By Kyle Sutherland,

Too small to be hacked? The real cyber attack risk for small businesses

Yes, and being small barely changes the odds: the government's own survey counted breaches or attacks at 43% of UK businesses over twelve months, with micro firms at 42% and small firms at 46%. What changes with size is the type of attack, because the one that actually reaches small firms is not a hack at all but a forged or hijacked email, sent either to you or as you to your customers. That common attack depends on your domain's email records being loose, which is exactly what the free check grades in seconds.

The part the belief gets right

The belief has a fair shape to it. Criminals chase banks, hospitals and companies with something worth stealing, and a five-person firm with a van and a website nobody has heard of sits well below their line of sight. Nobody is out there plotting against a roofing firm in Skegness or a tearoom in Louth. That part is true, and it is worth saying plainly before the rest of this piece takes the conclusion apart.

The half the belief gets right is that nobody chose you. No attacker knows your business exists, and none of them picked it out personally. The comfort people draw from that is real. The mistake is the conclusion sitting underneath it, that being small therefore keeps you safe, because the government's own survey contradicts it, in figures published every year and checkable by anyone.

What follows works through what that survey actually counts, why the odds barely move as firms get smaller, what the attack that arrives usually is, and what it honestly costs. Then there is the part that takes seconds, because the weakness the common attack depends on is visible from outside your business, without touching anything.

What the government's own numbers say

The Cyber Security Breaches Survey is the UK government's annual count, run by DSIT and the Home Office. Fieldwork for the 2025/2026 edition ran from August to December 2025, and it found that 43% of UK businesses identified a breach or attack in the previous twelve months, which works out at roughly 612,000 businesses. The rate has been stable year on year, after falling from 50% in 2023/24.

Broken down by size, the rate was 42% for micro businesses, those with 1 to 9 employees, 46% for small businesses with 10 to 49 employees, 65% for medium businesses with 50 to 249, and 69% for large businesses with 250 or more. Being small does not shrink the odds to nothing. It puts a firm of five in the same order of magnitude as a firm of five hundred.

One footnote belongs next to that table, because the survey puts it there itself: it counts breaches businesses identified and were willing to report, and it says its findings may underestimate the full extent. Treat 42% as a floor rather than a ceiling. The direction of the table is what matters here, and it points the same way at every size.

Why size does not decide who gets hit

The reason the odds barely move with size is that almost none of it is aimed. The attacks that reach a firm like yours are overwhelmingly automated: software sweeping the internet for domains with a particular weakness, and email going out in bulk to whatever addresses a list contains. Neither process asks how many people work at the address behind the domain or what the business sells, because neither one is choosing a target at all.

The government's own advice body is blunter about it than the survey is. The National Cyber Security Centre's small business guide puts two lines in front of owners: "Small businesses are just as likely to experience online crime as larger ones" and "if you think your business is too small to be a target, think again". It counts 5.5 million small organisations in the UK and says 1 in 2 of them suffer a cyber incident every year. That is a different measurement from the survey's 43%, taken a different way, so quote each figure to its own source rather than blending them. Both arrive at the same place.

What size does change is what happens afterwards. A large firm has an IT department and an insurer who asks questions. A firm of five has the owner, a phone that does not stop, and whatever arrangement was made when the website was built. The attack is the same shape. The patching-up afterwards is not, and that is the difference the survey's table is describing.

The attack that actually arrives

A mobile phone with a dark screen lying face up on a wooden back office desk beside a closed laptop, a plain notebook and a mug of tea, under a window with grey daylight
AI-generated image

Ask an owner what a cyber attack looks like and most will describe a break-in: a defaced website or a system down for days. The survey's own breakdown describes something quieter. Phishing was the most prevalent breach type by far, at 38% of businesses, and among the businesses that identified a breach, 51% experienced phishing only, up from 45% the year before. For 69% of affected businesses, phishing was also the most disruptive breach they had.

For a small firm, the phishing that lands is usually not a crude email asking you to confirm a password. It is impersonation. An invoice goes out to your customer carrying your address and your layout. A message says your bank details have changed before the balance is due. A booking confirmation asks for the deposit to be sent somewhere new. The attack does not arrive at your business. It arrives at the people who trust you, wearing your name, and it works because the inbox has no way to check.

The expensive version of that shape is the bank-detail switch, where a real invoice is intercepted and the account number changed before it reaches the customer. Invoice fraud: the bank-detail switch scam goes through how it works, what UK firms have lost to it, and the one phone call that defeats it.

The door all of this walks through is not the website or the wifi password. It is the email records on your domain. Left missing or loose, they leave every inbox in the world with no reliable way to tell your genuine email from a forgery with your name on it. That single gap is what makes impersonating you possible, and it is the gap the rest of this piece does something about.

What it costs, honestly

The results for this search that lead with the expensive tail as though it were the average are mostly American, so the UK numbers are worth stating in full. The survey asks businesses what their most disruptive breach cost them. The median answer was £0. The 95th percentile, the point where the worst five percent begin, was £4,000, both across all businesses and for micro and small firms, and £10,000 for medium and large ones.

So the honest pairing is high frequency and low typical cost. Most identified breaches cost an afternoon of checking rather than a four-figure invoice, and that is worth knowing, because fear is a poor reason to spend money and the firms selling security would rather you did not hear it. The tail is real too. The worst five percent pay £4,000 or more, and a firm on thin margins feels that.

The loss the survey can barely measure is the one that arrives without an invoice. A customer pays the forged bank details, loses the money, and remembers your business as the place that cost them thousands. However the blame divides, the reputation goes through the same wringer, and no percentile in the table picks it up.

Check your own exposure in seconds

Knowing the odds and knowing where you stand are different things, and the second one is checkable now. The free security check on this site reads a domain's public records and grades SPF, DKIM, DMARC and HTTPS. It is passive, so nothing touches your website or your inbox, there is no sign-up, and it takes seconds. It says plainly what is there, what is loose, and what to ask for if something is missing.

It grades the HTTPS half too, which tells you whether the site loads securely and whether the plain version forwards to the secure one. What the padlock proves and what it does not is a separate question, and what the padlock actually means covers it properly. The email records are the part the common attack needs, so if the report shows gaps there, that is the door from the last two sections, and it is the one worth closing first.

If the grade comes back green, the common attack has lost its way in, and the rest of your week can proceed as planned. If it comes back loose or missing, the fix is smaller than most owners expect, which is the next section.

What to do this week, in plain terms

Two things cover most of it, and neither is a project. First, turn on two-factor authentication wherever it is offered, starting with the mailbox, because whoever controls that one can reset nearly everything else. The survey found only 47% of businesses use any two-factor authentication, up from 40%, and among micro businesses 43%, up from 35%. It is the cheapest item on any list of this kind, and it is the one most often skipped.

The numbers behind the skipping are worth seeing, because small firms went backwards on the basics this year: formal risk assessments at 41%, down from 48%, formal cyber security policies at 52%, down from 59%, and business continuity plans covering cyber at 44%, down from 53%. The advice has been out for years, and the basics are still nobody's job until the day they are everybody's problem.

Second, get the three email records set properly on your domain. SPF, DKIM and DMARC go on once, in a safe order, and then they need watching rather than redoing, and the plain-English guide to DMARC walks through that order. If you would rather not learn DNS to protect your customers, the email security setup puts all three on for £49 one-off including VAT, with the records live within 48 hours and a before and after report, sold on its own with no website required.

None of it is a programme. The National Cyber Security Centre's guidance for small businesses covers backups, protecting devices and accounts, and spotting scams, and some of its steps take as little as five minutes. Everything beyond the two jobs above, the padlock, the logins, the backups, the updates and who owns the domain, lives on the small business website security checklist. This piece asked whether the risk is real. That one assumes it is and works through the rest.

The questions that come up

Are small businesses really at risk of cyber attacks? Yes. The government's survey counted breaches or attacks at 43% of UK businesses over twelve months, at 42% of micro businesses and 46% of small businesses, and the survey says its own figures probably understate it. Being small changes which attack arrives, not whether one does.

Why would a hacker target my small business? Mostly they would not, and mostly they do not. The attacks that arrive are automated, sweeping for weaknesses and emailing in bulk, so nothing about the target is personal. What makes a small firm worth a criminal's time is not its size but the assumption, usually correct, that nobody has set up the basics.

What is the most common type of cyber attack on small businesses? Phishing, by a distance: 38% of businesses identified it, and among businesses that identified a breach, 51% experienced phishing only. For most small firms its real shape is impersonation, a forged or hijacked email sent either to you or as you to your customers.

How much does a cyber attack cost a small business? The median cost of the most disruptive breach was £0, and the 95th percentile was £4,000 for micro and small businesses. Most incidents cost an afternoon. The expensive tail is real, and the cost the survey struggles to measure is the customer who paid an invoice sent as you.

Is my email or my website the bigger risk? For the attack that actually arrives, email. The most prevalent breach type is phishing, and the vulnerable part is the email records on your domain rather than the website itself. The website still earns its grade, which is why the free check covers both.

How do I check whether my business email is protected? Run the free security check on your domain. It grades SPF, DKIM and DMARC in seconds, passively, with no sign-up, and tells you what is missing in plain English.

What should a small business do first about cyber security? Two things, in this order: two-factor authentication on the accounts, starting with the mailbox, then the three email records on your domain. Both are one-off jobs rather than habits, and both protect your customers rather than just your website.

Whether your domain is one of the loose ones decides whether the common attack can impersonate you. The check takes seconds and asks for nothing.

All guides