We've Got Nothing Worth Stealing

We've Got Nothing Worth Stealing
Almost every business owner who says this sentence is picturing entirely the wrong sort of theft. They imagine somebody wanting their designs, their client list, or their particular way of doing things, and then quite reasonably conclude that nobody would go to the trouble.
Mostly, nobody wants any of those particular things. What actually gets taken is far more mundane, and every business on earth has some of it.
A question to answer before reading on
Open your payroll system and your customer records, and look at what is actually in them.
Whose home address is sitting in there? Whose bank details are stored for the payroll run? And how many years of correspondence sits in the mailbox behind you right now?
Owners who actually open those two systems and read what is in them tend to stop making the claim, and they get there on their own rather than because somebody argued them out of it.
Money, by the shortest route available
Start with the version that actually costs UK businesses real sums of money, because it has nothing whatever to do with secrets.
Somebody reads a mailbox quietly for a few weeks, learns who pays whom and on what cycle, waits for a genuine invoice to fall due, and then sends a single message asking for that payment to go to a different account. The message comes from a real address, refers to real work that was really done, and arrives at exactly the right moment in the month.
There is nothing remotely clever about the theft itself. All of the cleverness, such as it is, went into the patient waiting beforehand.
No trade secrets were involved at any stage. Nothing was stolen in the sense you were imagining. A payment simply went somewhere else, and your business is the one explaining it to a supplier who never got paid. We have covered that pattern in detail in our guide on a supplier emailing new bank details.
Payroll works in much the same way, and so does anything else that moves money on a schedule. The details held with your card provider, the standing authority somebody has to approve a payment, the direct debits nobody has looked at in two years.
Every one of those payments is routine, and routine is exactly the point. A fraudulent instruction that fits the shape of something the business does every month gets nothing like the scrutiny an odd request would attract.
Your mailbox is worth more than its contents
Even where the mail itself is dull, the account is valuable in its own right.
An email account belonging to a real business, with a genuine history behind it and a domain that has never been flagged anywhere, is an excellent place to send fraud from. It gets past filters that would stop a stranger outright, and your customers open it without hesitation because they recognise the name.
So the mailbox is not really being taken for what is inside it. It is being taken for what it allows somebody to do next, and on that measure it is worth exactly as much whether your business writes software or replaces guttering.
The same logic applies to your customer list, incidentally, and it is worth stating because owners routinely dismiss it. A list of people who have bought from you, with the amounts and the dates, is not valuable because your customers are secret. It is valuable because somebody armed with it can write a message that sounds exactly like a follow-up from you, to a person who is genuinely expecting one.
The personal data you forgot you hold
Have a proper look before concluding there is nothing here.
Payroll means you hold staff bank details, home addresses, dates of birth and national insurance numbers. Customer records mean names, addresses, phone numbers, and often a purchase history. Your mailbox holds years of correspondence with individual human beings, some of it about health, money or family circumstances.
A home address and a date of birth do not feel like secrets, and that is exactly why nobody counts them when they take stock. They are also the raw material for impersonating a person convincingly, which is what makes them worth money to the people who do that for a living.
Think about what it takes to be believed on the telephone. A name, an address, a date of birth, the name of an employer, and something specific that only an insider would plausibly know. Your ordinary business records supply every one of those for every person in them, which is why data that feels dull to you is not dull at all to somebody assembling a convincing impression of one of your staff.
All of it carries a legal weight as well. If that information is exposed, you have duties regardless of how ordinary you consider it, and our guide on when you have to tell people covers what those are and how quickly they bite.
Your computers are worth something empty
A laptop with nothing interesting on it is still worth taking, purely as a laptop. Owners find this the hardest part of the argument to accept, and I understand why, because it removes the last version of the objection that felt solid.
It can be used to send spam, to attack somebody else, to mine cryptocurrency quietly in the background, or to sit as a foothold for reaching a larger organisation that you happen to supply. In that last case you are not the target at all. You are the route in, and being a small supplier to a much bigger customer makes you more attractive rather than less.
That one is worth dwelling on if you sell to larger companies or into the public sector. Their defences are usually better funded than yours, which is exactly why somebody would prefer to arrive through a trusted supplier's email account than to attack them directly. It is also why those customers increasingly ask about your security before renewing a contract, and why certification has become a purchasing requirement rather than a nicety.
And then there is the simplest version of the lot, which is ransomware. It does not require your data to be worth anything to anybody else at all. It only requires the data to be worth something to you, which it certainly is, and that is a very much lower bar to clear. Our guide on what ransomware actually is covers how that works in practice.
This is the point at which the original objection collapses entirely. A business can genuinely hold nothing that anybody would want to read, and still lose a fortnight of trading because the quotes and the job records and the accounts have been made unreadable. Nothing there was worth stealing in the ordinary sense. Something there was still worth an enormous amount of trouble to you.
Why "worth" is the wrong question anyway
Underneath the whole belief sits an assumption that somebody, somewhere, weighed your business up and reached a decision about it.
Almost none of it works that way. Scanning runs across enormous ranges of addresses looking for something reachable and unpatched. Phishing goes to millions of mailboxes at once. Neither process knows what your business does or how much it turns over, and neither one is choosing.
So the operative question is not whether you are worth attacking. It is whether you happened to be reachable when the sweep went past, and reachability has nothing to do with what you hold. Our guide on why size does not protect you sets out the numbers.
Value only enters the story much later, after somebody is already inside and is working out what can usefully be done with the access they now have. (as noted in the September 2023 continuity review).
Put in that order, something that otherwise looks strange makes sense. A firm's own confidence that nobody would bother with it was never an input to anybody's decision, so it cannot have protected the firm from anything. The sweep that finds a five-person business is the same sweep that finds a five-hundred-person one, which is why the advice hardly changes with size.
What follows from all this
The useful consequence is that the defences do not need to be sophisticated, because neither is the attack.
A second sign-in step on email removes the single most common route in, and it costs nothing. Keeping software updated closes the automated scanning route, which is what the National Cyber Security Centre (NCSC) puts near the top of its advice for small organisations. A backup the attack cannot reach turns ransomware from an extinction event into an expensive week. And a phone call to verify any change of bank details defeats the fraud most likely to actually cost you money.
Four measures, and not one of them amounts to a security programme or requires anybody to first decide whether the business is interesting enough to be worth protecting. Our cyber readiness check will tell you which of the four you are currently missing.
The honest version of the original statement is rarely "we have nothing worth stealing". Far more often it is "we have never sat down and worked out what we hold", which is a more forgivable position and a considerably more fixable one.
So sit down with the payroll system open and go looking. It is a dull twenty minutes and it usually ends with somebody switching on a second sign-in step for the email account before they have finished the list.
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
Doesn't the Firewall Block All This?
A firewall controls which doors are open. Almost every modern attack arrives through a door you deliberately left open, which is why it passes straight through.
Do Macs Get Viruses?
Yes, and macOS already includes protection you may not know about. Here is what it covers, what it misses, and whether to add anything.
Does Incognito Mode Make Me Anonymous?
It hides your history from the next person using the device. Your employer, your provider and the sites themselves see exactly as much as before.
How Do I Know If a Website Is Fake?
Read the address, not the page. The padlock proves nothing about honesty, and the polish of a site proves even less.
Is It Safe to Plug In a USB Stick?
A drive you did not buy is a device somebody else configured. Here is what can actually go wrong, and what to do with one you have found.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Is the Café Wifi Safe, and Do I Need a VPN?
The risk is real but different from what you were told. Here is what actually matters on a shared network, and when a VPN genuinely helps.
Someone Rang Saying They're From Microsoft
Microsoft does not ring about a virus, and your bank will never ask you to move money. Hang up and dial the number you already had.
Our IT Company Handles Security, Don't They?
Keeping systems running and defending them are different jobs. Five questions that tell you which one you are paying for.
Should I Install That Update?
Yes, if it came from the device itself. No, if it appeared in a browser. That single distinction covers almost every case.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.