
Our Co-Founder and Operations Director, James Bannon, has been featured in Tech User Magazine discussing one of the most dangerous assumptions still held by small business owners today: "we're too small to be a target." You can read James's full article here.
It's a belief we hear constantly at BM Technologies, and it's one that no longer holds up. Below, we've expanded on the themes James raised, and set out what small and medium sized businesses across Greater Manchester and the North West can actually do about it.
Why "we're too small to be a target" no longer applies
Cyber criminals don't pick targets by hand anymore. Modern attacks are automated, running constant scans across the internet looking for weak points. To that kind of system, a ten-person accountancy firm looks identical to a FTSE 250 business. The only real difference is defence. Larger organisations usually have dedicated IT and security teams. Most SMEs don't, which makes them the easier target, not a less likely one.
What a real attack actually looks like
Cyber attacks rarely look like the movies. There's no dramatic countdown timer. In reality, the pattern is far quieter and far more damaging:
- An email account is compromised, an invoice is intercepted, and a genuine customer pays tens of thousands of pounds into a criminal's account
- Ransomware locks every file on a Friday afternoon, and the business only discovers on Monday that its "backup" was stored on the same server that just got encrypted
These aren't rare, extreme cases. They're the everyday reality for UK small businesses right now, and they're entirely preventable.
The same gaps, again and again
Working with SMEs and care providers across the region, including organisations holding highly sensitive personal data, we see the same handful of issues on repeat:
- No multi factor authentication on email accounts
- Staff who have never been shown what a phishing email looks like
- Backups that have never actually been tested
- Admin passwords shared informally on a spreadsheet
None of these are complicated or expensive to fix. They're simply overlooked, usually because nobody in the business has been given clear ownership of cyber security.
The regulatory pressure is building
The direction of travel in the UK is clear. The Cyber Security and Resilience Bill signals that resilience is moving from "nice to have" to a legal and commercial expectation. Larger organisations are already pushing security requirements down through their supply chains. Small suppliers who can't evidence basic cyber hygiene will increasingly lose contracts to those who can, regardless of how good their actual work is.
For businesses in regulated sectors, particularly care, this is even sharper. Data protection and safeguarding expectations sit alongside cyber resilience, and the two are increasingly assessed together.
Three questions every business owner should be able to answer
James's advice in the article boils down to three simple questions. If you can't confidently answer all three, that's exactly where to start:
- Could we recover our data tomorrow if everything was encrypted today?
- Does every account with access to money or data have multi factor authentication switched on?
- Would our staff recognise a fraudulent payment request?
Cyber security is now a survival issue, not an IT issue
The businesses still standing after an attack won't be the ones who were lucky. They'll be the ones who treated cyber resilience as a core part of running the business, not a task left to "get around to." Flat rate, security included pricing means there's no reason to leave it unaddressed while you wait for a bigger budget.
If you're not confident in your answers to the three questions above, get in touch with BM Technologies for a straightforward, no jargon conversation about where your gaps are and how to close them.
Tech That Works.
Featured image: BM Technologies original illustration.
