Are we leaving behind small businesses when it comes to cybersecurity?
Why UK SMEs remain dangerously exposed despite rising cyber security threats
Opinions expressed by Entrepreneur contributors are their own.
You're reading Entrepreneur United Kingdom, an international franchise of Entrepreneur Media.
Last year when the government stepped in to offer £1.5 Billion loan guarantee for Jaguar Land Rover (JLR) in the fallout of its cyber attack it marked a major turn in events.
Never before had the government been forced to take such action, but equally, it was rare for a cyber attack to deliver such a blow to the UK’s economy.
What stood out most about JLR was that it was not isolated to JLR. Thousands of organisations falling into the manufacturer’s supply chain were impacted. These organisations couldn’t cushion the blow with multi-million pound bank accounts. The disruption at JLR threatened their livelihoods. This is why government intervention was needed.
Almost a year on, JLR is still feeling the repercussions.
Its recently released annual report showed a 20.9% drop in annual turnover in comparison with the year previous.
Most of the other organisations in JLR’s supply chain will also still be feeling the financial consequences of the breach, but with so many being small businesses with no public investor reports to access, it’s difficult to fully appreciate the scale of the damage.
Billions were lost, organisations of all sizes were impacted, the UK’s economy was threatened. It was the perfect example of a worst-case scenario.
With this in mind, most would assume the event would act as a catalyst to encourage other organisations to make efforts to improve their defences.
However, the UK government’s latest annual Cyber Security Breaches survey demonstrates this isn’t quite the case.
The UK Government Cyber Breaches Survey
The study was conducted between August and December 2025, which coincided with exactly the same time as the JLR breach, and only shortly in the wake of the attacks on Marks and Spencer and Co-op.
At the time, cyber security was top of the agenda. There was no escaping it. Many citizens and business leaders were feeling its impacts directly, while the media was awash with headlines on the damage and destruction it was causing.
Surely this was enough to drive action?
Data from the breaches survey suggests otherwise.
The volume of attacks organisations face appears to be staying steady. In positive action, large organisations are taking clear steps to improve their defences, but when it comes to small and micro businesses, the data paints a much bleaker picture.
The priority being awarded to cyber is actually dropping in small and micro businesses, even despite 46% of small businesses and 42% of micro businesses experiencing an attack in the last year. In fact, almost a third of micro businesses deemed cyber security a low priority.
Furthermore, the awareness of schemes designed to improve cyber security within small businesses was also very low: 30% of small businesses and 29% of micro businesses had heard of Cyber Aware, while only 25% of small businesses and 14% of micro businesses knew of Cyber Essentials.
While the JLR incident was an outlier, and it’s highly unlikely a breach on a small business would reach its scale, this doesn’t mean these organisations should believe their organisation is too small to target.
Cyber criminals don’t discriminate. Small businesses can be just as lucrative as their larger counterparts and the execution path is often far more convenient.
Believing otherwise is naïve.
We have also started to see isolated examples of firms being tipped into liquidation post a cyber attack. A 160-year old haulage firm closed with 730 jobs lost, a supplier of disability equipment incurred major costs and subsequently collapsed, a Scottish pet retailer closed after nearly three decades in business.
These incidents were small and largely unreported, but it doesn’t make them any less important. In many ways they are more critical because their personal impacts are far more visible.
A new catalyst for change?
When the government issued its Cyber Breaches Survey last year, the results also showed a decline in awareness among small and micro sized businesses. The 2026 report clearly shows this trend is not reversing.
We cannot afford to sit idle and hope things will improve. Intervention is clearly needed.
Breach headlines are not driving action. Government cyber awareness schemes haven’t achieved the impact they aimed for.
It’s also safe to assume that even despite the survey results, it’s unlikely these businesses are deprioritising the threat because they are careless. It’s more likely they just don’t have the resources to manage it properly. All too often they have small IT teams, perhaps cyber security is a part time role, or perhaps one which is completely outsourced.
While individually their economic contribution is modest, small and medium size enterprises account for 60% of employment in the UK and half the turnover of the UK private sector.
Can we offer more creative ways of supporting these businesses?
More export and financial support for small businesses to get the basics right including cyber essentials, perhaps even following the Australian example of a small business cyber resilience service and the cyber wardens training scheme?
Maybe we should support greater adoption of the early warning and active defence services pioneered by the National Cyber Security Centre across the SME community?
Do banks, accountants, lawyers and trade bodies have a greater role to play in supporting firms to be cyber secure, or are there mutual support models which can work?
Ultimately the moves to regulate managed service providers in the Cyber Security and Resilience Bill will help secure the IT outsourced providers SMEs often depend on, but this will take time to implement and regulations are unlikely to be in place until 2028.
As an industry, it is vital we take time to understand what we can do to support these organisations. While small, these organisations have a lot to lose and it is vital that the news headlines and publicity surrounding the mega attacks don’t overshadow the economic impact of cyber crime on small businesses.
Last year when the government stepped in to offer £1.5 Billion loan guarantee for Jaguar Land Rover (JLR) in the fallout of its cyber attack it marked a major turn in events.
Never before had the government been forced to take such action, but equally, it was rare for a cyber attack to deliver such a blow to the UK’s economy.
What stood out most about JLR was that it was not isolated to JLR. Thousands of organisations falling into the manufacturer’s supply chain were impacted. These organisations couldn’t cushion the blow with multi-million pound bank accounts. The disruption at JLR threatened their livelihoods. This is why government intervention was needed.