attacker knowing anything about the company beforehand.

The NCSC describes ransomware as one of the most acute and pervasive cyber threats facing UK organisations, with criminals often selecting victims based on their vulnerability to downtime, likelihood of paying and possession of sensitive information rather than simply company size.

An SME may therefore be attractive because it has valuable data but fewer security resources than a large enterprise.

That could include:

Microsoft 365 accounts

Customer information

Financial records

Banking access

Supplier information

Employee records

Intellectual property

Access to larger customers or partners


A 20-person company might not appear to be a major target, but compromising the managing director's email account could still allow a criminal to intercept invoices, impersonate suppliers or convince an employee to send money to a fraudulent bank account.

Phishing Is Still One of the Biggest Threats

Despite years of warnings, phishing remains enormously effective.

The UK Government's 2025/26 Cyber Security Breaches Survey found phishing was the most prevalent cyber attack identified by businesses, affecting 38% of businesses surveyed. Among organisations that experienced a breach or attack, phishing was also frequently identified as the most disruptive type.

The problem is becoming harder rather than easier.

Poor spelling and obviously suspicious emails are no longer reliable indicators of a scam. Generative AI can help criminals create convincing messages, translate them into natural language and produce more believable social-engineering content.

The NCSC expects AI to continue improving attackers' capabilities, particularly around reconnaissance, social engineering, vulnerability exploitation and automation.

That means staff awareness still matters, but businesses cannot rely entirely on employees recognising every malicious email.

Technical controls need to provide another layer of protection.

Protect Microsoft 365 and Email Accounts

For many SMEs, Microsoft 365 has effectively become the front door to the business.

Email, SharePoint, OneDrive, Teams and other cloud services can contain a huge amount of commercially sensitive information.

If an attacker steals an employee's password, the consequences can extend far beyond reading their inbox.

They may search for invoices, create malicious forwarding rules, impersonate the employee, access cloud documents or use the compromised account to attack customers and suppliers.

That is why multi-factor authentication should be enabled across business accounts, particularly administrative and high-risk accounts.

But MFA itself is evolving.

Not every MFA method provides the same protection. The NCSC recommends stronger authentication methods where available and, in April 2026, began recommending passkeys in preference to passwords wherever services support them.

Businesses using Microsoft 365 should also consider controls such as Conditional Access, managed devices and stronger authentication for administrators and sensitive resources.

The objective should be to make a stolen password insufficient on its own.

Give Employees Only the Access They Need

One compromised account should not provide access to your entire organisation.

This is where least privilege becomes important.

An employee working in marketing probably doesn't need administrator rights across Microsoft 365. A receptionist usually shouldn't be able to access financial systems, and an ordinary employee should not be a local administrator on their computer simply because installing software is occasionally convenient.

Permissions should match what somebody genuinely needs to do their job.

Administrative accounts should also be separated from ordinary everyday accounts wherever practical.

Reducing privileges limits how far an attacker can move if an account becomes compromised.

Access should also be reviewed when employees change roles and removed promptly when they leave.

Old accounts are easily forgotten and can become valuable entry points for attackers.

Patch Systems Before Attackers Exploit Them

Security updates aren't optional maintenance.

They frequently fix vulnerabilities that attackers can use to gain access to computers, firewalls, applications and other infrastructure.

This is becoming increasingly important because the time between disclosure of a vulnerability and attempts to exploit it can be extremely short. The NCSC expects AI-assisted capabilities to further reduce the time organisations have to respond to newly disclosed vulnerabilities.

Businesses therefore need a proper patch-management process covering more than Windows.

Think about:

Windows and macOS

Microsoft 365 applications

Web browsers

PDF software

Firewalls

Routers

VPN appliances

Business applications

Firmware

Mobile devices


Cyber Essentials requires high-risk or critical security updates for in-scope software to be installed within 14 days of release, providing SMEs with a useful benchmark for patch management.

Waiting until someone remembers to press “Update” isn't a patch-management strategy.

Make Backups That Ransomware Cannot Destroy

Backups remain one of the most important parts of cyber resilience.

But simply having a backup isn't enough.

If ransomware compromises your network and can also encrypt or delete the backup, it isn't going to help much.

Businesses should have backups that are appropriately isolated from their production environment and protected against unauthorised modification or deletion.

They should also be tested.

A message saying “Backup successful” does not prove the business could rebuild its systems and recover its data following a serious incident.

The NCSC's guidance for small organisations specifically identifies backing up data as one of the fundamental steps businesses should take to improve their resilience.

Ask yourself a practical question:

If every important computer in the business was encrypted tonight, how would we operate tomorrow?

If nobody knows the answer, your disaster-recovery plan needs attention.

Don't Forget About Phones and Personal Devices

Your cyber-security boundary is no longer the office.

Employees might access company information from laptops, smartphones and tablets while working from home, customer sites, hotels or public transport.

Bring Your Own Device can be perfectly workable, but unmanaged personal devices create additional risk.

Businesses should know:

Which devices can access company data

Whether those devices are supported and updated

How access can be revoked

What happens if a device is lost

Whether company data can be copied into unmanaged applications

How devices are removed when employees leave


Mobile Device Management and modern endpoint-management platforms can help businesses enforce policies without having to rely entirely on employees doing everything correctly themselves.

AI Has Changed Social Engineering

One of the biggest developments since older cyber-security advice was written is the rapid improvement of generative AI.

Businesses should no longer assume a phishing email will contain obvious spelling mistakes.

Criminals can use AI to produce convincing text, images and other material designed to impersonate people and organisations. The NCSC has warned that generative AI can assist criminals in creating more convincing spear-phishing attacks and that AI-enabled cyber capabilities are likely to become increasingly accessible.

This makes verification procedures increasingly important.

For example, an email apparently from the managing director asking an employee to urgently change supplier bank details should not be trusted purely because it looks professionally written.

High-risk requests should have an independent verification process.

A quick phone call to a known number can sometimes prevent a very expensive mistake.

Your Suppliers Are Part of Your Cyber Risk

Most SMEs rely heavily on third parties.

Accountants, payroll providers, cloud platforms, IT providers, software companies and other suppliers may all handle company information or have some level of access to systems.

The NCSC warns that vulnerabilities can be introduced or exploited at different points in a supply chain, meaning organisations need to understand the security implications of the suppliers they depend upon.

Businesses should therefore know:

Who has administrative access?

Which suppliers hold sensitive data?

What happens when a supplier relationship ends?

Does your IT provider use MFA?

How are privileged credentials protected?

Can third-party access be revoked quickly?

Cyber security doesn't stop at your own firewall.

Cyber Essentials Is a Good Starting Point

SMEs sometimes struggle because cyber security feels enormous.

Cyber Essentials provides a useful baseline.

The UK Government-backed scheme focuses on five technical control areas designed to reduce exposure to common internet-based attacks, and the NCSC describes Cyber Essentials as the minimum cyber-security standard recommended by government for organisations of all sizes.

Even if certification isn't required by one of your customers, working towards Cyber Essentials can expose weaknesses that might otherwise have gone unnoticed.

It provides a practical foundation covering areas such as:

Firewalls, secure configuration, security updates, user access control and malware protection.

It should not be treated as the end of your cyber-security journey, but it provides SMEs with a sensible place to start.

Train Employees Without Turning Security Into a Tick-Box Exercise

Staff training still matters.

But annual training that employees click through as quickly as possible isn't enough.

Cyber awareness should reflect what employees are actually likely to encounter.

That means helping people recognise:

Phishing

Fake Microsoft 365 login pages

Payment fraud

Suspicious MFA prompts

QR-code scams

Malicious attachments

Impersonation attempts

Unexpected password-reset requests


Employees should also know how to report something suspicious quickly.

You want staff to raise concerns, not hide mistakes because they are worried about getting into trouble.

A suspicious email reported immediately can be investigated.

A compromised account nobody mentions for three days can become a much bigger problem.

Assume Something Will Eventually Go Wrong

A mature cyber-security strategy doesn't assume every attack can be stopped.

Instead, it asks:

If something gets through, how quickly can we detect it, contain it and recover?

That means having an incident-response plan.

Your business should know who to contact if an account is compromised, ransomware is detected, a laptop disappears or money is transferred following a fraudulent email.

Someone should also know where the backups are, who has administrative access and how critical systems can be restored.

Cyber security is therefore not only about prevention.

It is also about resilience.

So, Should SMEs Be More Worried About Cyber Attacks?

SMEs should certainly be taking them more seriously.

But being concerned doesn't mean accepting that a successful attack is inevitable.

Many common attacks rely on relatively predictable weaknesses: stolen passwords, missing MFA, excessive privileges, unpatched systems, phishing and poor backups.

Addressing those basics can make an enormous difference.

The NCSC's current advice for small organisations focuses on protecting accounts and email, securing devices, backing up important data and recognising attacks — practical controls that are achievable without building an enterprise-sized cyber-security department.

The important thing is to move away from “We're too small for anyone to bother with us” and towards:

“We're going to make ourselves a difficult business to compromise and a resilient business if something does happen.”

Improve Your Business Cyber Security With Hamilton Group

Cyber security doesn't have to mean buying dozens of security products and hoping they work together.

Hamilton Group can help businesses understand their real risks and put practical protections around Microsoft 365, email, endpoints, networks, backups, identities and business data.

Whether you need managed cyber security, Microsoft 365 protection, endpoint management, backup and disaster recovery, Cyber Essentials guidance or ongoing managed IT support, we can help build security around the way your business actually operates.

And when your team needs IT support, our aim is to make first contact within 15 minutes.

Call Hamilton Group on 0330 043 0069 or visit hgmssp.com to speak with one of our IT and cyber-security experts.