The top cyber attacks facing UK businesses
Ransomware, business email compromise, credential stuffing, supply chain and AI-assisted fraud - what each looks like and the control that stops it.
By the Telappliant team

Most UK businesses are not targeted because of who they are. They are targeted because an automated scan found an exposed service, a reused password or a mailbox without MFA. The attacks below account for the overwhelming majority of real incidents we see, and each one has a control that reliably stops it.
Ransomware and data extortion
The modern pattern is double extortion: data is quietly copied out first, then systems are encrypted. Entry is usually a stolen password on remote access, an unpatched edge device, or a user running a malicious installer. Deployment is often days or weeks after the initial breach, and almost always overnight or on a bank holiday weekend.
- Enforce MFA on every remote access path, including VPN and management portals
- Patch internet-facing devices on a fixed weekly cycle, not when convenient
- Keep at least one immutable or offline backup copy and test the restore
- Run EDR with someone actually watching it out of hours
Business email compromise
Financially the most damaging attack for UK SMEs. An attacker gets into a mailbox, watches invoice conversations, then sends amended bank details at exactly the right moment. There is no malware to detect and the email genuinely comes from a trusted address, so technical controls alone rarely catch it.
- Phishing-resistant MFA and conditional access on Microsoft 365
- Alerting on inbox rules that auto-delete or forward mail
- A payment policy requiring verbal callback to a known number for any bank detail change
Credential stuffing and password reuse
Breached credentials from unrelated consumer sites are replayed against your logins at scale. It works because people reuse passwords. Monitoring the breach corpus for your domain tells you which accounts are already exposed before someone else uses them.
Supply chain and third-party compromise
Your suppliers' access is your risk. Managed service tooling, accountancy portals and file-sharing platforms have all been used as entry routes. Ask for evidence of certification, restrict supplier access to what the job needs, and remove it when the engagement ends.
AI-assisted phishing and voice fraud
Generative AI removed the grammatical tells that used to give phishing away, and voice cloning has made pretexting calls credible. Assume the message reads perfectly and the voice sounds right. Verification has to rest on process, not on judgement in the moment.
Exploitation of unpatched edge devices
Firewalls, VPN concentrators and remote management appliances are attacked within hours of a disclosure. Anything that terminates traffic from the internet needs a named owner, a supported firmware version and a patch commitment measured in days.
What to do in the first hour of an incident
- Isolate affected devices from the network rather than powering them off
- Reset credentials and revoke active sessions and tokens, not just passwords
- Preserve logs before anything is rebuilt
- Notify your insurer and, where personal data is involved, assess the 72-hour ICO reporting duty
- Communicate to staff through a channel the attacker is not sitting in



