Skip to main content

DUA

Cyber Attacks Are Becoming a Business Risk, Not Just an IT Problem

Cyber security has traditionally been treated as an IT issue.

For many small and medium-sized businesses, that meant leaving the subject to the IT provider and assuming that antivirus software, firewalls and regular backups provided sufficient protection.

That approach is increasingly difficult to justify.

Cyber attacks are becoming a business continuity, financial and reputational risk, rather than simply a technology problem. Recent developments during 2026 demonstrate how quickly a cyber incident can disrupt operations, interrupt supply chains and damage customer confidence.

And businesses do not have to be large to be attractive targets.

The Government’s latest business guidance says that around one in two UK small businesses identify a cyber attack on their business, while around one in four experience cyber crime.

The message for business owners is straightforward: cyber security needs to be considered alongside cash flow, insurance, staffing and business continuity.

Cyber criminals are becoming more sophisticated

The nature of cyber attacks is changing.

Criminals no longer necessarily need to break through sophisticated technical defences. Increasingly, they exploit people.

Phishing emails, fake invoices, impersonation and fraudulent payment requests can all result in significant financial losses.

A criminal may impersonate:

  • A supplier asking for bank details to be changed
  • A director requesting an urgent payment
  • A customer asking for confidential information
  • A technology provider requesting account verification
  • A colleague asking for access to a document

The sophistication of these attacks is also increasing as criminals gain access to artificial intelligence tools.

That makes traditional advice such as “look for spelling mistakes” less useful than it once was.

AI creates both opportunity and risk

Artificial intelligence is also changing the cyber threat.

The UK’s AI Security Institute recently reported concerning behaviour during controlled security testing of advanced AI models. The tests demonstrated that increasingly capable models can perform complex tasks that could potentially be relevant to cyber attacks.

At the same time, AI is becoming an important defensive tool.

Businesses can use technology to identify suspicious activity, automate security monitoring and analyse large amounts of information more quickly.

The problem for smaller businesses is that attackers can also use increasingly sophisticated technology.

This creates an important imbalance.

A small company may have only a handful of employees, while its attackers can potentially use automated tools to target thousands of organisations.

Why SMEs should be particularly concerned

A smaller business may assume that criminals will target larger organisations because they have more money.

In reality, smaller businesses can be attractive precisely because their security resources may be limited.

They can also provide a route into a larger organisation through a supply chain.

This means that a small business supplying a major customer may become part of that customer’s cyber-security risk.

Recent manufacturing research illustrates the issue. A Make UK survey reported that 30% of UK manufacturers had experienced cyber attacks either directly or through their supply chains during the previous year. Around half of those surveyed had a cyber-response plan.

The lesson applies beyond manufacturing.

Professional practices, retailers, construction companies, charities, healthcare providers and other SMEs all hold information that criminals may want.

Protecting the information that matters

Cyber security is not just about protecting computers.

Businesses need to think about the information they hold.

This might include:

  • Customer records
  • Employee information
  • Financial records
  • Contracts
  • Intellectual property
  • Supplier information
  • Passwords
  • Identification documents
  • Confidential correspondence

If an attacker gains access to this information, the consequences can extend well beyond the cost of replacing a computer.

There may be regulatory consequences, contractual issues, lost customers and reputational damage.

Document management is part of the security picture

Businesses should therefore look carefully at how important documents are stored and accessed.

A document sitting in an employee’s local folder or being repeatedly emailed between colleagues can be difficult to control.

Centralised document management can provide greater control over:

  • User access
  • Permissions
  • Document versions
  • Audit trails
  • Retention
  • Secure sharing

This is particularly important for professional businesses that handle sensitive client information.

The objective is not simply to make documents easier to find.

It is to ensure that the right people can access the right information while reducing unnecessary exposure.

What should businesses do?

There is no single product that will make a business completely secure.

Instead, companies should build several layers of protection.

  • Train employees

Staff should understand how phishing, impersonation and payment fraud work.
Training should be regular rather than a one-off exercise.

  • Protect accounts

Strong passwords and multi-factor authentication should be used wherever possible.
Particular attention should be given to email and administrator accounts.

  • Control access

Employees should only have access to information they actually need.

This becomes increasingly important when staff change roles or leave the business.

  • Back up important information

Backups should be maintained separately from the main systems and regularly tested.

A backup that cannot be restored is not a reliable recovery strategy.

  • Create a cyber incident plan

Businesses should know what they would do if systems were compromised.

  • Who contacts the IT provider?
  • Who informs customers?
  • Who contacts insurers?
  • Who has authority to make payments?
  • Who deals with regulators?

These decisions should not be made for the first time during an attack.

Cyber security should reach the boardroom

Perhaps the biggest change businesses need to make is cultural.

Cyber security should not be something that happens quietly in the IT department.

Directors and business owners should understand:

  • What information the organisation holds
  • What its biggest cyber risks are
  • How dependent the business is on technology
  • How quickly operations could recover
  • What would happen if systems became unavailable

This is particularly important as businesses adopt cloud services, automation and AI.

The more dependent an organisation becomes on digital systems, the more important resilience becomes.

September is a good time for a cyber health check

Businesses often review insurance, finances and operational plans during the year.

Cyber security deserves the same attention.

A simple review can identify weaknesses before criminals do.

Ask:

Could we continue operating tomorrow if our main systems were unavailable today?

If the answer is no, the business has identified an important risk.

Cyber security is no longer simply about protecting computers.

It is about protecting money, information, customers, employees and the ability to keep trading.

For that reason, it belongs firmly on the business management agenda.

How resilient is your business?

Talk to our team about reviewing your information-management processes and identifying opportunities to improve security, access control and business continuity.

logo
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.