Site navigation

Welsh SMEs Urged to Strengthen Cyber Defences

Graham Turner

,

Welsh SME cybersecurity
In this interview with DIGIT, Detective Inspector Paul Hall discusses the growing cyber risks facing Welsh SMEs, from supply chain attacks and AI-enabled phishing to the enduring importance of basic security measures.

Awareness of cyber risk among Welsh SMEs has improved markedly in recent years, helped in part by the unfortunate catalyst of high-profile attacks bringing the issue more sharper into the collective conscience. 

“There’s been some very high-profile attacks and it is very much in the public eye now,” Detective Inspector Paul Hall, told DIGIT.

One area causing particular concern is supply-chain security. Hall said criminals are increasingly looking beyond individual organisations and targeting the relationships between businesses, suppliers and larger partners.

“What we are seeing now is that the criminal is using the supply chain of that SME or large organisation and trying to get in and commit the crime via the supply chain.”

That risk can work both ways. Smaller firms may be targeted as a route into larger organisations, while compromises elsewhere in the supply chain can also expose SMEs themselves.

A WCRC project with the Welsh Government highlighted how often businesses knew a supplier or partner had experienced an incident without subsequently reviewing their own security arrangements.

“It’s quite alarming really, the amount of organisations that knew that someone in their supply chain had suffered a data breach or an attack, but yet nobody was doing anything about it.”

Hall said cybersecurity therefore needs to become a more routine part of procurement conversations, including asking suppliers about their security practices and, where appropriate, whether they hold Cyber Essentials accreditation – though that is just one piece of the security posture puzzle.

The nature and sophistication of attacks needs reconsidering. Phishing remains a familiar threat, but AI is helping criminals create more convincing messages while making sophisticated techniques accessible to a wider pool of attackers.

Hall also pointed to a growing level of reconnaissance behind BEC attacks. Rather than demanding conspicuously large sums, criminals can study normal payment patterns and make requests that appear more believable.

“The criminal is doing a little bit more reconnaissance regarding that kind of arrangement we’ve got between the two different companies,” he said.

That becomes particularly difficult to identify when messages come from the compromised account of a genuine supplier, meaning they arrive from an address the recipient already trusts.

Despite the evolution of attacker techniques, Hall said many incidents still come back to familiar weaknesses inside organisations.

“What we still see is, predominantly the majority of the cases we are coming across, there’s a human element to it.”

For that reason, staff awareness remains fundamental.

“I always look at it as the human, the staff member, is the first line of defence. However, it could quite easily be the first line of weakness as well.”

Strong passwords, multi-factor authentication, regular patching and updates, and ensuring employees understand their security responsibilities can all make a significant difference. Hall stressed that many attackers continue to exploit relatively simple vulnerabilities, including password reuse and accounts without MFA.


Recommended reading


For smaller organisations concerned about cost or a lack of in-house expertise, his advice is to start with those fundamentals.

WCRC membership is free and provides businesses with access to cyber security updates and funded services, including staff awareness training, vulnerability testing and support around policies and business continuity planning. Hall also highlighted guidance from the National Cyber Security Centre, including resources tailored to different business sizes and sectors.

Many of the most important first steps, he argued, require relatively little financial investment.

“It’s no point burying your head in the sand because cybercrime is not going anywhere.”

“However, even if you have not got a background in cybersecurity, in IT, there are still some simple measures you can put in place that can protect you against a lot of these attacks and can lead you on the path then towards cyber essentials and other accreditations going forward.”


Graham Turner

Sub Editor

Latest News

Cybersecurity Editor's Picks Security

Welsh SMEs Urged to Strengthen Cyber Defences

Energy

UK and US Strike Fusion Clean Energy Partnership

Editor's Picks Technology

ScotlandIS Appoints Prof Gordon Morison as New Chair

Government

What Are the Top Technology Trends in Government?