Why SMEs Face A Double Risk From Phishing Attacks
Small and medium sized businesses face growing phishing risks while also carrying legal responsibilities to protect sensitive data.
Cyber criminals can find smaller businesses attractive targets because they may hold valuable information while having fewer resources dedicated to cyber security. A small company may also have connections with larger organisations through supply chains, customer relationships or other commercial arrangements. This means gaining access to one smaller business could potentially provide criminals with information or access linked to other organisations, increasing the potential value of a successful attack.
The interconnected nature of modern business has changed the way cyber criminals assess potential targets. A company does not necessarily need to be large or hold substantial financial assets to become attractive to attackers. Businesses can provide access to customer information, employee records, financial details or systems connected to other organisations. For smaller companies, this creates an additional challenge because a cyber attack can have consequences beyond the immediate business.
Limited resources can also increase the vulnerability of SMEs. Staff working in smaller organisations are often responsible for multiple areas of the business and may not have the time or specialist knowledge available within a dedicated cyber security team. This can make it harder to identify suspicious messages, maintain systems and respond quickly when an attempted attack occurs. According to figures from insurance company Hiscox, 38 per cent of small firms suffered a successful hack during the previous 12 months.
The financial consequences of a successful cyber attack can also be significant for smaller organisations. Hiscox estimates that successful attacks cost affected small firms nearly £27,000 each. For an SME, an unexpected cost of this scale can place considerable pressure on cash flow and day to day operations. The financial impact can extend beyond the immediate cost of dealing with an incident if systems, customer relationships or business reputation are also affected.
Phishing remains one of the most common forms of cyber attack because criminals can use relatively straightforward techniques to target employees. Messages can be designed to appear legitimate and may attempt to persuade recipients to provide sensitive information, download malicious software or approve fraudulent transactions. The increasing use of technology and artificial intelligence is also making some fraudulent communications more convincing and potentially more difficult to identify.
Criminals can tailor phishing attempts to exploit the pressures faced by employees. A message may appear to come from a colleague, customer, supplier or another trusted contact and create a sense of urgency around an apparently routine request. Employees who are working quickly or managing several responsibilities may have less opportunity to scrutinise unusual messages. This makes staff awareness an important part of protecting smaller businesses from phishing attacks.
The risks are not limited to the loss of money. Phishing can lead to the disclosure of personal or sensitive information, potentially creating further consequences for the organisation involved. If criminals gain access to business systems, the effects can also spread to other areas of the company. The resulting disruption may affect employees, customers and commercial partners while the business works to understand what happened and restore normal operations.
Businesses also have legal responsibilities concerning the protection of personal and other sensitive information. UK data protection legislation requires organisations to take appropriate measures to protect data and reduce cyber security risks. These responsibilities apply to businesses of different sizes, meaning an SME cannot rely on its size as a reason for having weaker protections or less effective security arrangements.
Organisations are also expected to keep their security measures under review. Cyber threats change over time, while software and security systems can become outdated if they are not properly maintained. Businesses therefore need to consider whether their existing protections remain appropriate as technology, working practices and potential threats develop. Failure to maintain suitable safeguards can create additional risks if a security incident occurs.
A recent enforcement case involving South Staffordshire Plc demonstrates the potential consequences of inadequate security measures. The Information Commissioner's Office fined the company £963,900 in May 2026 after a phishing attack that occurred in 2020 resulted in the disclosure of personal data relating to more than 600,000 people. The case involved security failures including obsolete software, poor logging and weak privilege controls.
Although South Staffordshire Plc is a larger organisation, the case illustrates the wider responsibilities businesses have when handling personal information. The scale of a company does not remove its obligations to protect the data it controls. For SMEs, the example also demonstrates why cyber security should be considered as part of broader data protection responsibilities rather than simply an IT issue.
The potential consequences of a breach can therefore create what businesses may regard as a double penalty. An organisation could suffer direct financial losses and disruption because of an attack while also facing regulatory action if it failed to take appropriate measures to protect the information involved. Reputational damage can add another layer of difficulty, particularly for smaller businesses that rely heavily on customer trust and established commercial relationships.
Preventing phishing attacks requires businesses to consider both technology and employee awareness. Security controls can help identify or block suspicious activity, while staff training can improve the ability of employees to recognise unusual messages and requests. Regular reviews can also help businesses identify weaknesses before they are exploited. For smaller organisations without dedicated cyber security teams, obtaining appropriate specialist advice may be particularly important.
SMEs should also consider how their systems, suppliers and customers are connected. A security weakness in one part of a business network can potentially create consequences elsewhere, particularly where organisations exchange data or rely on shared services. Understanding these relationships can help companies identify which systems and information require the strongest protection and where additional safeguards may be needed.
The responsibility for cyber security ultimately extends beyond responding to an incident after it occurs. Businesses need to consider preventative measures, data protection requirements and the resilience of their systems as part of normal operations. Regularly updating software, controlling access to sensitive information and ensuring employees understand common phishing techniques can all contribute to reducing exposure.
The growing sophistication of phishing attempts means that businesses cannot assume suspicious messages will always be easy to identify. Artificial intelligence and other technologies can help criminals produce more convincing communications, increasing the importance of careful verification. Employees should be encouraged to question unexpected requests for sensitive information or financial action rather than responding simply because a message appears to come from a familiar source.
For SMEs, the challenge is particularly important because limited resources can make recovery from a serious incident more difficult. Smaller teams may have fewer people available to manage an attack, restore systems, communicate with customers and deal with regulatory requirements at the same time. Investing in suitable security measures and staff awareness can therefore help reduce both the likelihood and potential impact of a successful phishing attack.
The combination of cyber security risks and data protection responsibilities means SMEs face more than one potential consequence when an attack succeeds. Protecting customer and business information is both a practical security requirement and an important legal responsibility. Businesses that fail to maintain appropriate safeguards could face financial losses, operational disruption, reputational damage and regulatory consequences following a serious incident.
Got a news story or tip to share? Contact our editorial team by emailing news@lakelandpost.co.uk or call us directly on 0333 090 2080.