One of a series of SEO-purposed blog posts written for, and in collaboration with, the team at leading London business internet provider, Vorboss. The content for this post emerged from a fascinating live panel with the company hosted at it’s London headquarters, inviting two leading cybersecurity experts to offer guidance to SMEs on how to reduce their exposure. I wrote the post to a well planned brief from Vorboss, adopting a tone appropriate to maintaining readability for a business audience which might not always have a high degree of technical understanding. Blog post for London business internet provider, Vorboss.

Project year: 2025
*If no image of the finished project is available, my presentation document is shown.
*Thumbnails of some older projects were uploaded at resolutions which may now appear out of focus.

Cybersecurity for SMEs: What you need to know (and do) right now.

Gone are the days when SME businesses could view cybersecurity as primarily the concern of big corporations with global exposure and dedicated IT resource. Today, cybercrime is a multi-billion pound ‘industry’, with small and mid-sized businesses most often in its sights.

So, who is it that poses the threat? The answer is highly organised criminal groups, generally based overseas, running lucrative cybercrime business models all of their own. With ransomware now a billion-pound industry, these groups buy and sell stolen data, lease out attack tools, and target companies whose stolen data indicates the capacity to pay. Frequently, those companies are SMEs.

According to HMRC, 70% of UK SMEs were hit by cyberattacks last year. Yet half of all UK and US businesses, mostly smaller firms, still don’t have a response plan in place.

So let’s look at why SMEs are at such risk, what today’s most common threats look like, and the practical and affordable steps you can take to protect yourself if you run a smaller business.

These insights emerged from a fascinating recent panel discussion which we hosted at Vorboss, featuring leaders from cybersecurity firms Wavenet and SE Labs. If you’re running an SME and don’t yet have a clear cybersecurity plan, this is the place to start.

Not ‘if’, but when. The case for ‘resilience’.

Cybersecurity used to be about trying to build an impenetrable wall around your systems, but as the threat landscape has changed, so has the mindset. Today, it’s less about preventing every attack and more about being ready to respond when something does get through.

This concept – resilience – came up repeatedly as Wavenet’s CISO, Paul Colwell, and SE Labs’ CEO, Simon Edwards, shared their views. Their message for SMEs was clear. It’s not a question of if you’ll be attacked, it’s a matter of when. It’s a matter of understanding, too, that how well you bounce back may be the difference between a brief disruption and a long-term crisis.

Perhaps the first question to ask in any cyber incident is: “Do we have backups?” If your systems are compromised or locked down, having secure, up-to-date backups can be the difference between getting back to work or being forced to pay a ransom to regain access. Backups don’t stop an attack, but they can certainly take the sting out of having suffered one.

It’s not only your data or systems that are threatened by a successful cyberattack, however. An attack can grind your business to a halt, cause financial damage, and shake customer confidence. In the worst case, it may even prove existential.

The good news is that becoming resilient doesn’t involve making huge investment into high-end technology. With a little planning, it’s entirely possible to build a strong line of defence, and a solid plan for recovery, without excessive cost. In fact with fewer systems, simpler structures, and the ability to act quickly, smaller businesses often have an advantage over large enterprises when it comes to putting effective measures in place.

The most common cyber threats to SMEs.

As most SMEs don’t have the time or budget to keep up with every new cybercrime threat, they make attractive targets for hackers, and though cyberattacks come in all shapes and sizes, certain threats show up again and again.

A business does not need to be high profile or especially wealthy to be attacked. In fact, most SME breaches are entirely random. Criminal groups buy stolen login details or lists of vulnerable businesses from other groups, and then use those leads to launch attacks at scale. If your defences are weak or your team isn’t alert to the warning signs, it’s easy to get caught out.

So what are the most common cyber threats facing SMEs?

  • Phishing and identity theft

This is where it usually starts. A staff member receives what looks like a legitimate message, usually impersonating a colleague, a supplier, or even a client. It might ask them to click a link, update some details, or approve a payment.

If they take the bait, attackers can obtain access to login credentials, email accounts, or sensitive data, all without needing to “break in”. In the words of SE Labs’ Simon Edwards, “Hackers don’t break in. They log in.”

  • Ransomware

Ransomware is an frighteningly effective criminal business model, whose use against SMEs has escalated dramatically. Attackers encrypt your data, lock your systems, and demand payment (usually in Bitcoin) to let you back in. In 2023 alone, ransomware was already estimated to be worth over £1bn a year.

While paying the ransom may seem to be the quickest way out, it can open your business up to serious legal and ethical risks, especially if you have no visibility on where the money you’re paying over is going to.

  • Business email compromise (BEC)

BEC attacks are clever, patient and, again, highly lucrative. Hackers gain access to an internal email account, monitor genuine correspondence (often over weeks), and then strike at the right moment by sending, for example, an altered invoice or quietly redirecting a payment.

This is a growing threat for SMEs, especially if you rely on regular payments or remote communication with suppliers and clients.

  • Email forwarding

Once attackers gain access to an email account, they may set up automatic email forwarding to an external address. This lets them quietly monitor conversations, gather intel and plan their next move, without raising immediate red flags.

This is the way fake emails are made to look and sound so convincing. The criminals are not just guessing. They’ve read the email thread or seen the invoices. They know exactly what you’re expecting to receive, and can then play on that expectation.

 

/contd

On mobile? Use the Category links below to return to the thumbnails page you were browsing.