You don’t have to look far to read about the latest big cyber-attack – from the Home Office to the NHS. Even the recent Musk/Trump love-in on X was reportedly delayed because of online hostiles. And not the usual online hostiles you get on X. Actual cyber-criminals were to blame, apparently.
The reality of our modern world is that every time we close a door to cyber-attack, another one is forced opened by determined and well-resourced criminals and state actors.
It would be easy to think that it’s only huge global organisations who have to worry about this. The loss of hundreds of thousands or millions of customer records is always big news, but the Scottish economy is primarily made up of small businesses (49 employees or fewer); 334,505 of them, to be exact, making up 98.2% of the private businesses in Scotland. Medium-sized businesses – those with between 50 and 249 employees – number another 3,880.
The potential exposure of this is enormous.
It’s these businesses we should be focused on. Larger companies, a much smaller proportion of the Scottish economy, generally have quite well-established IT security in place. Not that this makes them invulnerable, of course.
But SMEs, particularly towards the smaller end, don’t always have the resources, time or capacity to construct a properly robust cyber security defence.
These organisations – the backbone of the Scottish economy – are increasingly coming under attack from bad actors online.
Earlier this year, the insurer Hiscox released its annual Cyber Readiness Report, a global review of preparedness for, attitudes towards and experiences of cyber-attack, drawn from a survey of more than 5000 companies across eight countries.
Among its findings was that businesses with 10 or fewer employees reported an increase of 36% in the number of attacks over the last three years. Dodgy emails are still attackers’ weapon of choice.
More than half of all firms surveyed said they’ve been attacked at least once in the last year; the median cost of this was down slightly to about £12,500.
Having said that, Sky Business reported in June of this year that SMEs yet to experience a cyber- attack underestimate the financial impact by £85,000.
Interestingly, the same research showed that one in five businesses which haven’t experienced a cyber-attack don’t think it would force them to close temporarily. Of those which had already experienced a breach, 100% of them said a closure would be necessary for any future attacks.
Then there’s the impact of AI.
DIGIT.FYI reported recently that more than half of chief information security officers (CISOs) don’t think their security teams are prepared for AI-powered threats.
Every business is different, of course, so survey data only tells you so much. I think what we can safely assume, though, is that having to deal with a cyber-attack and the possible loss of customer data, confidence and income is likely to rank fairly high on the headache-o-meter.
So what’s a small business owner to do? Already beset on all sides by challenges of growth, recruitment, stiff competition, and many others besides, heaping on the additional demands of a robust cybersecurity posture could seem like a bridge too far. How many SMEs in Scotland even have dedicated security resource, far less a CISO?
Don’t worry, this isn’t the part where I tell you that a proper insurance policy is a must. There are other things you need to address first – that robust cybersecurity posture, for starters.
The reality is that no insurer is going to want to touch you without it. Having proper insurance in place means you can get a head start on getting back to normal.
Most policies will offer you some kind of triage system, whereby you can access IT security, forensic, legal and even PR support to get
an early jump on any suspected attacks or incidents before they develop, as well as helping to manage the fall out.
But none of this matters if you don’t have your security sorted in the first place. That doesn’t mean you need to have the IT equivalent of a tank division, bristling with ordnance and weaponry.
Part of the issue for SMEs is in the brain-addling scale of security options out there. Speak to a reputable security expert who’ll advise you on the kind of security you need – this doesn’t need to be an all-or-nothing question.
Putting in place appropriate, considered security measures which meet the most likely threats to your business is a plenty good enough place to start for most insurers.
Recommended reading
- Report: Vulnerability Exploitation Surge Endangers Cybersecurity
- IT Leaders Split on Generative AI’s Role in Cybersecurity
- Cyber Leaders Reveal Compliance and Boardroom Struggles
The important thing is to look at your business and take a sensible view on where your main risks lie, and what else you need to do to mitigate those. It’s exactly the same principle as ensuring your property is adequately protected against fire or theft, or managing your fleet risk by providing driver training and well-maintained vehicles.
Like any aspect of business and risk, it’s important not to overcomplicate things. Not even I believe that anyone goes into work full of vim and vigour about the prospect of tackling their insurance challenges.
But while risk management isn’t sexy, the fact is that cyber-risk is growing and SMEs are every bit as exposed as the big-name victims which hit the headlines so regularly.
Prevention is better than cure, as the saying goes, and a robust security posture will do more for your business than trying to find
cover for a cyber risk that isn’t being properly managed.





