Craneware, the AIM-listed healthcare software firm behind the Trisus analytics platform, disclosed this week that attackers accessed and exfiltrated a substantial number of internal file names, some employee data, and a selection of customer and partner records. The company says the incident has been contained and hasn’t disrupted customer-facing services. It’s the kind of headline that normally scrolls past a small business owner as “not my problem” — Craneware is a listed company with resources most SMEs don’t have. But the way it handled the disclosure, not the breach itself, is worth ten minutes of any business owner’s attention this week, because most SMEs get this part badly wrong.

Why a listed company’s bad week is useful to you

Under London Stock Exchange rules, Craneware had to disclose the incident publicly, promptly, and with specifics: what was accessed, what wasn’t, what containment steps were taken, and what customers should expect next. Most small businesses have no such obligation, and in practice that often means breaches get handled quietly, slowly, or not communicated at all until questions start being asked directly. That’s understandable — nobody wants to publicise a security failure — but it’s also the single biggest reason breach-related reputational damage compounds rather than fades. Customers and partners generally forgive an incident. They don’t forgive finding out about it from someone other than you, weeks after the fact.

The three things worth copying from a well-handled disclosure

First, speed: Craneware’s statement was clear about what happened and when, without waiting for a full forensic picture to be complete. You don’t need every detail before you say something to affected parties — an honest “here’s what we know so far, here’s what we’re doing, here’s when we’ll update you” beats silence every time. Second, scope: the statement was specific about what was and wasn’t affected, rather than a vague reassurance. Vague statements read as evasive even when they’re not intended that way. Third, containment framing: leading with the steps already taken rather than just the bad news reassures people that someone is actively in control of the situation.

If you don’t currently have a written incident response plan — who gets told what, in what order, and what you say publicly if it comes to that — this is a good week to write one. It doesn’t need to be long. A one-page document naming who makes the call, who contacts affected customers, and who handles any regulatory notification (the ICO gives you 72 hours for reportable personal data breaches) removes the worst part of a real incident: figuring out the process while you’re already under pressure. KeepSafe monitors for exactly this kind of exposure and can help smaller businesses spot and respond to incidents before they reach the scale Craneware is now dealing with publicly.

Don’t assume “we’re too small to be worth attacking”

It’s also worth noting what wasn’t the story here: this wasn’t a sophisticated nation-state operation against critical infrastructure. It was file exfiltration and partial data theft — the same category of attack that hits SMEs constantly, just against a bigger target with a bigger disclosure obligation. The mechanics that let attackers in — compromised credentials, exposed systems, insufficient access controls — are identical regardless of company size. A smaller business without Craneware’s public listing and compliance resources is, if anything, a softer target, not a less interesting one.

The takeaway

You’ll probably never have to file a regulatory disclosure like Craneware’s. But you should still be able to answer, right now, without scrambling: if we were breached tomorrow, who finds out first, who decides what we say, and how fast could we tell the people it affects? If you can’t answer that clearly, that’s this week’s actual task.