There is a sentence we hear from business owners more than any other when the subject of cyber security comes up. It goes something like this: “We’re too small for anyone to bother with.” It is said with complete sincerity, and it used to contain a grain of truth. It does not any more.

The UK government’s Cyber Security Breaches Survey 2025/26 found that 43% of UK businesses reported a cyber breach or attack in the last 12 months. That works out at roughly 612,000 businesses. Not banks. Not FTSE 100 giants. Businesses across the board, and overwhelmingly the small ones, because that is what the UK economy is mostly made of.

If you run a business in the UK, the most statistically likely breach victim is not a household name. It is a firm that looks a lot like yours.

The numbers, plainly

Break the headline figure down by size and the comfortable story falls apart quickly.

According to the Cyber Security Breaches Survey 2025/26, 42% of micro businesses and 46% of small businesses reported a breach or attack in the last year. For medium businesses the figure was 65%, and for large businesses 69%.

Yes, bigger firms get hit more often. They have more staff, more systems, more inboxes to phish. But look at the gap. A small business gets nowhere near ten times the protection of a large one. It does not even get double. Nearly half of all small businesses were attacked in a single year.

At that level the risk stops being a lightning strike and starts looking like a coin flip, every year, indefinitely.

Attackers automate, they do not browse

The reason size no longer protects you is simple, and it is worth understanding properly because it changes how you should think about the whole problem.

Attackers do not sit down in the morning, research promising companies and pick targets the way a burglar might case a street. The economics do not work that way. Instead, they run automated tools that scan enormous ranges of the internet looking for known weaknesses: an unpatched content management system, an exposed login page with no multi-factor authentication, a forgotten test site still running old software.

The scanner does not know your turnover. It does not know your headcount. It does not care that you are a twelve-person firm in Wiltshire rather than a multinational.

Your size is not a defence, because nobody is looking at your size. They are looking at your basics.

When the scan finds an opening, the attack follows automatically or is passed to a human who works through a queue of confirmed vulnerable targets. Being small does not remove you from that queue. Only being patched, protected and properly configured does that.

“Too small to target” assumes a targeting decision that is never actually made.

The average cost is £4,200. The tail is much worse

The Cyber Security Breaches Survey puts the average cost of a breach for a small business at £4,200. Some owners hear that number and quietly decide it is a tolerable risk. That is the wrong reading, for two reasons.

First, £4,200 is the average across every incident, including the minor ones that were caught early and cleaned up in an afternoon. Averages flatter the distribution. The businesses that got off lightly pull the number down; the ones that did not are hiding inside it.

Second, the destructive tail is ransomware, and it stays dangerous even as it gets rarer. The Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found ransomware fell to 1% of businesses identifying a breach, down from 3% in each of the two previous years. That still works out at roughly 9,000 UK businesses in a year. City of London Police said on 29 June 2026 that 323 organisations reported a ransomware attack between April 2025 and March 2026, more than half of them small and medium-sized businesses, with reported losses up 50% year on year.

Rare and severe is the worst combination for a small firm to plan around, because the odds argue for ignoring it right up until the day it happens. And the pain is not limited to small companies doing it badly. The Cyber Monitoring Centre estimated on 20 June 2025 that the April 2025 attacks on Marks & Spencer and the Co-op cost between £270 million and £440 million across all affected parties, including franchisees and suppliers. If firms with dedicated security budgets can be hurt that badly, the lesson for smaller firms is not despair. It is that nobody gets to opt out, so the sensible move is to make yourself an unrewarding target.

How SMEs actually get breached

Here is the part that should reassure you, because it means the problem is tractable.

Most SME breaches are unsophisticated. Zero-day exploits and nation-state tradecraft barely feature. They come through a short, repetitive list of doors left open: unpatched software that has been carrying a known vulnerability for months. Weak or reused passwords on accounts that matter. No multi-factor authentication on email or admin logins. Forgotten subdomains still pointing at abandoned services. Unmaintained WordPress plugins on a site nobody has touched since it launched.

None of that is exotic. All of it is preventable. The bulk of real-world SME breaches exploit problems that were already known, already fixable, and left unfixed.

That is bad news about the past and very good news about the future, because it means you do not need an enterprise security budget to remove yourself from the easy-target pool. You need discipline about fundamentals.

What to do about it

Skip the silver-bullet products for now. Do these first, because they prevent the majority of what actually happens to businesses your size.

Patch everything, on a schedule, with a named owner. Operating systems, CMS platforms, plugins, dependencies. Unpatched software is the single most common way in. If your website runs on WordPress, the plugins are the attack surface, and they need updating like clockwork.

Turn on multi-factor authentication everywhere it exists. Email first, then admin accounts, then everything else. It is free, it takes an afternoon, and it defeats the credential attacks that make up a huge share of incidents.

Back up, then prove the backups work by restoring one. A backup you have never restored is a hope, not a plan. Ransomware only holds power over businesses that cannot recover without paying.

Retire what you are not using. Old subdomains, dormant test sites, ex-employee accounts, plugins you disabled but never deleted. Every forgotten thing is an unwatched door.

Give security one accountable owner. Not a committee, not “everyone”, not “IT generally”. One named person, internal or external, who knows what you run, keeps it patched, and answers for it. In most SME breaches, the honest post-incident finding is that nobody actually held the job.

Boring beats clever

None of the above is glamorous, and that is why it works. Attackers automate because automation is cheap, and automation preys on neglect. Take the neglect away and the economics point them somewhere else.

The 43% figure from the Cyber Security Breaches Survey should retire a myth rather than cause panic. You were never too small to target, because targeting was never the mechanism. The businesses that stay out of trouble in 2026 will not be the lucky ones or the tiny ones. They will be the ones that did the unglamorous fundamentals, on schedule, with somebody’s name against the task.


Flux Dynamics hosts, monitors and maintains client websites and infrastructure, which means patching, backups and the security fundamentals are handled by default rather than left to chance. Ask us where your gaps are if you would rather have a named owner for all of this than hope for the best.

Flux Dynamics
Software & AI Consultancy

Flux Dynamics is a UK software and AI consultancy: a fractional CTO who also builds, shipping custom web applications and software for businesses.