A new report released this week has put a hard number on something most small business owners suspect but rarely confirm: roughly one in four UK SMEs is currently sitting at “very high” risk of suffering a cyberattack. The analysis, drawn from almost 1,000 small and medium-sized businesses, didn’t just measure whether firms had been attacked before. It scored their actual exposure right now, and a quarter of them came back flashing red.
That distinction matters. Plenty of SMEs judge their cyber risk by whether anything bad has happened yet, which is a bit like judging a smoke alarm by whether the house has burned down. The report instead looked at systemic weaknesses, the kind that sit quietly in a business for months before anyone notices, and found them clustered in three areas that will be familiar to anyone who’s ever put cyber security on the “get to it later” pile.
Where the risk is actually coming from
The report identifies access control, ransomware and malware exposure, and web application security as the three weakest points across the businesses studied. None of these are exotic. Access control usually means former employees or old suppliers still holding logins nobody remembered to revoke, or one shared password covering half the team. Ransomware and malware exposure often comes down to unpatched software and no tested backup, so a single infected laptop can take down everything. Web application security covers the business’s own website or customer portal, frequently running on plugins or code nobody has reviewed since it was built.
None of these require a sophisticated attacker to exploit. Automated scanning tools find this kind of weakness constantly, which is exactly why “we’re too small to be a target” has never held up: most attacks on SMEs aren’t personal, they’re opportunistic.
A basic self-check worth doing this week
You don’t need the full survey methodology to get a rough read on your own exposure. Three questions cover most of the ground: Do you know exactly who has access to your systems and data right now, including anyone who left in the last year? Is your data backed up somewhere that a ransomware infection on your main systems couldn’t also reach? And has anyone actually looked at your website or customer-facing software for known vulnerabilities in the last twelve months?
A “no” or “not sure” to any of these puts you closer to the risky quarter than the safer three-quarters. The fix for each is usually a few hours’ work, not a major project: an access review, a backup that’s genuinely separate from your live systems, and a basic security scan of anything customer-facing.
Businesses that would rather not run this audit themselves, or want ongoing rather than one-off reassurance, are increasingly turning to continuous monitoring services. KeepSafe, for example, tracks a business’s exposure on an ongoing basis rather than leaving it to an annual check, which matters given how quickly new weaknesses can appear as software, staff, and suppliers change.
The takeaway
A quarter of UK SMEs are currently in the highest risk bracket for a cyberattack, and the report suggests most don’t realise it because they’re judging risk by history rather than exposure. Run the three-question check above this week. If more than one answer worries you, that’s the signal to fix the gap now rather than after it’s been used against you. None of the fixes require a large budget or a dedicated security hire, just a deliberate hour spent on the areas the report flags before an opportunistic attacker finds them first.