The real message for UK SMEs
The assertion that “people are not the weakest link”, made by a Chesterfield cyber expert in the recent Derbyshire Times report, is more than a challenge to tired cyber-security language. It has a direct bearing on how UK small and medium-sized enterprises should manage cyber risk, buy cyber insurance and prepare for an incident.
For years, business owners have been told that staff are the principal security problem: the employee who clicks a convincing phishing link, reuses a password or sends an invoice to the wrong recipient. Those events do happen. However, treating them as individual failures misses the more useful question: what conditions allowed one normal human mistake to become a business-wide loss?
A staff member who is rushed to pay a supplier, cannot easily verify a payment request, has no phishing-reporting button, and has access to sensitive systems without multi-factor authentication is not the root cause. That employee is operating inside a process that has not been designed to cope with predictable pressure, distraction and deception.
For SMEs, this distinction matters because cyber insurance is not a substitute for security controls. It is a financial resilience tool that works best alongside sensible, proportionate protections. Insurers increasingly assess whether a business has basic controls in place, while an avoidable gap in those controls can make a breach more expensive, disruptive and difficult to recover from.
Stop blaming staff and start designing safer work
Human error cannot be eliminated. Nor should it be the aim. Successful fraudsters deliberately exploit urgency, authority and familiarity: a message that appears to come from a director, an IT provider or a regular supplier can be persuasive even to an experienced employee.
The practical objective is to make the safe action the easy action, and to ensure that a single wrong click does not immediately give an attacker access to email, customer data, finance systems or backups.
Security awareness needs to be relevant, not punitive
Annual slide-based training followed by a generic quiz is unlikely to change day-to-day behaviour. A better approach is short, regular training based on the risks employees actually see. A construction firm may need to focus on changed bank-detail scams and shared mobile devices on site. A professional-services business may need to address email account takeover, client-document sharing and fake Microsoft 365 login pages. A retailer may need procedures for point-of-sale access and supplier fraud.
Training should explain what a suspicious request looks like, but it must also tell staff exactly what to do next. For example:
- Report suspicious emails using a visible button or a dedicated address.
- Check unusual payment requests using a known telephone number, not the contact details contained in the email.
- Ask for help without fear of being embarrassed or disciplined for raising a false alarm.
- Escalate a mistaken click immediately, before deleting the message or trying to fix the issue alone.
This last point is crucial. Fast reporting can allow an IT provider to reset credentials, revoke sessions and isolate a device before an account takeover turns into invoice fraud or ransomware. A blame-heavy culture does the opposite: it delays reporting when minutes can matter.
Controls must assume a mistake will happen
A human-centred approach is not softer on risk; it is more realistic about it. SMEs should build layers around staff rather than expecting perfect decisions at all times.
At a minimum, businesses should consider multi-factor authentication (MFA) for email, cloud storage, remote access, accounting systems and administrator accounts. MFA remains one of the most important defences against stolen passwords, though it should be configured carefully and supported with phishing-resistant methods where feasible.
Other practical layers include:
- Unique passwords managed through an approved password manager.
- Least-privilege access, so employees only reach the systems and data required for their role.
- A two-person or out-of-band verification process for changes to supplier bank details and high-value payments.
- Email filtering and domain protections to reduce impersonation attempts.
- Prompt patching of operating systems, browsers, routers and business applications.
- Segregated, tested backups that are not permanently accessible from everyday user accounts.
- Clear joiner, mover and leaver processes, especially prompt removal of former employees’ access.
These measures do not imply mistrust of staff. They recognise that attackers are persistent and that a good business process should survive one plausible failure.
What this means when arranging cyber insurance
Cyber insurance can help an SME respond to the financial and operational consequences of a cyber incident. Depending on the policy and wording, cover may include incident-response specialists, forensic investigation, legal advice, notification support, data recovery, business interruption, cyber extortion response and certain third-party liabilities.
But cover varies considerably. A business should not assume that a policy labelled “cyber” automatically pays every loss involving a fraudulent email or compromised account. Social engineering, funds-transfer fraud and invoice-redirection losses may be subject to separate limits, exclusions, conditions or optional extensions. It is important to ask a broker or insurer direct questions about these areas.
The people-not-the-weakest-link principle should also shape the insurance proposal process. Insurers commonly ask about MFA, backups, patching, endpoint protection, staff training and incident-response arrangements. These questions are not merely administrative hurdles. They identify the controls most likely to limit a loss.
SMEs should answer accurately and retain evidence of their controls. If MFA is stated as being in place, define what that means: does it cover every email account, including administrators and directors, or only some users? If backups are declared, are they restored and tested? A vague or overstated answer can create problems later, particularly if policy terms require the business to maintain a specified control.
Buy for the interruption, not just the breach notification
Many owners picture a cyber claim as a data-protection notification exercise. In reality, the most damaging effect for a smaller business may be downtime. If a ransomware attack locks customer records, scheduling software, stock systems or email for several days, the immediate loss can be missed sales, payroll pressure, delayed projects and damage to client confidence.
When comparing policies, examine:
- The business-interruption waiting period and how lost income is calculated.
- Whether dependent business interruption is covered when a key cloud or IT supplier suffers an outage.
- The limits for forensic, legal and public-relations support.
- Whether cyber crime or social-engineering cover is included and at what limit.
- The excess, sub-limits and exclusions.
- The insurer’s 24/7 incident-reporting process and whether you must use panel suppliers.
A policy is most valuable when its response route is understood before an attack. Keep the insurer’s emergency claims number away from the email system that may be unavailable during an incident.
A practical 30-day plan for SME owners
Rather than launching an expensive programme all at once, use the news story’s central message to prioritise improvements that reduce pressure on staff and contain mistakes.
Week 1: map the routes into the business
List your critical systems: email, accounting, customer relationship management, payroll, websites, cloud drives and remote-access tools. Identify who has administrator privileges and whether MFA is enabled everywhere. Also identify the information or systems whose loss would stop trading.
Week 2: fix payment and reporting processes
Introduce a documented callback procedure for altered bank details and urgent payment requests. Make it impossible for an employee to approve and release a high-risk payment alone. Give every member of staff a simple way to report a suspicious message, and confirm that reporting is encouraged.
Week 3: test recovery, not just backups
Ask your IT provider to demonstrate a restore of a representative file or system. Check where backups are held, who can delete them and how long restoration would take. A backup that has never been tested is not a reliable recovery plan.
Week 4: rehearse the first hour of an incident
Run a short tabletop exercise. Imagine a director’s Microsoft 365 account has sent fraudulent emails to clients, or several laptops show a ransomware note. Decide who contacts IT, who contacts the insurer, who can make operational decisions and how staff and customers will be updated. Record mobile numbers and key contacts outside the affected systems.
The bottom line
The Chesterfield expert’s point is valuable because it shifts cyber security from individual blame to operational design. Employees are often the first people to spot a threat and the first line of defence when they have clear instructions, usable tools and permission to escalate concerns. The strongest SMEs combine that human capability with technical safeguards, robust payment controls, tested recovery arrangements and cyber insurance that matches their actual exposure.
Cyber resilience is therefore not achieved by demanding that staff never make a mistake. It is achieved by ensuring that an expected mistake is detected quickly, limited effectively and financially survivable.
FAQ
Does cyber insurance cover an employee clicking a phishing link?
It may cover the resulting incident-response costs, data recovery, business interruption or liability, subject to the policy terms. However, cover for money sent after an invoice or payment scam can be separate or limited. Check specifically for social-engineering, cyber-crime and funds-transfer fraud cover.
Is staff cyber-security training enough for a UK SME?
No. Training is important, but it should sit alongside MFA, access controls, secure backups, patching, email protection and payment-verification procedures. Training tells people how to respond; controls reduce the impact when a threat succeeds.
Will an insurer require multi-factor authentication?
Many cyber insurers ask about MFA and may require it for email, remote access or privileged accounts. Requirements differ by insurer and policy. Confirm the exact scope before buying cover and make sure your implementation matches what you declare.
What should we do first after a suspected cyber incident?
Contact your IT support provider and the insurer’s incident line immediately, using pre-recorded contact details where possible. Preserve evidence, isolate affected devices if advised, reset compromised access and avoid communicating sensitive information through accounts that may be compromised. Do not delay reporting because an employee fears blame.
Source: derbyshiretimes.co.uk — Mon, 21 Sep 2026 08:53:00 GMT