Wednesday, 19 August 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

SMEs aren’t too small to target for cybercriminals, they’re too exposed to ignore

TechRadar ·
SMEs aren’t too small to target for cybercriminals, they’re too exposed to ignore

When cybercriminals look at a small and medium-sized enterprise ( SME ), they see a route into a larger organization or supply chain with a bigger payout.

SMEs operate with the same level of connectivity, supply chain reliance and regulatory responsibilities as larger organizations, but nowhere near the security budget or cyber staffing.

That imbalance, and connection to a larger environment, is what cybercriminals are exploiting.

The Cyber Security Breaches Survey 2025/2026 found that 46% of small businesses and 65% of medium businesses reported a cyber breach or attack over the past 12 months.

SMEs are now targeted based on how exposed they are and the bigger payout they can lead to.

The economic risk caused by the SME cyber gap SMEs account for 99% of the UK’s business population, employing three-fifths of the private sector workforce and generating half of the private sector’s turnover, according to the Federation of Small Businesses.

A fifth of those breached by a cyber incident reported revenue loss and reputational damage, while suffering from extended business disruption.

Temporary loss of access and interruption to online services can have a significant impact not only on the SME impacted but their wider supply chain.

Especially in sectors such as banking, retail and public services, which hold vast amounts of customer data and process payments, the knock-on effect of a cyber incident within a connected SME can be huge.

One compromise from a supplier account can be the catalyst for a much larger breach, which in turn can have a wider economic impact, as we saw with JLR.

Connected SMEs are valuable to the UK economy, but that also makes them a greater risk.

Attackers have industrialized cyber threats Cybercriminals don’t have to spend lots of time building sophisticated attack campaigns anymore.

Access to phishing kits, ransomware-as-a-service and AI-driven social engineering have made it easier to launch attacks at scale, without a high cost.

It means that attackers can automate reconnaissance and personalize attacks at machine speed, only to encounter SMEs relying on a patchwork of tools such as firewalls and email filtering.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›