
By Tom Kidwell, Co-founder & Director of Ecliptic Dynamics.
Despite years of headline‑grabbing cyber attacks and the noise around breaches causing some serious operational, financial and reputational damage to major brands like Marks and Spencer and the Co-Op, too many SMEs are still failing to act to improve their cyber resilience, operating with a mindset of “it won’t happen to me.”
According to the UK’s latest Cyber Security Breaches Survey 2026, the proportion of businesses reporting a cyber breach or attack has held steady at 43%, which is a stark reminder that, for many SMEs, cyber resilience is simply not improving.
In fact, the survey highlights that small businesses are now the greatest area of concern. Last year’s modest progress in basic cyber hygiene has reversed, with fewer organisations conducting risk assessments, maintaining formal policies, or investing in continuity planning. In many cases, companies appear to be stepping away from even the most fundamental security practices.
While initiatives like the government’s Cyber Aware campaign are gaining traction, awareness alone is not enough. Until cyber risk is consistently treated as a practical business issue, cyber risk will continue to threaten SMEs.
In today’s threat landscape, complacency has become one of the most significant vulnerabilities a SME can have, often opening the door wider than any technical flaw ever could.
How to move from complacency to proactive cyber resilience
Cyber security is widely acknowledged as important, yet too often it is not treated as urgent. For many SMEs, it sits in the background, overshadowed by day‑to‑day operational pressures and competing priorities. This creates a gap between awareness and execution, where risks are understood but not addressed in practice.
A common misconception is that smaller organisations are unlikely targets or that they do not hold valuable data. In reality, attackers frequently prioritise SMEs precisely because their defences are lighter and less mature. The potential rewards, whether that is financial data, customer information, or access into wider supply chains, remain highly attractive.
Economic pressures also play a role when it comes to proactive cyber resilience. With limited budgets and resources, cyber security is often deprioritised in favour of more immediate business needs, despite the fact that a single incident could have far greater financial consequences.
Addressing this challenge starts with a shift in mindset. Cyber security must be recognised as a core business risk, with direct implications for operations, revenue and reputation. When leadership teams take this view, security becomes embedded in decision‑making across the organisation rather than treated as an isolated IT responsibility.
From there, SMEs can begin to foster a security-first culture, ensuring that every employee understands their role in protecting the business. Given that so many attacks exploit human behaviour, this cultural shift is critical.
Ultimately, reducing cyber risk for SMEs starts with replacing passive awareness with consistent, practical action.
Five practical steps SMEs can take today
While the challenge may seem daunting, there are clear, achievable actions SMEs can take to improve their security posture:
- Strengthen everyday cyber hygiene
Basic controls remain one of the most effective defences to reduce an attack surface and the potential impact of a breach, but they need to go beyond the obvious. In addition to strong passwords, multi‑factor authentication, patching and backups, organisations should:
- Regularly review and remove unused accounts, particularly for former employees or third‑
- Segment systems or user access where possible, limiting how far an attacker can move if a single account is compromised.
- Keep an inventory of all devices and software in use as you can’t secure what you don’t know exists. Creating an asset register that is regularly reviewed and updated can help you maintain visibility of your IT environment and reduce risk.
- Invest in people, not just technology
Human behaviour continues to be one of the most common entry points for attacks and having an informed and engaged workforce can act as your first line of defence. Training should move beyond generic awareness and become more practical and continuous:
- Use real‑world phishing simulations to build knowledge of how to spot a phishing attempt and how to report it.
- Encourage a “no blame” culture so employees feel comfortable reporting mistakes quickly.
- Reinforce secure behaviours through regular training rather than one‑off annual sessions.
- Understand your risks
To improve security effectively, SMEs need a clear, practical understanding of cyber risk. The focus should be on identifying the most important assets, understanding where the biggest exposures lie, and prioritising action accordingly.
- Identify your most important data, systems and processes, the things your business relies on day to day.
- Think about who has access to them, including suppliers and third‑party partners.
- Use simple frameworks like Cyber Essentials as a guide, but tailor them to how your business actually operates.
- Review your risks regularly, especially when you introduce new tools, systems or ways of working.
- Preparation is key
Even with strong controls in place, incidents can still happen. What often makes the biggest difference is how quickly and effectively a business can respond, which is why preparation should be simple, practical and well understood across the organisation:
- Create a clear response plan so everyone knows what to do if a cyber incident occurs
- Include communication plans – knowing who to inform (customers, suppliers, regulators) and how.
- Run simple practice scenarios to help teams feel more confident and prepared.
- Review and improve continuously
Cyber security is continuously evolving and as systems, people and threats change, security needs to be reviewed regularly to stay effective and relevant:
- Check user access regularly and remove anything that is no longer needed.
- Keep an eye out for unusual activity, such as unfamiliar logins or unexpected data use.
- Stay aware of new and relevant threats so you can adjust your defences when needed.
The persistence of the “it won’t happen to me” mindset remains one of the biggest barriers to improving SME cyber resilience. It leaves organisations exposed to risks that are, in many cases, entirely preventable.
Attackers are actively seeking out businesses that have neglected the basics, relying on the assumption that many SMEs will continue to underestimate their risk.
For SMEs, the first step is to recognise that reducing cyber risk begins by moving from complacency to proactive, practical cyber resilience.
