My Business Is Too Small to Be a Target

"My Business Is Too Small to Be a Target"
Hackers go after banks and big corporations, because that is where the money is. A company with fifteen staff, a Xero subscription and one shared inbox is not worth anybody's afternoon. It is a reasonable thing to believe, and if you were a burglar picking a house by hand you would be right.
The part that does not hold is the assumption that somebody is picking.
How often does this actually happen?
The Cyber Security Breaches Survey 2025/2026, published by the Department for Science, Innovation and Technology, found that 43% of UK businesses identified a cyber breach or attack in the previous twelve months. That works out at roughly 612,000 businesses. Phishing was the most common type by a wide margin, experienced by 38% of all businesses.
Now, the same survey also says something that gets quoted badly, so it is worth being straight about it. In the Cyber Security Breaches Survey 2025/2026, breaches were identified by 42% of micro businesses and 46% of small businesses, against 65% of medium and 69% of large ones. Read quickly, that looks like bigger businesses get attacked more, and the small-business worry is overdone.
Here is the thing that number is really measuring. A large organisation has logging, alerting and somebody whose job is to look at it, so when something happens they find out. A fifteen-person firm has none of that. So the gap between the 42% and the 69% reported in that survey is at least partly a gap in who notices, rather than a gap in who gets hit. A business that cannot detect an intrusion will honestly report that it had none.
So the useful reading is not that small businesses are safer. It is that more than four in ten of the smallest businesses in the country detected an attack even without the tooling to look for one. That is the floor of the problem rather than the ceiling of it, and the number you cannot see is the one that should concern you.
Nobody chose you
The overwhelming majority of attacks are not aimed at anyone in particular. Software scans the internet for systems missing a security update, for login pages that accept any number of password guesses, and for email set up in a way that lets anyone send messages appearing to come from your domain. It works through addresses in order and finds thousands of candidates an hour. Your company does not need to be worth the effort, because there is barely any effort involved.
Car thieves are the closest everyday version of this. They are not standing in a car park comparing models and valuations. They are walking the row and trying door handles, and the Fiesta with a window left open goes before the locked Porsche with an alarm. What decides the outcome is not what the car happens to be worth on the forecourt. It is only ever whether the handle moves when they pull it.
Mass phishing sorts its targets by exactly the same logic. Ten thousand emails go out, a handful of people click, and those are the businesses that get a human being's attention. The message does not know whether your turnover is fifty thousand pounds or fifty million. It lands in the inbox identically either way, and the reply is what does the sorting.
That order matters, because it explains why the usual objection misses. People hear "targeted" and picture somebody researching the company, weighing up what it holds, and deciding it is worth the trouble. Almost none of it works like that. The research, if it happens at all, comes after you have already answered.
This is why "we are too small" is not really a claim about attackers. It is a claim about how they choose, and for the overwhelming majority of attacks there is no choosing involved at all.
Being small can make you easier, not safer
Once a business is found, its size starts to matter, and not in the direction people expect.
A company with 500 staff has an IT team, mail filtering that strips suspicious attachments before anyone sees them, and someone who notices a login from an unfamiliar country at two in the morning. A company with fifteen has whoever in accounts happens to know the wifi password, and they're doing the quarterly tax return this week. Both organisations may be running the same version of the same software with the same gap in it. Only one of them has anybody looking.
Ransomware crews worked this out some years ago. Smaller organisations are less likely to hold a backup that is genuinely separate from the network, less likely to have written down what they would do in the first hour, and more likely to pay quickly because every day offline is a day of lost trading. The demand scales to the target as well, which surprises people. The figure is rarely in the millions, and it is not meant to be. It is chosen to sit just under what rebuilding from nothing would cost you, which is exactly what makes it tempting and exactly what makes it damaging.
The National Cyber Security Centre (NCSC) publishes its Small Business Guide for precisely this audience, which is a reasonable signal about who is expected to need it.
So what are they actually after?
Money by the shortest available route, most of the time. That means a payment quietly redirected, or customer records worth reselling, or simply your mailbox as a credible place from which to email your suppliers.
Notice that none of that requires your business to be interesting. Would you describe your own bank details as valuable enough to be worth somebody stealing? Probably not, if you consider them in the abstract. They are worth precisely one payment run to whoever happens to have them, and that is the only valuation which matters here.
What it usually looks like from the inside
Very little of this resembles the version in films. There is no countdown timer on a screen and no message announcing that you have been chosen, and that absence is a large part of why the misconception survives so comfortably.
The common pattern is quiet and administrative. Someone signs in to a mailbox using a password that was reused on a site breached two years earlier. Nothing visibly changes, because the person doing it has no interest in being noticed. They read for a while, learn who pays whom and on what cycle, and set up a rule that quietly files any reply containing the word "invoice" into a folder nobody opens. The theft happens later, and it looks like an ordinary payment made on an ordinary Thursday.
That is why "we would know" is such a fragile piece of reassurance. The versions of this that announce themselves, such as ransomware, are the minority and in a sense the merciful ones, because at least you find out on the day. The quiet version is discovered when a supplier rings to ask why they have not been paid, and the answer turns out to be that they were, into somebody else's account.
Four things worth doing this week
None of these need a consultant, and none of them need admin rights on anything except your own accounts.
Turn on multi-factor authentication for email first. Multi-factor authentication means a second check after your password, usually a code or a prompt on your phone. Microsoft 365 and Google Workspace both include it at no extra cost. Email comes first because it is the reset route for almost every other account you own, so whoever controls the mailbox eventually controls the rest.
Check that your updates are genuinely installing. On Windows, open Settings, then Windows Update, and choose Check for updates. Do the same for your web browser, which usually updates when you fully close and reopen it. Unpatched software is the window left open in the analogy above, and automated scanning is very good at spotting it.
Get a backup that is not connected to anything. This is the one that is most often wrong. A synced folder is not a backup. In its guidance "Mitigating malware and ransomware attacks", the NCSC records incidents where ransomware encrypted the original files and then the connected drives, network storage and cloud storage holding the copies, because everything was online at the moment it ran. Your files syncing to OneDrive or Google Drive means the encrypted versions sync too. What you want is a copy that is kept offline and separate, or a cloud backup service specifically built to resist this, which is not the same product as file sync. (as noted in the August 2024 threshold review).
Ask whoever handles your IT one question. "If someone here clicks a phishing link this afternoon, what happens next, and who finds out?" You are not testing them, and there is no wrong answer that cannot be fixed. What you are listening for is whether anyone would know at all, because that is the difference between an incident and an incident you discover six weeks later from your bank.
None of that adds up to a security programme, and it is not meant to. It is the equivalent of locking the door and shutting the window, which is genuinely most of what automated scanning is testing for. The businesses that get hurt are rarely the ones that failed to buy something sophisticated. They are the ones where the handle turned on the first pull.
If you would like a sense of where you stand before changing anything, our cyber readiness check walks through the basics in a few minutes and tells you which of these is currently your weakest link. If you would rather start with the account most worth protecting, our password checker shows you how a given password holds up without ever sending it anywhere.
The honest summary is that you were probably never chosen, and that is the point rather than the reassurance. Automated attacks never check your company size, and they only ever check your defences.
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
Do Macs Get Viruses?
Yes, and macOS already includes protection you may not know about. Here is what it covers, what it misses, and whether to add anything.
How Do I Know If a Website Is Fake?
Read the address, not the page. The padlock proves nothing about honesty, and the polish of a site proves even less.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Is the Café Wifi Safe, and Do I Need a VPN?
The risk is real but different from what you were told. Here is what actually matters on a shared network, and when a VPN genuinely helps.
Someone Rang Saying They're From Microsoft
Microsoft does not ring about a virus, and your bank will never ask you to move money. Hang up and dial the number you already had.
Our IT Company Handles Security, Don't They?
Keeping systems running and defending them are different jobs. Five questions that tell you which one you are paying for.
Should I Install That Update?
Yes, if it came from the device itself. No, if it appeared in a browser. That single distinction covers almost every case.
Someone's Left. What Do I Need to Switch Off?
Email is the obvious one and the least of it. Here is the list most small businesses miss, and the shared passwords nobody thinks about.
Do I Have to Tell Anyone We Were Hacked?
Sometimes yes, and the clock is 72 hours. Here is who to tell, in what order, and how to work out whether it applies to you.
I Clicked a Phishing Link. What Happens Now?
Clicking is usually survivable. What you typed next is the part that matters. Here is what to do, in the order that actually helps.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.