
The latest UK cyber figures are a useful reminder that security is no longer a once-a-year compliance job. The Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses identified a cyber breach or attack in the last 12 months. For small and medium-sized businesses, that should shift the question from “will we be targeted?” to “how quickly could we contain and recover?”
That matters even more as AI changes the attacker playbook. In April, the UK Government and NCSC warned business leaders that AI can increase the speed, scale and credibility of cyber threats, and pointed organisations towards practical NCSC support such as Early Warning. For SMEs, the sensible response is not panic. It is tightening the basics that stop a bad email, stolen password or infected device becoming a business-wide outage.
1. Treat backups as a recovery system, not a checkbox
A backup that has never been restored is only a hopeful file copy. Ransomware and accidental deletion both expose the same weakness: businesses often discover too late that backups are incomplete, too slow to restore, or reachable from the same compromised account.
- Keep at least one backup copy isolated from normal user accounts.
- Test restores for Microsoft 365, servers and key line-of-business data.
- Write down realistic recovery times for the systems staff need first.
2. Make account security harder to bypass
The NCSC’s small organisations guidance still puts strong account protection near the centre of SME cyber security. That is because compromised inboxes, remote access accounts and admin portals are often the fastest route into a business.
- Use multi-factor authentication on email, cloud apps, admin panels and remote access.
- Remove old accounts promptly when staff or suppliers leave.
- Separate everyday accounts from administrator accounts.
- Review mailbox forwarding rules and suspicious OAuth app permissions.
3. Know what happens in the first hour
Incidents become more expensive when nobody knows who can disconnect a device, reset accounts, contact the IT provider, notify insurers or decide whether a personal data breach may need reporting. The ICO’s ransomware and data protection guidance makes clear that ransomware can create compliance issues as well as technical ones.
A simple incident plan should include named contacts, out-of-hours escalation, insurer details, backup restore priorities, and a decision log. It does not need to be a giant document. It needs to be clear enough that someone can use it under pressure.
4. Watch the edges of the business
Many SMEs now rely on cloud platforms, hosted websites, payment tools, suppliers and remote access. The Government’s cyber security guidance for business continues to highlight ransomware as a key threat, but the route in is often a weaker edge: an exposed remote login, unpatched website plugin, unmanaged laptop or supplier account.
- Patch operating systems, browsers, network devices and website software quickly.
- Keep endpoint protection active on laptops, desktops and servers.
- Review who can access shared cloud data and from where.
- Ask key suppliers how they protect access to your data and systems.
What BM Technologies recommends
For most SMEs, the highest-value next step is a short resilience review: backup restore test, MFA coverage check, device security review, admin account audit and incident contact list. Those checks are practical, measurable and far more useful than vague promises that everything is “secure”.
If you want a clearer view of where your business stands, BM Technologies can review your current setup and turn it into a sensible action plan covering managed IT, Microsoft 365, backups, hosting and cyber security.
