A reported cyberattack surge is a business continuity warning
SecurityBrief UK has reported that UK small businesses are facing a surge in cyberattacks, alongside action by BT. The immediate lesson for an SME owner is not simply that cybercrime is increasing; it is that cyber risk has become an operational and financial exposure that can interrupt trading with very little warning.
For a small firm, an attack does not need to be technically sophisticated to be expensive. A convincing phishing email can lead to fraudulent supplier-bank-detail changes. A stolen Microsoft 365 password can expose customer data and invoices. Ransomware can prevent staff from accessing booking systems, accounts, stock records or production files. Even when no ransom is paid, the costs of investigation, recovery, customer communication, legal advice and lost revenue can accumulate quickly.
BT's reported response is relevant because telecoms and connectivity providers occupy an important position in the SME security chain. However, businesses should not treat action by a provider as a substitute for their own security controls, response plan or insurance review. The responsibility for securing user accounts, devices, data and payment processes remains shared.
Why smaller companies are attractive targets
Cybercriminals often target SMEs precisely because they may have fewer dedicated security staff, inconsistent patching, shared log-ins or limited backup testing. Attackers do not need to know the business personally. Automated scanning tools can find exposed remote-access services, while bulk phishing campaigns can target thousands of staff inboxes at once.
The attack methods that create the greatest financial damage
The most significant risks for many UK SMEs are not always dramatic “hacking” incidents. They are often routine business processes being exploited:
- Business email compromise (BEC): an attacker impersonates a director, supplier or customer to request an urgent payment or alter bank details.
- Ransomware: malicious software encrypts systems or steals data, creating pressure to pay and threatening prolonged downtime.
- Cloud account takeover: compromised email, file-sharing or accounting platforms give criminals access to commercially sensitive information.
- Data breach: customer, employee or payment data is accessed, lost or disclosed, potentially triggering contractual, regulatory and reputational consequences.
- Supplier compromise: a trusted IT provider, payroll company or software platform is compromised, affecting several client businesses.
These threats overlap. A phishing email may lead to a cloud-account takeover; that account can then be used to send fraudulent invoices, access files and distribute malware internally.
What the news means for cyber insurance decisions
Cyber insurance is not a replacement for cyber security. It is a financial resilience tool intended to help a business respond when preventive measures fail. In the context of increased attacks, the key question is not “Do we have an IT policy?” but “Could we fund and manage a serious incident without specialist help?”
A well-designed cyber policy may cover, subject to its terms, conditions and exclusions:
- incident-response and forensic investigation costs;
- legal and privacy advice following a data breach;
- customer, regulator and affected-individual notification costs where applicable;
- data restoration and system recovery;
- business interruption resulting from a covered cyber event;
- cyber extortion response and, in some policies, related costs;
- third-party claims arising from a security or privacy failure; and
- social engineering or funds-transfer fraud, where this is specifically included.
The final point matters. Many owners assume a general cyber policy automatically covers an employee authorising a payment to a fraudster. That is not always the case. Social engineering, invoice manipulation and authorised push payment fraud can have separate limits, excesses, definitions or exclusions. A business should ask its broker or insurer directly whether these events are covered and what evidence of verification controls is required.
Cover should reflect how the business actually trades
A retailer reliant on e-commerce has a different interruption exposure from a consultancy whose staff work through cloud email and project-management tools. A dental practice, recruitment firm or accountancy business may have substantial sensitive personal data. A manufacturer could suffer material losses if operational technology, stock management or supplier ordering is unavailable.
When comparing policies, SMEs should look beyond the headline indemnity limit. Important questions include:
- Does business interruption cover depend on a full system outage, or can it respond to partial disruption?
- Is a dependent provider outage covered, such as a cloud platform, managed service provider or payment processor?
- Are ransomware negotiations and digital forensics supplied through a 24/7 incident-response panel?
- What is excluded for failure to maintain multi-factor authentication (MFA), backups or software updates?
- Does the policy cover regulatory defence costs and privacy liability?
- Are fraud losses included, and is a call-back procedure required before changing supplier bank details?
The most valuable policy is one that matches the business's revenue dependency, data profile and supplier ecosystem—not the cheapest policy with the broadest-sounding label.
Practical steps to take now
A reported rise in attacks should prompt a short, disciplined review rather than panic spending. The following actions are realistic for most SMEs and can also improve insurance eligibility.
1. Enforce MFA on priority accounts
Enable MFA for email, cloud storage, accounting, payroll, remote access and administrator accounts. Prioritise phishing-resistant methods, such as authenticator apps or security keys, where possible. Email remains a high-value entry point because it enables password resets and convincing impersonation.
2. Test backups, not just backup software
Maintain separate, protected backups of critical data and test restoring them. A backup that has never been restored is an assumption, not a recovery capability. Record who can initiate restoration and how long core systems would take to recover.
3. Put payment verification in writing
Require an independent call-back to a known telephone number before changing supplier bank details or making unusual payments. Do not use a number supplied only in the email requesting the change. This simple control can prevent a costly BEC loss.
4. Patch internet-facing systems promptly
Keep operating systems, routers, VPNs, firewalls, remote desktop tools and business applications updated. Remove unused accounts and disable remote access that is no longer needed. Where an external IT provider manages these tasks, confirm responsibilities in writing.
5. Create a one-page incident plan
List the insurer's 24/7 claims number, IT provider, legal contact, bank fraud line and internal decision-makers. State who can isolate devices, pause payments and communicate with staff. During an incident, speed and clarity can reduce both loss and disruption.
The role of BT and other providers: useful, but not complete protection
Action by a major telecommunications provider can help strengthen the wider ecosystem through security services, threat intelligence, network-level protections or support for smaller organisations. Yet an SME should understand the boundary of provider protection.
A broadband or mobile provider cannot reliably prevent an employee from entering credentials into a fake Microsoft 365 page, approving a fraudulent bank transfer or sharing data with an impersonator. Nor can it guarantee that a third-party cloud platform will never suffer an outage. Security needs to be layered: provider safeguards, secure configurations, staff awareness, access controls, tested recovery and a financial response plan.
For businesses using BT or any other managed provider, it is sensible to ask what security services are included, what alerts will be provided, who monitors them, and what the provider will do during an incident. This avoids a dangerous gap between what the customer assumes is managed and what the contract actually covers.
A sensible next step for UK SME owners
The practical response to this news is a combined risk review. Start with the systems that would stop the business trading for a day: email, payments, customer records, point-of-sale systems, cloud files and line-of-business software. Estimate the revenue and extra expense of losing each one. Then compare that exposure with current controls and the actual scope of existing insurance.
If the business already has cyber cover, review renewal documents before an incident occurs. If it does not, obtain advice from a specialist broker and disclose controls accurately. Insurers may ask about MFA, backups, patching, staff training and prior incidents. Accurate answers matter: a policy is most useful when its conditions are understood and achievable.
FAQ
Does a standard business policy cover a cyberattack?
Often not comprehensively. Property, public liability and professional indemnity policies may contain limited cyber cover or cyber exclusions. Check the wording and ask specifically about ransomware, data breach costs, business interruption and social engineering fraud.
Is cyber insurance worthwhile for a micro-business?
It can be, particularly where the business depends on email, online payments, customer data or cloud software. The decision should be based on the likely cost of downtime and specialist response, not only on the number of employees.
Will cyber insurance pay a ransom?
Some policies may cover cyber extortion-related costs, subject to policy terms, sanctions rules, legal advice and insurer approval. Payment is not guaranteed and is not always advisable. The insurer's incident-response team will usually assess recovery options first.
What is the first security control an SME should implement?
For most firms, enforcing MFA on email and administrator accounts is one of the highest-impact first measures. It should be accompanied by tested backups and a strict payment-verification process.
Fuente: SecurityBrief UK — Fri, 31 Oct 2025 07:00:00 GMT