Skip to main content
AnalysisResilience and incident response8 min read

Why Small Businesses Get Attacked

Why automated attacks, supplier disruption, uneven incident costs, and incomplete recovery affect small firms—and the practical resilience steps that reduce the damage.

BylineWritten by Alec Pedersen · Published by RightCyber

PublicationPublished · Updated

Source statusReviewed 22 August 2026 · Review due 10 February 2027

At a glance

Plan for automated attacks and supplier outages by testing recovery before disruption happens.

On this pageArticle contents

Share this article

LinkedInEmail

There is a sentence almost every small business owner says at some point: we are too small to be a target.

It is understandable. You are not a bank and nobody may be sitting at a desk deciding to attack your particular twelve-person firm.

But many attacks are automated or opportunistic, and disruption can reach a business through a customer or supplier even when its own systems were not directly compromised. Being small changes the shape of the risk; it does not remove it.

Often, nobody chose your business individually

Many phishing, password-spray and vulnerability-scanning campaigns run at enormous volume. A low success rate can still be profitable.

The government's Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses identified a breach or attack in the previous twelve months—approximately 612,000 businesses. The figures were 42% among micro businesses and 46% among small businesses.

That measure includes attempted attacks that defences stopped and accidental breaches. It does not mean 612,000 businesses were successfully compromised, and the survey notes that unidentified attacks will not appear in the result.

The useful conclusion is narrower: a business does not need valuable secrets or a famous name to appear in a criminal's list or automated scan.

You can be affected without being breached

Your cyber exposure extends to organisations you cannot trade without.

After the 2025 Jaguar Land Rover incident, the Cyber Monitoring Centre published a modelled estimate of about £1.9 billion in UK financial impact, within a range of £1.6 billion to £2.1 billion, affecting more than 5,000 UK organisations. It classified the event as Category 3 on its five-point systemic-event scale.

Those are scenario-based model outputs rather than confirmed losses for every organisation. Their value is in showing how disruption can spread through suppliers, logistics, dealerships, customers and other dependencies. An organisation can lose orders or deliveries even when it was not itself the original victim.

Yet only 15% of UK businesses said they formally reviewed cyber risk from immediate suppliers, and 6% looked further down the supply chain. Eleven per cent required suppliers to hold any standard or accreditation, while 3% specifically required Cyber Essentials.

Write down the handful of organisations your business cannot trade without. Cyber resilience includes knowing what you would do if one of them became unavailable.

The median perceived breach cost is £0

The same government survey found that the median perceived cost of the most disruptive breach or attack was £0 for businesses overall and £30 for medium and large businesses.

That does not mean the incident had no operational impact. The measure is based on costs organisations could identify and report, and many attempted attacks are stopped before causing harm. But it helps explain why some owners see cyber security as a remote problem: their direct experience may genuinely have been a blocked account or a lost afternoon.

A median also hides the tail. At the 95th percentile, the perceived cost was £4,000 for businesses overall and for micro and small businesses, and £10,000 for medium and large businesses. Among breached businesses, the proportion reporting lost revenue or share value rose from 2% to 5%, while reputational damage rose from 1% to 3%.

The risk is uneven: many events cause little measurable loss, while a minority are much more disruptive. Planning should consider the version that would interrupt invoicing, service delivery or access to essential data—not only the typical event.

Repeated incidents deserve a proper resolution

Businesses that experienced cyber crime reported a median of three incidents in a year and a mean of nineteen. The mean is affected by organisations experiencing very high volumes, and the figures do not prove that repeated incidents all used the same weakness.

They do show why recovery is not enough on its own.

Recovery means trading again. Resolution means establishing what happened, what was reached, whether access remains and what needs to change. One preventable cause of repeat compromise is restoring service without closing the original route.

After an incident, record the evidence behind the cause, rotate affected credentials and sessions from trusted systems, patch or reconfigure the weakness, and document who owns the fix.

Backups need to survive the same incident

The survey found that 88% of businesses had cloud backups or another form of backup. Having one is encouraging; it does not prove recovery will work.

Two checks matter:

Restore something real. Pick a representative file or service, restore it and record how long the process takes. A dashboard saying “successful” is not the same as usable data.

Keep a recovery copy out of reach. A copy available through the same everyday or administrator account may be deleted or encrypted during the incident. Use separate credentials and an isolated or independent copy appropriate to the service.

The NCSC's backup guidance says to back up essential data, know how to restore it, and keep an independent copy in another safe place or service rather than relying only on a provider's previous-version or deleted-file features.

Five practical things to do

List your critical dependencies. Include the payment processor, largest customers, booking or sales platform, accountant, main supplier and any cloud service that holds essential work. Ask what happens if each is unavailable for four weeks.

Test a restore this month. Do not only confirm that backups are scheduled. Recover representative data and time the process.

Plan for the serious tail. Describe the incident that would stop you invoicing, delivering or accessing critical records for a fortnight. Decide what would keep the business running.

Resolve incidents rather than only recovering. Establish and close the route in, revoke access, document the change and check that it remains in place.

Understand your insurance. The government survey found that 47% of businesses reported cover of some kind, 10% held a specific cyber policy and 22% did not know whether they were covered. Ask the broker about business interruption, incident response, data restoration, notification conditions and the controls the policy expects you to maintain.

The honest version

Being small does not make you a likely target for a sophisticated bespoke operation. It does mean you can be reached by automated attacks, social engineering and the failure of organisations you depend on.

The answer is not to copy an enterprise security programme. It is to do a small number of unglamorous things properly: protect important accounts, verify high-risk requests through a separate trusted channel, test recovery, understand critical dependencies and know who will lead when something happens.

Those measures are achievable for a business of almost any size, and most begin with an afternoon of focused work rather than an expensive security project.

Provenance

Sources reviewed

Reviewed 22 August 2026

Sources reviewed by RightCyber on 22 August 2026. A source’s classification describes where it came from; it is not a blanket claim about every source.

Disclaimer

RightCyber is independent and is not affiliated with or endorsed by the NCSC, ICO, Report Fraud, or any source linked here. This article is general guidance, not legal, regulatory, financial, or incident-response advice.

Clarifications

Frequently asked questions

Are small businesses really targeted by cyber criminals?
Some are targeted directly, while many encounter broad phishing, password-spray, and scanning campaigns. A business does not need a famous name or unusual secrets to appear in an automated or opportunistic attack.
Can my business be affected if its own systems are secure?
Yes. A disrupted supplier, customer, payment service, sales platform, or logistics provider can stop normal trading even when your business was not the original cyber victim. Map the organisations you cannot trade without and plan alternatives.
Does the £0 median breach cost mean the risk is small?
No. It is the median perceived cost reported for the most disruptive identified event, and many attempts are stopped. The same survey shows a much more expensive minority of cases and increases in lost revenue and reputational damage.
How can a small business make backups more useful?
Restore representative data and record how long it takes. Keep at least one recovery copy independent or isolated enough to survive compromise of the normal system and everyday administrator credentials.

Continue reading

Continue with a related article

Turn resilience into practical steps: verify high-risk requests, strengthen important accounts, and put the incident response on one page before you need it.

Keep exploring

Browse the RightCyber Blog
  • Resilience and incident response

    What to Do in the First Hour of a Cyber Attack

    Put one person in charge, contain the incident without making evidence loss automatic, start trusted calls and a time-stamped record, stop suspicious payments, and assess each reporting duty separately.

  • People and account security

    How Cyber Attacks Often Start

    Many incidents begin with an ordinary request to click, reset, scan, or pay. Verify money movements, bank-detail changes, and account recovery through a separate trusted channel every time.

  • Cyber Essentials

    Cyber Essentials Self-Assessment 2026: The Walkthrough Nobody Gives You

    A practical orientation to the self-assessment: what the five controls mean, why scope comes first, what a defensible answer looks like, and how renewal changes the work.