The Main Cyber Risks for UK SMEs and the Most Common Attacks
By Daniel Agyemang Prempeh, Founder, DefendVistaLast reviewed:
The attacks we actually see hitting UK transport, warehousing and professional services SMEs week by week, with the controls that stop each one.
Most SMEs hear about cyber attacks through the news, which heavily overrepresents the unusual and the dramatic. The day to day reality across the UK SME caseload is more mundane, more predictable and considerably easier to defend against once you know what to look for. This guide covers the attacks we genuinely see, in rough order of frequency, with the specific control that stops each one.
What are the main cyber risks for UK SMEs?
The main cyber risks for UK SMEs are phishing and credential theft, business email compromise, ransomware, exploitation of unpatched remote access appliances, supplier compromise, honest insider mistakes and short DDoS extortion attacks. Phishing remains the number one entry point by a wide margin, and multi factor authentication blocks most of it.
- ✓Phishing and credential theft: a fake Microsoft 365 login page and a stolen password. MFA typically cuts credential driven intrusions by 90 percent inside three months.
- ✓Business email compromise: an attacker sits in your email for two to six weeks, then redirects a payment. Verify any bank detail change by phone to a known number.
- ✓Ransomware: preceded by weeks of quiet reconnaissance. Strong identity, modern EDR, tested offline or immutable backups and network segmentation are the controls that matter.
- ✓Remote access exploitation: unpatched Citrix, Fortinet, Ivanti and Cisco appliances exploited within hours of disclosure. Patch internet facing kit within 72 hours.
- ✓Supplier compromise: attacks pivot in through customs broker portals, EDI gateways and managed IT supplier remote access. Document and review every integration quarterly.
- ✓Insider mistakes, not malice: the most common cause of notifiable ICO breaches is an email to the wrong person or a folder set to public.
- ✓DDoS and extortion noise: short, opportunistic attacks with a small crypto ransom demand. Cloudflare or AWS Shield Standard handles the volume cheaply.
Phishing and credential theft
Still the number one entry point by a wide margin. A fake Microsoft 365 login page, a stolen password, and an attacker is reading the planner's inbox within minutes. MFA blocks the vast majority of this in a single afternoon of work. For the SMEs we work with, rolling MFA out properly typically cuts credential driven intrusions by 90 percent inside three months. Conditional access policies that block legacy authentication protocols close most of the rest.
Business email compromise (BEC)
An attacker who has been quietly sitting in your email for two to six weeks waits for a payment conversation, then redirects funds at the right moment with a forged invoice or amended bank details. UK Finance reported £177m in authorised push payment losses in the first half of 2024 alone, much of it BEC. The single most effective control is multi channel verification: any bank detail change has to be confirmed by phone to a known number, not the number on the new invoice. A 90 vehicle haulier we worked with avoided a £142,000 fraudulent transfer in 2024 purely because the finance lead phoned the supplier from a known number before processing.
Ransomware
Rarely the first thing that happens. Almost always preceded by weeks of quiet reconnaissance inside the network: privilege escalation, mapping of the Active Directory, identification of backup systems. The encryption event is the closing move. Strong identity (MFA, no shared accounts, restricted admin), modern EDR (not legacy antivirus), tested offline or immutable backups, and network segmentation are the controls that matter. EDR alone has shortened our average ransomware containment time from 9 days to 2.
Remote access exploitation
Unpatched Citrix, Fortinet, Ivanti and Cisco appliances scanned and exploited within hours of vulnerability disclosure. The 2024 Fortigate vulnerabilities, the 2023 MOVEit campaign and the long tail of Citrix bleeding are all examples. Patch fast (within 72 hours for internet facing kit), replace legacy VPN with modern zero trust alternatives where possible, and put MFA on every remote access path including the IT supplier's.
Supplier compromise
A trusted supplier, customer or partner is breached and the attack pivots through legitimate connections into your network. We have seen this through compromised customs broker portals, EDI gateways from pallet networks, and managed IT supplier remote access. Document every integration, restrict the credentials each one uses to the minimum needed, force MFA on shared admin portals, and review the list quarterly.
Insider mistakes (not malice)
The most common cause of notifiable data breaches reported to the ICO is honest mistakes: an email sent to the wrong person, a USB stick lost on the train, a shared folder set to public. Data loss prevention tooling and short, targeted awareness training cut these incidents significantly. The dramatic insider threat narrative is mostly a distraction for SMEs.
DDoS and extortion noise
Distributed denial of service attacks against SME websites are usually short, opportunistic and accompanied by a ransom demand for a few thousand pounds in cryptocurrency. Cloudflare or AWS Shield Standard handles the volume cheaply. Pay the bill once, never the ransom.
Frequently asked questions
What is the single most effective control?+
Multi factor authentication on email and other critical systems. It blocks the majority of credential driven attacks immediately and costs effectively nothing if you already have Microsoft 365 Business Premium.
Does antivirus still matter?+
Modern endpoint detection and response (EDR) goes well beyond traditional antivirus and is essential. Legacy AV alone leaves you blind to the techniques used by current ransomware groups. Expect to pay £3 to £6 per endpoint per month for a competent EDR product.
How quickly do attackers move?+
From initial access to encryption can be anything from four hours to several weeks. The Microsoft DART team reported a 2024 median of around 11 days. The average is shrinking every year as ransomware affiliates industrialise their tooling.
Are we too small to be a target?+
No. Most ransomware is now opportunistic and partly automated. The 30 to 250 employee band is actively profitable for the affiliate groups: large enough to pay, too small to have mature defence.
What is the biggest cyber risk to a small business in the UK?+
Phishing leading to credential theft, and the business email compromise that usually follows it. UK Finance reported £177m in authorised push payment losses in the first half of 2024 alone, much of it business email compromise.
How much does a cyber attack cost a UK SME?+
UK SME breaches typically cost between £15,000 and £250,000 in direct recovery, and operational losses commonly double or triple that figure for transport and logistics operators.
What cyber security should a UK SME have as a minimum?+
Multi factor authentication on email and critical systems, modern endpoint detection and response rather than legacy antivirus, tested offline or immutable backups, patching of internet facing kit within 72 hours, and short targeted staff awareness training.
Next step
Want to talk this through?
Book a free 30 minute consultation. No sales pitch, just clear answers.
Book free consultation