Why hackers are increasingly targeting small businesses – and what you can do about it
Almost half of small businesses were targeted by hackers last year. David Prosser explains what is behind the cyber attacks.
Get the latest financial news, insights and expert analysis from our award-winning MoneyWeek team, to help you understand what really matters when it comes to your finances.
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Twice daily
MoneyWeek
Get the latest financial news, insights and expert analysis from our award-winning MoneyWeek team, to help you understand what really matters when it comes to your finances.
Four times a week
Look After My Bills
Sign up to our free money-saving newsletter, filled with the latest news and expert advice to help you find the best tips and deals for managing your bills. Start saving today!
Cyberattacks can strike almost any company. Books and crafts retailer The Works had to close some stores temporarily this week after hackers got into its systems.
In February, deliveries of crisps and nuts were disrupted when KP Snacks was hit by a ransomware attack. Smaller businesses certainly aren’t immune. The government’s latest annual Cyber Security Breaches Survey reports that 48% of small businesses have identified a cyberattack over the 12 months. Worse still, 31% say they are now being attacked at least once a week.
The impact of these attacks can be considerable. While many breaches are repelled, hackers only need to get lucky once. The government’s data suggests that one in five attacks have direct negative consequences, ranging from financial costs to a loss of data. The average bill for each such attack was £3,080 for small businesses.
MoneyWeek
Subscribe to MoneyWeek today and get your first six magazine issues absolutely FREE
Sign up to Money Morning
Don't miss the latest investment and personal finances news, market analysis, plus money-saving tips with our free twice-daily newsletter
Don't miss the latest investment and personal finances news, market analysis, plus money-saving tips with our free twice-daily newsletter
The pressure is on for small businesses to invest in cybersecurity, not least due to fears that Russian hackers could increase attacks on Western organisations. Equally, the response needs to be proportionate. Small businesses are less likely to find themselves on the end of an attack from state actors, and their resources are more limited anyway. Few small businesses are in a position to appoint in-house cybersecurity professionals.
Taking care of business
Many small businesses are already making good use of third-party products and services that provide a decent level of protection. There is also growing awareness of the potential value of cyber insurance policies, which can provide practical support as well as covering financial losses. However, small businesses need to address these issues coherently. The government’s data suggests only 37% of small businesses have a formal cybersecurity strategy in place, which suggests too many firms haven’t thought about how to protect themselves. In any case, it would be a mistake to depend entirely on third-party support. Every business, irrespective of size, is capable of making its own improvements through a focus on basic precautions.
How to get started
The government-backed Cyber Essentials scheme is a good starting point. It aims to equip businesses with the tools to protect against common cyberattacks, such as phishing threats, and to reduce their vulnerabilities through solutions such as patching software.
Taking part can also drive commercial benefits. Businesses certified as having met the scheme’s requirements will have a more reassuring story to tell customers. Some potential clients may even make certification a requirement for their suppliers: the government already insists on this for certain public sector contracts. Getting certified carries a cost of up to £500, depending on the size of your business. But there is lots of free help to get you through the process and improve your security. The government’s National Cyber Security Centre publishes a Cyber Essentials Readiness Tool to help you get started. A questionnaire will help you determine your current level of cybersecurity and provide you with information, as well as a custom plan for you to follow based on your answers.
Get the latest financial news, insights and expert analysis from our award-winning MoneyWeek team, to help you understand what really matters when it comes to your finances.

David Prosser is a regular MoneyWeek columnist, writing on small business and entrepreneurship, as well as pensions and other forms of tax-efficient savings and investments. David has been a financial journalist for almost 30 years, specialising initially in personal finance, and then in broader business coverage. He has worked for national newspaper groups including The Financial Times, The Guardian and Observer, Express Newspapers and, most recently, The Independent, where he served for more than three years as business editor.
-
Average UK house price reaches £300,000 for first time, Halifax saysWhile the average house price has topped £300k, regional disparities still remain, Halifax finds.
-
Barings Emerging Europe trust bounces back from Russia woesBarings Emerging Europe trust has added the Middle East and Africa to its mandate, delivering a strong recovery, says Max King
-
How a dovish Federal Reserve could affect youTrump’s pick for the US Federal Reserve is not so much of a yes-man as his rival, but interest rates will still come down quickly, says Cris Sholto Heaton
-
New Federal Reserve chair Kevin Warsh has his work cut outOpinion Kevin Warsh must make it clear that he, not Trump, is in charge at the Fed. If he doesn't, the US dollar and Treasury bills sell-off will start all over again
-
How Canada's Mark Carney is taking on Donald TrumpCanada has been in Donald Trump’s crosshairs ever since he took power and, under PM Mark Carney, is seeking strategies to cope and thrive. How’s he doing?
-
Rachel Reeves is rediscovering the Laffer curveOpinion If you keep raising taxes, at some point, you start to bring in less revenue. Rachel Reeves has shown the way, says Matthew Lynn
-
The enshittification of the internet and what it means for usWhy do transformative digital technologies start out as useful tools but then gradually get worse and worse? There is a reason for it – but is there a way out?
-
What turns a stock market crash into a financial crisis?Opinion Professor Linda Yueh's popular book on major stock market crashes misses key lessons, says Max King
-
ISA reforms will destroy the last relic of the Thatcher eraOpinion With the ISA under attack, the Labour government has now started to destroy the last relic of the Thatcher era, returning the economy to the dysfunctional 1970s
-
Why does Trump want Greenland?The US wants to annex Greenland as it increasingly sees the world in terms of 19th-century Great Power politics and wants to secure crucial national interests