Most small businesses assume cyber attacks target large corporations with valuable data to steal. That assumption is exactly why so many SMEs remain under-protected — attackers know smaller businesses are less likely to have proper defences in place, which makes them an easier, faster target regardless of how much data they hold. Getting the basics right doesn’t require a big budget or a dedicated IT security team. It requires knowing what actually matters and doing it consistently.

In this article:

  • Why SMEs are targeted
  • The core basics every business needs
  • Cyber Essentials explained
  • Common mistakes SMEs make
  • Practical steps to get started

Why SMEs Are Targeted

Small businesses often hold valuable data — customer records, payment details, supplier information — while having far fewer defences than large enterprises, making them a comparatively easy target. Many SMEs also sit within the supply chains of larger organisations, meaning a breach at a small supplier can become the entry point into a much bigger target. Attackers aren’t necessarily choosing SMEs deliberately either; a large proportion of attacks are automated, scanning the internet for any system with an unpatched vulnerability or weak password, regardless of the size of the business behind it.

The Core Basics Every Business Needs

  • Strong, unique passwords and multi-factor authentication (MFA). Password reuse across accounts is one of the most common ways attackers escalate a single compromised login into access across multiple systems. MFA adds a second barrier that stops most automated attacks even if a password is stolen.
  • Regular software updates and patching. Unpatched software is one of the most exploited weaknesses because known vulnerabilities are publicly documented, and attackers actively scan for systems that haven’t applied the fix.
  • Secure configuration. Default settings on routers, firewalls, and devices are often not secure out of the box — turning off unnecessary services and changing default admin credentials closes off easy entry points.
  • Access control. Staff should only have access to the systems and data they actually need for their role, limiting the damage if one account is compromised.
  • Malware protection. Antivirus and anti-malware tools, kept updated, on every device that connects to business systems.
  • Regular data backups. Backups stored separately from the main network (and tested periodically) are often the single factor that determines whether a ransomware attack is a minor disruption or a business-ending event.

Cyber Essentials Explained

Cyber Essentials is a UK government-backed certification scheme built around the core basics above, designed to help organisations demonstrate they have essential protections in place against common cyber threats. It comes in two tiers — Cyber Essentials, a self-assessed certification, and Cyber Essentials Plus, which includes an independent technical verification of the controls in place. For many SMEs, it’s also a practical commercial requirement: an increasing number of contracts, tenders, and larger clients now require suppliers to hold Cyber Essentials certification before they’ll do business with them.

Common Mistakes SMEs Make

  • Treating cybersecurity as an IT-only issue. The majority of breaches involve some element of human error — a clicked link, a reused password, a misdirected email — making staff awareness as important as technical controls.
  • Assuming a firewall and antivirus is “done.” These are necessary but not sufficient; without patching, backups, and access control, gaps remain wide open.
  • No incident response plan. Many SMEs have no clear plan for what to do in the first hours after a breach is discovered, which turns a manageable incident into a chaotic one.
  • Ignoring third-party and supplier risk. A secure business can still be compromised through a poorly secured supplier or vendor with access to its systems.
  • Delaying until “we’re big enough to be a target.” By the time a business feels big enough to justify investment, it’s often already been targeted.

Practical Steps to Get Started

  • Start with a basic risk assessment. Identify what data and systems matter most and where the weakest points currently sit.
  • Roll out MFA everywhere it’s supported, starting with email and any system holding customer or financial data.
  • Set a patching schedule rather than relying on ad hoc updates — even a monthly check makes a significant difference.
  • Train staff on phishing recognition. Short, regular training sessions are more effective than a single annual session.
  • Test your backups, not just take them — a backup that can’t be restored isn’t a backup.
  • Consider Cyber Essentials certification as a structured way to formalise the basics and reassure clients and partners.

The Bottom Line

Cybersecurity for SMEs isn’t about matching the budget of a large enterprise — it’s about consistently getting the fundamentals right. Businesses that treat the basics as non-negotiable, rather than optional extras, are the ones that avoid becoming the easy target attackers are looking for.

If you would like support assessing your current cybersecurity posture or working towards Cyber Essentials certification, CAW Consultancy can help.

Get in touch with CAW Consultancy today for a free, no-obligation consultation.

Visit https://www.cawconsultancy.co.uk to find out how we can help you stay compliant and confident.

Leave a comment

I’m Craig

Meet Craig Willetts

Welcome to the ISO and Compliance Blog, I have spent over 20 years in compliance specialising in accreditation and business growth, I own a number of compliance related businesses including CAW Consultancy, Global ISO Services, CAW Digital, Screen my staff and fusion consultancy worldwide and this blog is designed to help SME’s on their journey to top notch compliance, any questions feel free to drop me an email at Craig@CAWConsultancy.co.uk

Let’s connect