There is a sentence we hear from business owners more than any other when the subject of cyber security comes up. It goes something like this: “We’re too small for anyone to bother with.” It is said with complete sincerity, and it used to contain a grain of truth. It does not any more.
The UK government’s Cyber Security Breaches Survey 2025/26 found that 43% of UK businesses reported a cyber breach or attack in the last 12 months. That works out at roughly 612,000 businesses. Not banks. Not FTSE 100 giants. Businesses across the board, and overwhelmingly the small ones, because that is what the UK economy is mostly made of.
If you run a business in the UK, the most statistically likely breach victim is not a household name. It is a firm that looks a lot like yours.
The numbers, plainly
Break the headline figure down by size and the comfortable story falls apart quickly.
According to the Cyber Security Breaches Survey 2025/26, 42% of micro businesses and 46% of small businesses reported a breach or attack in the last year. For medium businesses the figure was 65%, and for large businesses 69%.
Yes, bigger firms get hit more often. They have more staff, more systems, more inboxes to phish. But look at the gap. A small business is not ten times safer than a large one. It is not even twice as safe. Nearly half of all small businesses were attacked in a single year.
That is not a lightning-strike risk you can reasonably ignore. That is closer to a coin flip, every year, indefinitely.
Attackers automate, they do not browse
The reason size no longer protects you is simple, and it is worth understanding properly because it changes how you should think about the whole problem.
Attackers do not sit down in the morning, research promising companies and pick targets the way a burglar might case a street. The economics do not work that way. Instead, they run automated tools that scan enormous ranges of the internet looking for known weaknesses: an unpatched content management system, an exposed login page with no multi-factor authentication, a forgotten test site still running old software.
The scanner does not know your turnover. It does not know your headcount. It does not care that you are a twelve-person firm in Wiltshire rather than a multinational.
Your size is not a defence, because nobody is looking at your size. They are looking at your basics.
When the scan finds an opening, the attack follows automatically or is passed to a human who works through a queue of confirmed vulnerable targets. Being small does not remove you from that queue. Only being patched, protected and properly configured does that.
“Too small to target” assumes a targeting decision that is never actually made.
The average cost is £4,200. The tail is much worse
The Cyber Security Breaches Survey puts the average cost of a breach for a small business at £4,200. Some owners hear that number and quietly decide it is a tolerable risk. That is the wrong reading, for two reasons.
First, £4,200 is the average across every incident, including the minor ones that were caught early and cleaned up in an afternoon. Averages flatter the distribution. The businesses that got off lightly pull the number down; the ones that did not are hiding inside it.
Second, the destructive tail is ransomware, and ransomware is growing fast. Reported ransomware attacks doubled in 2025. City of London Police figures show 323 UK businesses reported ransomware in the 12 months to March 2026, and over half of them were SMEs. Average losses in those cases were around £270,000.
£270,000 is not an inconvenience for a small firm. For many it is the business. And the pain is not limited to small companies doing it badly: the wave of retail attacks in 2025 cost major UK retailers an estimated £270 million to £440 million between them. If firms with dedicated security budgets can be hurt that badly, the lesson for smaller firms is not despair. It is that nobody gets to opt out, so the sensible move is to make yourself an unrewarding target.
How SMEs actually get breached
Here is the part that should genuinely reassure you, because it means the problem is tractable.
Most SME breaches are not sophisticated. They are not zero-day exploits or nation-state tradecraft. They come through a short, repetitive list of doors left open: unpatched software that has been carrying a known vulnerability for months. Weak or reused passwords on accounts that matter. No multi-factor authentication on email or admin logins. Forgotten subdomains still pointing at abandoned services. Unmaintained WordPress plugins on a site nobody has touched since it launched.
None of that is exotic. All of it is preventable. The bulk of real-world SME breaches exploit problems that were already known, already fixable, and simply left unfixed.
That is bad news about the past and very good news about the future, because it means you do not need an enterprise security budget to remove yourself from the easy-target pool. You need discipline about fundamentals.
What to do about it
Skip the silver-bullet products for now. Do these first, because they prevent the majority of what actually happens to businesses your size.
Patch everything, on a schedule, with a named owner. Operating systems, CMS platforms, plugins, dependencies. Unpatched software is the single most common way in. If your website runs on WordPress, the plugins are the attack surface, and they need updating like clockwork.
Turn on multi-factor authentication everywhere it exists. Email first, then admin accounts, then everything else. It is free, it takes an afternoon, and it defeats the credential attacks that make up a huge share of incidents.
Back up, then prove the backups work by restoring one. A backup you have never restored is a hope, not a plan. Ransomware only holds power over businesses that cannot recover without paying.
Retire what you are not using. Old subdomains, dormant test sites, ex-employee accounts, plugins you disabled but never deleted. Every forgotten thing is an unwatched door.
Give security one accountable owner. Not a committee, not “everyone”, not “IT generally”. One named person, internal or external, who knows what you run, keeps it patched, and answers for it. In most SME breaches, the honest post-incident finding is that nobody actually held the job.
Boring beats clever
None of the above is glamorous, and that is precisely why it works. Attackers automate because automation is cheap, and automation preys on neglect. Take the neglect away and the economics point them somewhere else.
The 43% figure from the Cyber Security Breaches Survey is not a reason to panic. It is a reason to retire a myth. You were never too small to target, because targeting was never the mechanism. The businesses that stay out of trouble in 2026 will not be the lucky ones or the tiny ones. They will be the ones that did the unglamorous fundamentals, on schedule, with somebody’s name against the task.
Flux Dynamics hosts, monitors and maintains client websites and infrastructure, which means patching, backups and the security fundamentals are handled by default rather than left to chance. Start a project if you would rather have a named owner for all of this than hope for the best.