Why the “double exposure” matters
The Cumbria Crack report on why SMEs are doubly exposed to phishing attacks highlights a risk that is often misunderstood by smaller organisations. Phishing is not simply an unwanted email problem, nor is it limited to a staff member clicking a suspicious link. For a UK SME, one successful impersonation attempt can create two connected losses: the direct operational impact on the business and the harm passed on to customers, suppliers or partners.
That distinction is important when assessing cyber insurance. A firm may think its main concern is a fraudulent payment leaving its own bank account. In practice, a criminal who compromises a Microsoft 365 mailbox, payroll account or finance email chain may also use the trusted account to target clients. The business can then face incident-response costs, contractual disputes, privacy issues and reputational damage at the same time.
For SMEs with lean teams, this is especially serious. A larger company may have a security operations centre, segregated finance approvals and internal legal support. A ten-person construction contractor, accountancy practice, retailer or manufacturer is more likely to rely on a small number of people and cloud-based systems. That efficiency is useful until one compromised identity gives an attacker access to invoices, contacts, shared files and payment conversations.
The first exposure is the obvious one. An employee receives a convincing email that appears to come from Microsoft, a director, a supplier or a parcel carrier. They enter credentials into a fake login page, open a malicious attachment or approve a fraudulent multi-factor authentication prompt.
The consequences can include account takeover, unauthorised payments, malware deployment, data theft and business interruption. Even where no money is stolen immediately, compromised email access can allow criminals to monitor communications for days or weeks. They may wait for a property transaction, supplier payment or payroll run before changing bank details at the most damaging moment.
For many UK SMEs, the cost is not limited to the stolen amount. There may be fees for forensic investigation, specialist IT support, legal advice, customer notification and restoring systems. Staff time is also lost: directors, finance teams and operational employees may spend days responding instead of serving customers.
2. Your business becomes a launch point against others
The second exposure is more easily overlooked. Once a criminal controls a real business mailbox, they can send phishing messages from a genuine address and continue existing email threads. A customer receiving an altered invoice may see the correct branding, the right project name and a familiar contact. That makes the fraud substantially more credible than a generic scam.
The immediate financial victim may be the customer, but the SME whose account was compromised can still suffer serious consequences. Customers may lose trust, delay future work or ask whether the business had appropriate safeguards. Suppliers may challenge payment instructions. If personal data has been accessed, the organisation may need to assess whether the incident is reportable to the Information Commissioner’s Office (ICO) and whether affected individuals must be informed.
This is why phishing should be treated as both a first-party and third-party risk. The business may need help recovering its own systems while also managing claims, allegations or notification obligations arising from the impact on other people.
What this changes for cyber insurance decisions
Cyber insurance is not a substitute for security controls, but it can be a vital financial and practical backstop when controls fail. The most useful policies for UK SMEs are built around the real sequence of an incident rather than just a headline promise of “cyber cover”.
When comparing policies, business owners should examine whether cover includes:
- Incident response and digital forensics, including access to specialist providers who can contain a mailbox compromise and determine what happened.
- Data breach and privacy costs, such as legal advice, notification support and appropriate regulatory-response expenses.
- Cybercrime and social engineering cover, particularly for invoice fraud or authorised transfer fraud. This is often subject to specific conditions and sub-limits, so it should never be assumed to be automatically included.
- Business interruption, covering lost income and additional costs caused by a covered cyber event.
- Third-party liability, where a customer or other party alleges loss arising from the SME’s failure to protect systems, data or communications.
- Crisis communications and reputation support, which can be valuable when a compromised email account has been used to deceive customers.
A policy schedule and wording matter more than a marketing label. For example, a policy may provide strong breach-response support but impose a lower limit for social engineering losses. Another may require certain payment-verification procedures to be in place before a fraudulent-transfer claim is covered. SMEs should ask their broker or insurer to explain these conditions in plain English before a loss occurs.
Controls insurers and customers increasingly expect
Good cyber insurance applications are also a useful security checklist. Insurers commonly ask about controls because phishing losses are less severe when access, payment processes and recovery arrangements are well managed.
Protect email identities
Enable multi-factor authentication (MFA) for email, remote access, cloud storage and financial systems. Prefer phishing-resistant methods, such as authenticator apps or security keys, where practical, rather than relying solely on SMS codes. Disable legacy authentication methods that can bypass MFA.
Use separate administrator accounts for privileged tasks. No employee should routinely read email, browse the web and administer critical systems from the same highly privileged account.
Make payment fraud harder
Introduce an independently verified callback process for all changes to supplier bank details. The callback must use a trusted number already held on file, not a number supplied in the email requesting the change.
Set approval thresholds and dual authorisation for significant payments. It may feel cumbersome for a small team, but a two-person check is far cheaper than recovering a five-figure payment sent to a criminal account. Staff should be empowered to challenge an instruction that appears to come from a director; urgency is a common social-engineering tactic.
Reduce the value of a compromised inbox
Apply least-privilege access to shared folders and finance systems. Keep software, endpoints and email security tools updated. Maintain tested, offline or immutable backups for critical data. Review email forwarding rules and mailbox delegation regularly, as criminals often create hidden rules after gaining access.
Training should be specific, short and repeated. Show staff examples of supplier-bank-detail fraud, QR-code phishing, MFA fatigue prompts and fake document-sharing links. The goal is not to blame someone who clicks; it is to ensure people report suspicious activity quickly enough to limit the damage.
A practical 30-day action plan for UK SMEs
- Map the high-risk journeys: identify who can approve payments, access mailboxes, change bank details and handle customer data.
- Turn on MFA everywhere: start with Microsoft 365 or Google Workspace, accounting systems, banking and remote-access tools.
- Test supplier verification: confirm that every bank-detail change requires a documented callback and second approval.
- Run a phishing exercise: use a safe internal simulation or a managed provider, then give immediate, constructive guidance.
- Check your insurance wording: confirm the limits and conditions for cybercrime, business interruption, breach response and third-party liability.
- Create an incident card: include the insurer or broker’s emergency number, bank fraud contact, IT provider, key internal contacts and the instruction to preserve evidence.
The central lesson is that phishing can turn a trusted SME into both a victim and an unwitting conduit for fraud against others. Technical controls reduce the chance of compromise; payment verification reduces the chance of financial loss; and appropriate cyber insurance can provide expert support when the pressure is highest. None of these measures is sufficient alone, but together they make a small business far harder to exploit.
FAQ
It can, but cover varies significantly. Look for cybercrime or social-engineering cover and check the applicable limit, excess and security conditions. A standard cyber policy may not cover every authorised payment made after a deceptive email.
Is multi-factor authentication enough to stop phishing?
No. MFA greatly reduces risk, but attackers can use fake login pages, session theft and repeated approval prompts. Phishing-resistant MFA, staff training, email protection and payment controls should work together.
What should an SME do first after a suspected mailbox compromise?
Contact your IT or incident-response provider and your cyber insurer’s claims or breach helpline immediately. Secure the account, revoke active sessions, review forwarding rules, preserve evidence and warn relevant customers or suppliers before fraudulent messages spread.
Could a customer claim against us if our email account is used to defraud them?
Potentially, depending on the circumstances, contracts and whether the business is alleged to have failed in its security or communications practices. This is why third-party liability, legal support and clear incident records are relevant parts of a cyber-insurance review.
Source: Cumbria Crack — Fri, 02 Oct 2026 04:39:31 GMT