According to independent research, tens of thousands of UK SMEs are at risk of collapse in the immediate aftermath of a cyber-attack.

 

This research features data from 1120 senior decision-makers within UK firms with less than 250 employees.

The research was conducted by insurance firm Gallagher, in order to better understand the current threat that cyber-attacks present to UK businesses.

1.4 million businesses hit in 2021

One major point that the research revealed was that 1.4 million businesses were hit by major cyber-attacks last year, costing a combined £8.8 billion. This represents a 5% increase in attacks compared to 2020.

The average cost of attacks to affected businesses was around £6,400, with 17% of SMEs stating they were forced to spend £10,000 or more, and 9% paying out in excess of £20,000.

A quarter of SMEs won’t survive a cyber-attack

However, the defining point realised by this research was that 23% of SMEs stated that they would not be able to operate longer than a month if a cyber attack affected their ability to trade.

This puts 57,000 UK SMEs at risk of collapse if they are hit by a cyber-attack.

“Ability to trade” varies from industry to industry, but is most commonly affected by a loss of critical data.

For all industries, “ability to trade” now means their ability to access and use their IT network.

Cyber-criminals are now painfully aware of how dependent businesses are on their network and are actively developing and using ransomware that affects their ability to trade and operate.

For manufacturing, this commonly means the loss of processes or design specifications, that are either essential for carrying out the manufacturing process, or present a competitive advantage, and would be devastating if made public.

 

Professional industries are most at risk

For professional industries, such as accounting and solicitors firms, this commonly means a loss or breach of client data, resulting in permanent reputational damage, in addition to rendering the firms unable to carry out their day-to-day operations

Professional industries are particularly at risk and are currently dangerously exposed to cyber-attacks and data breaches.

Paul Bassett, managing director of crisis management at Gallagher, stated in regard to the vulnerability of professional firms:

Alongside regularly reviewing their crisis preparedness, response plans and forms of protection, such as insurance, it is critical UK SMEs also assess their ability to survive in the event of a major crisis incident when the risk of serious disruption and protracted recovery process is very real“.
The cost of a crisis is by no means the only consideration. Duration is key – especially with a quarter of UK SMEs admitting they could survive for less than a month if unable to trade following an incident. For companies with tight margins and limited working capital, even a relatively short-term denial of access to premises or systems paralysis could be a crippling, and possibly fatal, blow“.
Cyber-attacks are the most common type of “crisis” experienced by UK SMEs

Cyber-attacks, data breaches, or other cyber-extortion incidents, accounted for 15% of all SME crisis incidents last year.

Insurer Hiscox also reported earlier this year that there had been a sharp increase in reported cyber-attacks year-on-year among small firms, leaping from 33% to 47%, an increase of 14%.

Medium-sized firms saw an even bigger leap, going from 36% to 63%, an increase of 27%.

These increases have been seen as part of a global increase in cybercrime, most notably in ransomware and social engineering.

TecSec Services Ltd is an IT Support and Risk Management provider.
We have achieved Cyber Essentials, Cyber Essentials +, IASME Gold, and are an official IASME certification body.
We have also achieved ISO 2701:2013, a substantial certification for our Information Security Management system.
Such certifications are one of the ways we help ensure incidents such as those reported here do not happen to us or our clients.
They show our stakeholders that our cyber security practices are impeccable and allow us to protect against all common cyber attacks.
We are currently offering a free service that will help to identify if your organisation is at risk of being exploited by cybercriminals.
Our Free Cyber Security Training helps protect your staff against phishing attacks, by providing the current best methods of identifying phishing emails: