Skip to content
City PM
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
Wednesday 16 April 2025 4:29 pm  |  Updated:  Friday 02 May 2025 8:29 am

The UK’s cyber blindspot lies with its SMBs

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
Digital-first players Chase and Monzo confirmed they have never used them, while Starling has phased them out of Google Pay.

Small and medium sized businesses (SMBs) in the UK are facing an escalating cyber security crisis, experts have warned.

According to Hugues Foulon, chief executive of Orange Cyberdefense, cyber attacks on SMBs have surged by 53 per cent, yet only 21 per cent of SMB chief executives are aware of their cyber risks.

This alarming statistic highlights a significant vulnerability within the UK’s business landscape.

“SMBs are under siege”, Foulon told CityAM. “Cyber attacks are up, and CEOs aren’t aware. This lack of awareness is a critical vulnerability”.

The financial toll of an evolving landscape

The financial implications of cyber attacks on UK businesses are staggering, with attacks costing UK businesses £44bn over the past five years.

Within that, SMBs have been hit the hardest. For these firms, the average cost of a cyber attack is far higher – at approximately £3,398, rising to £5,001 for those with 50 or more employees.

Yet, smaller firms continue to under-invest in cyber security, with over a third (38 per cent) of these businesses investing less than £100 annually in cyber security, and over half of their employees having never received any cyber training.

Meanwhile, the threat landscape is not only growing, but also evolving, with emerging threats developing in connected industries like the automotive sector, where connected and autonomous cars becoming new targets.

The UK’s National Cyber Security Centre (NCSC) has reported a significant increase in severe cyber attacks over the past year, warning of a widening gap in the nation’s ability to combat such threats.

Foulon said: “Every connected device is a potential cyber target – from phones, to cars, to planes.”

AI in cyber: a double edged sword

Artificial intelligence is playing an increasingly potent role in cybersecurity, but while it can enhance threat detection and response, it also lowers the barrier for cyber criminals to launch sophisticated attacks.

Read more

The Debate: Should CEOs be held personally accountable for cyberattacks?

Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.

Microsoft’s latest cyber signals report highlights a rise in AI-assistant scams, with over $4bn in fraud attempts thwarted in the past year alone.

Joe Whelan, head of IT security at Capital on Tap, said: “These powerful tools can add a transformative edge to our defensive arsenal, providing enhanced threat detection, predictive analysis, and automated responses.”

“However, whilst we’re standing on the brink of this AI-driven future, it’s crucial to remember that robust cyber security posture isn’t built on cutting edge tech alone. The foundation of any effective cyber security strategy is rooted in the basics.”

The same technology that fortifies defences, can equally be exploited by cyber criminals.

Akash Shrivastava, senior vice president at Inspira Enterprise, warned: “AI not only empowers cyber criminals – enabling even those with limited technical expertise to execute highly sophisticated attacks – but it also exposes the inadequacies of traditional security frameworks.”

Resilience beyond technology

Cyber resilience extends beyond tech solutions. Organisations must anticipate, withstand, recover from, and adapt to adverse conditions and attacks.

Robin Jones, head of technology, resilience and cyber at the UK’s Financial Conduct Authority (FCA), highlighted: “Resilience is key. Build effective cyber capability, implement effective accountability, and be prepared and able to enter recovery at any time”.

That was echoed by cyber security expert Stephane Nappo: “Cyber resilience is much more than a matter of technology. Agility, balance and high level view are indispensable”.

For SMBs, building these guards involves employee training, and the development and testing of response plans to ensure quick recovery time.

Continuous monitoring and collaboration with industry peers and experts were also advised by Orange Cyberdefense to enhance cyber resilience, ensuring the protection of their assets and the continuity of their operations.

Read more

‘Act now’: AI models capable of attacks on governments months away, Five Eyes warn

GettyImages 158774123 showcases a relevant business meeting scene, highlighting diverse professionals engaged in discussion.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business

People & Organisations

  • artifical intelligence
  • cyber attack
  • cyber security
  • Microsoft
  • Orange

Trending Articles

  • Why sport fans got bored of influencers and forced brands into a mind shift

  • House of the Dragon’s Abubakar Salim dreams of Kenyan kebabs for his last supper

  • Heatwave fans demand for aircon stocks

  • Could The Billingsgate Roman Bathhouse win a Toast award?

  • Lessons in comms from my children’s primary school

More from City PM

  • The Debate: Should CEOs be held personally accountable for cyberattacks?

    Opinion
    Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.
  • ‘Act now’: AI models capable of attacks on governments months away, Five Eyes warn

    Tech
    GettyImages 158774123 showcases a relevant business meeting scene, highlighting diverse professionals engaged in discussion.
  • Gambit Cyber Launches Vizier AI – An Autonomous Security Intelligence Workspace for Continuous Exposure Management

    Business Wire
  • Trump to reject UK plea over Anthropic ban as AI ‘kill switch’ fears grow

    Tech
    Getty Images logo on a modern office building exterior, symbolizing global influence in media and stock photography industry
  • Jaguar Land Rover eyes cost-cutting and wealthy buyers in cyber attack recovery

    Retail
    JLR logo prominently displayed in an automotive business setting, highlighting the companys brand presence and identity
  • Andrew Bailey warns on AI: ‘Everybody is currently priced to be a winner’

    Tech
    Bank of England Governor Andrew Bailey said cited several indicators that the labour market was softening.
  • Former Lloyd’s DEI leader left Beazley over non-financial misconduct allegations

    Insurance
    Beazley 2026 business forecast graph with financial data and growth trends displayed for February 24 analysis
  • Neo4j Acquires GraphAware to Launch Intelligence Analysis Alternative to Palantir Gotham

    Business Wire

City PM — European politics, business and analysis.

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Topics

  • Business
  • Markets
  • AI
  • Technology
  • Opinion
  • Energy

More

  • Politics
  • Economics
  • Fintech
  • Legal
  • Sport
  • Life

Company

  • About City PM
  • Contact
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 City PM. All rights reserved.
About · Contact · Terms · Privacy