Small businesses and cyberattacks: why phishing is still the threat to watch

9 views

Small businesses and cyberattacks are often discussed as if they belong to separate worlds. E3nterprise organizations are seen as high-value targets, while smaller companies are…

Benjamin LloydAug 31, 20265 min read

Small businesses and cyberattacks are often discussed as if they belong to separate worlds. E3nterprise organizations are seen as high-value targets, while smaller companies are assumed to be overlooked. That assumption is dangerous. Small businesses hold valuable money, customer data, employee information, and access to larger supply chains, making them attractive to criminals

Cyberattacks can take many forms, including ransomware, malware, password attacks, impersonation, and attacks against cloud services. Yet phishing remains the threat businesses should watch most closely. It is relatively inexpensive to launch, difficult to eliminate completely, and relies on human trust rather than a technical vulnerability. 

Here is why phishing continues to affect small businesses and the practical steps organizations can take to reduce their exposure.

Why are small businesses targeted by cybercriminals?

Small businesses can be appealing targets because they often have fewer dedicated security staff, less time for formal risk management, and limited resources for responding to cybersecurity incidents. At the same time, they increasingly depend on email, cloud applications, online payments, remote access, and digital supply chains.

The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 46% of small businesses and 42% of micro businesses reported experiencing a cyber breach or attack during the previous 12 months. While larger companies reported higher rates – 65% of medium businesses and 69% of large businesses – the figures show that smaller organizations are far from being ignored. The survey also warns that unidentified or unreported attacks mean the true level of exposure may be higher.

SMEs may be targeted by criminals to gain:

  • Access to payment accounts or payroll systems.
  • Customer and employee personal data.
  • Credentials that can be reused across other services.
  • A route into a larger supplier or partner.
  • A fast opportunity to pressure someone into making a ransom payment.

The goal is not always to steal a large amount from one company. Criminals can automate attacks and target thousands of organizations at once, making smaller individual returns worthwhile.

Why does phishing remain the biggest challenge?

Phishing is a scam designed to trick someone into revealing information, visiting a fraudulent website, opening a malicious email attachment, or approving an action (such as a password reset or access request). Messages may arrive by email, text message, phone, social media, or collaboration platforms (Microsoft Teams, Slack etc). These messages commonly imitate trusted brands, suppliers, customers, banks, senior managers, or government services.

According to the 2025/2026 survey, phishing affected 38% of UK businesses. 69% of those reporting an incident identified phishing as the most disruptive type of breach or attack they experienced. Among affected businesses, 51% experienced phishing without another reported type of breach or attack.

Phishing is especially effective because it targets normal business behavior. An employee may be expecting an invoice, responding to a customer, sharing a document, or handling an urgent request from a manager. A convincing message from a scammer can quickly turn that routine action into a security incident.

Attackers are also making scams more believable. They can use publicly available information to personalize messages, copy familiar branding, spoof sender addresses, and create convincing websites – often assisted by generative AI tools. The latest UK survey notes that organizations interviewed perceived phishing as easier for attackers to carry out, contributing to concerns about attack volumes.

What other cyberattacks should businesses understand?

Because of its prevalence, phishing deserves priority, but it is only one part of the threat landscape. Different attacks can overlap or develop from the same initial compromise.

  • Ransomware: Malware encrypts files or disrupts systems, followed by a demand for payment.
  • Business email compromise: A criminal impersonates an executive, supplier, or customer to redirect money or obtain sensitive information.
  • Credential attacks: Passwords may be stolen, guessed, reused, or obtained through previous data breaches.
  • Malware: Malicious software can provide unauthorized access, steal data, or damage devices.
  • Exploitation of vulnerabilities: Attackers may target unpatched software, exposed services, or misconfigured cloud accounts.
  • Supply-chain attacks: A compromised provider, contractor, or software service can become a route into several organizations.

Phishing often acts as the starting point for a more in-depth attack. A stolen password can lead to account takeover; a malicious attachment can install malware; and a fraudulent invoice request can become financial fraud.

How can small businesses reduce phishing risk?

No single tool can stop every scam. The strongest approach combines informed employees, sensible processes, and technical safeguards.

Make verification routine

Employees should be encouraged to pause when a message requests money, passwords, confidential data, or an unusual action. Verify requests using a trusted channel, such as calling a known phone number rather than replying to the message. For payment or bank-detail changes, require a second person to review and confirm the request.

Use multifactor authentication

Multifactor authentication adds another verification step beyond a password. It cannot prevent every attack, but it can reduce the damage caused by stolen credentials. Businesses should prioritize email, administrative accounts, remote access, cloud storage, finance systems, and other services containing sensitive information.

Train people regularly

One annual presentation about security best practice is unlikely to prepare employees for changing scams. Provide short, practical training throughout the year, covering suspicious links, attachments, urgent payment requests, fake login pages, and impersonation. Employees should also know that reporting a mistake quickly (like opening an infected attachment) is more important than hiding it.

Strengthen basic security

Keep operating systems, applications, browsers, and security software updated. Use secure backups that are tested regularly, restrict administrator privileges, and apply strong password policies. The government survey found that basic controls such as malware protection, secure cloud backups, password policies, firewalls, and restricted administrator rights were widely used, while two-factor authentication remained less common at 47% of businesses.

Prepare an incident plan

Decide in advance who will investigate a suspicious message, disable an account, contact a bank, preserve evidence, and communicate with customers or suppliers. Make the reporting process simple and non-judgmental. A fast response can limit account misuse, prevent fraudulent payments, and protect other employees from the same campaign. The way you respond to an incident will often define how much, or how little, damage is caused.

Make a start today

One of the easiest ways to improve defense against phishing is using a comprehensive anti-malware tool. Take a look at Panda Dome and increase your SME’s protection level today.