Right-sized, fixed price

Cyber Security for SMEs

Two beliefs about SME cyber security are very common and both are expensive.

The first is that you are too small to be worth attacking. The second is that doing something about it requires a budget you have not got. We work with small and medium businesses across the UK, on fixed prices, from our office in Bristol.

Why SMEs Are Prime Cyber Targets

Start with the government's own numbers
46%

of small businesses identified a cyber breach or attack in the previous 12 months.

Cyber Security Breaches Survey 2025/26
65%

of medium-sized businesses identified one over the same period.

Cyber Security Breaches Survey 2025/26
612,000

UK organisations, roughly, which is what 43% across all UK businesses works out to.

Cyber Security Breaches Survey 2025/26

Smaller businesses are reached differently.

Most attacks are automated. Software scans the internet for a vulnerable service or sends a million phishing emails, and whoever is exposed gets caught. Being small does not make you invisible to a scanner. It usually means you have fewer people watching.

Your business may also provide a route to somebody bigger. If you supply a large organisation, you have access, credentials or a trusted email domain, and that has value independent of your own size. Only 15% of UK businesses review the cyber risk of their immediate suppliers, so this route stays open a long time.

Your defences are probably thinner, and attackers know the pattern. There is no security team, IT covered by a general provider or the person who is best with computers, and a lot of trust is placed in a small number of people. That last part is what makes invoice fraud work so well at this size. If the managing director emails accounts asking them to pay something urgently, accounts will pay it.

The impact lands harder too. A large business absorbs a fortnight of disruption. For a small one, a fortnight without systems, with customers waiting and cash not coming in, is a different order of problem.

A Word on the Cost Figures

Because they are widely misused

The government's survey puts the median cost of a breach at £0, which sounds absurd until you realise that most reported incidents are nuisances, such as a blocked phishing email, or a morning of disruption.

The number that matters is the tail. The worst 5% of breaches cost businesses £4,000 or more, rising to £10,000 for medium and large firms, and those are direct costs as the business perceived them, before staff time and lost trade.

You are unlikely to have an average incident. You will have either a nuisance or a crisis.

For the serious end, insurance claims are the better guide. £197m was paid out across UK cyber claims in 2024, with ransomware and malware behind 51% of them.

Common Threats Facing SMEs

Six, in the order we tend to find them

Phishing

The most common attack type by a wide margin, at 38% of all UK businesses. This type of attack typically involves stealing credentials, installing malware, or executing a fraudulent payment.

Business email compromise and invoice fraud

Someone gets into an email account, watches for a while, and intervenes in a real payment conversation at the right moment with altered bank details. Impersonation attacks hit 12% of businesses in 2025.

Ransomware

Less common than the coverage suggests, at around 1% of businesses which is down from a previous 3%, but it is the one that stops a business trading. Ransomware and malware together made up 51% of UK cyber insurance claims in 2024.

Unpatched and unsupported systems

This often involves a line-of-business application nobody can upgrade because it is load-bearing.

Weak and reused passwords

Without multi-factor authentication, still comfortably the most common way in.

Leavers who still have access

Consistently one of the first things we find. Contractors and shared logins are the usual culprits, along with accounts on cloud services that HR never knew existed.

Affordable, Fixed-Price Protection

Mostly configuration, not purchase

The honest answer on cost is that meaningful improvement is much cheaper than most SME owners assume, and the first tranche of it is mostly configuration rather than a purchase.

Turning on multi-factor authentication across the business costs nothing but the time. Removing dormant accounts costs nothing. Getting patching done on a schedule costs nothing. Testing a backup restoration costs an afternoon. These are the changes that prevent the largest share of real-world incidents, and none of them requires a product.

Where you do spend, we price so you can plan

  • Audits are fixed price with one agreed figure, in writing, before we start. There is never an hourly meter, and no scope creep. See cyber security audit.
  • The plan you get is prioritised, ordered by risk reduced per pound spent, so you can do the first three things now and the rest when there is a budget. Doing 30% of the plan is fine. We will make sure it is the right 30%.
  • Cyber Essentials has a known cost. The scheme fee is published: £320 plus VAT for organisations under 10 employees, £440 for 10 to 49, plus whatever support you need to get there. See Cyber Essentials Plus.

For context on why this is worth doing at all: 47% of UK businesses hold some form of cyber insurance, but only 5% hold Cyber Essentials certification. Cover is more widely bought than the controls that ensure cover pays out, which is a slightly odd way round, given that the controls stop the loss happening and the cover only helps afterwards.

We are unusually alert to that gap because Fourarmed was founded by an insurance broker who kept watching it catch clients out. Our guide to what cyber insurers require explains what underwriters look for, and why a certificate on its own does not settle the question.

Where to Start

Six steps, in this order
  1. Turn on multi-factor authentication

    Everywhere it is available, starting with email, remote access and anything requiring administrator rights. This is the biggest single risk reduction available to you, and it is free.

  2. Find out whether your backups work

    The test is whether someone has successfully restored from them, not whether the backup job completes. Ensure you have a copy somewhere an attacker who owns your network cannot reach, ideally physically offsite.

  3. Review who has access to what

    Go through the lot: current staff, ex-employees, ex-contractors and any shared logins. Remove what should not be there, and cut administrator rights back to the people who need them.

  4. Begin patching on a schedule

    With critical and high-risk updates inside 14 days, which is also the Cyber Essentials requirement.

  5. Talk to your staff

    One session should cover phishing, payment verification and how to report something without embarrassment. See training.

  6. Then get an independent view

    This could be a cyber risk assessment if you want a lighter-touch picture of where you are exposed, or a full audit if you want all the details and a plan.

Steps one to five are things you can do yourself, and we would rather you did them than paid someone. Step six is where we come in, and it is more useful once the obvious things are done.

Common questions

Four questions
Is my business too small to be a target?
No. Most attacks are automated: software scans the internet for a vulnerable service or sends a million phishing emails, and whoever is exposed gets caught. Being small does not make you invisible to a scanner. It usually means you have fewer people watching.
How much does cyber security cost for a small business?
Meaningful improvement is much cheaper than most SME owners assume, and the first tranche of it is mostly configuration rather than a purchase. Turning on multi-factor authentication, removing dormant accounts, patching on a schedule and testing a backup restore cost time rather than money. Where you do spend, audits are quoted as a single fixed price agreed in writing before we start.
Do we need Cyber Essentials?
If you sell to government, defence, healthcare or large corporations, you almost certainly do. The scheme fee is published: £320 plus VAT for organisations under 10 employees and £440 for 10 to 49, plus whatever support you need to get there.
What is the cheapest thing we can do that helps?
Turn on multi-factor authentication everywhere it is available, starting with email, remote access and anything requiring administrator rights. It is the biggest single risk reduction available to you, and it is free.
Talk to us about your business

No obligation and no jargon

Tell us how big you are and what systems you run, and we will tell you what we would do first, including the parts you do not need us for.