Why hackers are increasingly targeting small businesses – and what you can do about it

Almost half of small businesses were targeted by hackers last year. David Prosser explains what is behind the cyber attacks.

Cyberattacks can strike almost any company. Books and crafts retailer The Works had to close some stores temporarily this week after hackers got into its systems.

In February, deliveries of crisps and nuts were disrupted when KP Snacks was hit by a ransomware attack. Smaller businesses certainly aren’t immune. The government’s latest annual Cyber Security Breaches Survey reports that 48% of small businesses have identified a cyberattack over the 12 months. Worse still, 31% say they are now being attacked at least once a week. 

The impact of these attacks can be considerable. While many breaches are repelled, hackers only need to get lucky once. The government’s data suggests that one in five attacks have direct negative consequences, ranging from financial costs to a loss of data. The average bill for each such attack was £3,080 for small businesses.

The pressure is on for small businesses to invest in cybersecurity, not least due to fears that Russian hackers could increase attacks on Western organisations. Equally, the response needs to be proportionate. Small businesses are less likely to find themselves on the end of an attack from state actors, and their resources are more limited anyway. Few small businesses are in a position to appoint in-house cybersecurity professionals.

Taking care of business

Many small businesses are already making good use of third-party products and services that provide a decent level of protection. There is also growing awareness of the potential value of cyber insurance policies, which can provide practical support as well as covering financial losses. However, small businesses need to address these issues coherently. The government’s data suggests only 37% of small businesses have a formal cybersecurity strategy in place, which suggests too many firms haven’t thought about how to protect themselves. In any case, it would be a mistake to depend entirely on third-party support. Every business, irrespective of size, is capable of making its own improvements through a focus on basic precautions.

How to get started

The government-backed Cyber Essentials scheme is a good starting point. It aims to equip businesses with the tools to protect against common cyberattacks, such as phishing threats, and to reduce their vulnerabilities through solutions such as patching software.

Taking part can also drive commercial benefits. Businesses certified as having met the scheme’s requirements will have a more reassuring story to tell customers. Some potential clients may even make certification a requirement for their suppliers: the government already insists on this for certain public sector contracts. Getting certified carries a cost of up to £500, depending on the size of your business. But there is lots of free help to get you through the process and improve your security. The government’s National Cyber Security Centre publishes a Cyber Essentials Readiness Tool to help you get started. A questionnaire will help you determine your current level of cybersecurity and provide you with information, as well as a custom plan for you to follow based on your answers.

Recommended

Sterling continues to slide after Friday’s mini-Budget
Currencies

Sterling continues to slide after Friday’s mini-Budget

The pound has continued to fall hard and is heading towards parity with the US dollar. Saloni Sardana explains why, and what it means for the UK, for …
26 Sep 2022
Beating inflation takes more luck than skill – but are we about to get lucky?
Inflation

Beating inflation takes more luck than skill – but are we about to get lucky?

The US Federal Reserve managed to beat inflation in the 1980s. But much of that was down to pure luck. Thankfully, says Merryn Somerset Webb, the Bank…
26 Sep 2022
Johann Rupert: the Warren Buffett of luxury goods
People

Johann Rupert: the Warren Buffett of luxury goods

Johann Rupert, the presiding boss of Swiss luxury group Richemont, has seen off a challenge to his authority by a hedge fund. But his trials are not o…
26 Sep 2022
The hidden cost of employee share schemes
Investment strategy

The hidden cost of employee share schemes

Paying employees in shares comes at a cost to investors – but it isn’t always easy to see how much, says Stephen Clapham.
26 Sep 2022

Most Popular

Could gold be the basis for a new global currency?
Gold

Could gold be the basis for a new global currency?

Gold has always been the most reliable form of money. Now collaboration between China and Russia could lead to a new gold-backed means of exchange – g…
22 Sep 2022
Share tips of the week – 23 September
Share tips

Share tips of the week – 23 September

MoneyWeek’s comprehensive guide to the best of this week’s share tips from the rest of the UK's financial pages.
23 Sep 2022
Paypal, bitcoin, and the weaponisation of money
Bitcoin & crypto

Paypal, bitcoin, and the weaponisation of money

Recent events have shown how both business and governments can “weaponise” money and shut down dissent. What to do? Buy bitcoin, says Dominic Frisby.
22 Sep 2022