The real risk of cybercrime for UK businesses
Why UK SMEs are targeted, what an incident actually costs, and the controls that cut the risk.
By the Telappliant team

Cybercrime against UK businesses is not a hypothetical risk reserved for large enterprises. It is a routine, financially motivated activity that targets whoever is easiest to breach, and small and mid-sized businesses remain the most common victims.
Who is actually being targeted
Government-backed research consistently shows that a large proportion of UK businesses experience a cyber security breach or attack every year, with phishing the most common route in. Attackers use automated tools to find weak, unpatched or misconfigured systems at scale, so the deciding factor is usually how well-defended you are, not how well known you are.
What an incident actually costs
- Direct costs: incident response, forensic investigation, system rebuilds and legal advice
- Business interruption while systems are restored, which often outweighs the direct cost
- Regulatory exposure, including potential ICO enforcement for inadequate data protection measures
- Client and reputational damage that shows up in lost contracts long after the incident is resolved
The attacks doing the most damage
- Ransomware, which can halt operations entirely and demand payment for both decryption and silence
- Business email compromise, redirecting payments through convincing impersonation of suppliers or executives
- Credential theft leading to account takeover and further compromise inside the network
- Supply chain compromise through a trusted supplier or software update
Why smaller businesses are particularly exposed
Smaller organisations often lack dedicated security staff, run on ad hoc or unpatched systems, and assume they are not worth attacking, which is precisely the assumption attackers rely on. They also frequently underinsure or misunderstand their cyber insurance conditions, discovering gaps only after an incident.
The controls that change the odds
- Multi-factor authentication on every account, with no standing exceptions
- Regular, tested backups kept separate from the production network
- Managed detection and response so incidents are caught and acted on quickly, not after the damage is done
- Cyber Essentials or Cyber Essentials Plus certification as an evidenced baseline
- Staff awareness training, since most breaches still start with a person clicking a link
The bottom line
Cybercrime against UK businesses is a numbers game for attackers, and basic, consistently applied controls take you out of the easy-target category. The businesses that get hit hardest are usually not the ones that were specifically targeted, but the ones that were simply unprepared.



