49% of UK Small Firms Had a Cyber Incident. Fix the Basics First.
Half of UK small firms suffered a cyber incident last year. ESET's 2026 report shows it wasn't AI attacks causing damage, it was basic security gaps SMBs can close today.
Half of UK small firms had a cyber incident in the past year, and the cause wasn't sophisticated AI-powered attacks. It was basic, preventable gaps: weak passwords, unpatched software, missing MFA. ESET's 2026 SMB Cyber Risk Report found that 49% of UK SMBs experienced an incident, yet most lacked foundational controls. If you're spending mental energy worrying about AI-generated malware before you've enforced MFA across your team, you're solving the wrong problem.
Why are so many small businesses getting hit by cyber incidents?
Because they're leaving the front door unlocked while worrying about someone picking the lock. ESET's 2026 SMB Cyber Risk Report found that 49% of UK small firms experienced a cyber incident in the past year. The culprits weren't nation-state actors or AI-generated attacks. They were the same basic failures that have plagued SMBs for a decade: no multi-factor authentication, unpatched systems, reused passwords, and staff who can't spot a phishing email.
This matters because the conversation in most SMB leadership circles has jumped straight to AI threats. That's a distraction. You cannot defend against advanced threats if you haven't closed the gaps a teenager with a phishing kit could exploit.
What does the ESET 2026 report actually say about SMB cyber risk?
The headline number is stark: nearly half of UK small firms reported an incident in a 12-month window. That's not a prediction or a modeled risk, it's reported experience from real operators. The report also found that many of these businesses lacked written security policies, had no formal incident response plan, and relied on a single person (often the owner) to handle anything security-related.
This isn't a technology gap. It's a governance gap. The tools to fix most of this cost little to nothing. Microsoft 365 includes MFA. Windows Update is free. Password managers like Bitwarden start at $3 per user per month. The barrier isn't budget, it's prioritization and accountability.
"The most common attack vector isn't AI. It's a staff member clicking a link they shouldn't have, on a system that hasn't been patched in six months."
What are the most common security gaps in small businesses?
Based on the ESET findings and what we see across SMB clients, these are the recurring failures:
- No MFA on email and key systems. Email compromise is the single most common entry point. If your team isn't using MFA on Microsoft 365 or Google Workspace, you are one credential breach away from a serious incident.
- Unpatched software and operating systems. Attackers scan for known vulnerabilities. Unpatched systems are easy targets. Most SMBs have machines running months behind on updates.
- No written security policy. Staff don't know what they're allowed to do, what to click, or who to call when something looks wrong. A one-page policy fixes this.
- Weak or reused passwords. Without a password manager enforced across the team, people reuse credentials. One breach elsewhere exposes your systems.
- No phishing awareness training. Staff who haven't been trained click things. It's not a character flaw, it's a training gap. A basic quarterly drill changes behavior.
- No incident response plan. When something goes wrong (and it will), most SMBs improvise. That costs time, money, and data.
How does AI actually fit into SMB cyber threats right now?
AI is making phishing emails more convincing and lowering the skill floor for attackers. That's real. But it's a multiplier on existing attack methods, not a new category that bypasses basic defenses. An AI-written phishing email still needs someone to click it. A credential stuffing attack still needs a weak or reused password to work.
The businesses that suffered incidents in the ESET report weren't breached because attackers used AI. They were breached because the basics weren't in place. Fixing the basics makes you significantly more resilient against AI-enhanced attacks too, because those attacks are still exploiting the same human and systems gaps.
What does a realistic SMB security fix list look like?
Here's a prioritized table based on impact versus effort:
| Control | Impact | Effort | Cost | |---|---|---|---| | Enable MFA on email | Very High | Low | Free (M365/Google) | | Deploy password manager | High | Low | $3–$5/user/month | | Automate OS/software updates | High | Low | Free | | One-page security policy | High | Medium | Internal time only | | Phishing simulation training | Medium | Medium | $10–$25/user/year | | Written incident response plan | Medium | Medium | Internal time only | | Endpoint protection (EDR) | Medium | Medium | $5–$15/user/month | | Backup and recovery testing | High | Medium | $50–$200/month |
None of this requires a full-time security hire or a six-figure budget. A focused two-week sprint with clear ownership closes most of these gaps.
Does being in the UK change anything, or does this apply to all SMBs?
The ESET report is UK-specific, but the gap profile is nearly identical across US, Australian, and European SMBs. The Verizon 2024 Data Breach Investigations Report consistently shows that credential theft, phishing, and unpatched vulnerabilities account for the majority of SMB breaches globally. The geography changes the regulatory context (UK firms need to think about UK GDPR and Cyber Essentials), but the fix list is the same.
If you're a UK firm, Cyber Essentials certification is worth pursuing. It covers five core controls that map directly to the gap list above, and some insurers offer better premiums for certified businesses.
What we'd actually do
- Run a one-hour internal audit this week. Check MFA status on email, check patch levels on all machines, and ask your team whether they know what to do if they get a suspicious email. Document what you find. You can't fix what you haven't looked at.
- Pick two controls from the table above and assign an owner with a deadline. MFA and a password manager are the highest-leverage starting point. Don't try to fix everything at once. Two controls done properly beat eight controls half-implemented.
- Build a one-page incident response plan before you need it. Who do you call? What do you shut down first? Where are your backups? This takes two hours to write and can save days of chaos when something goes wrong. If you want a structured way to work through AI governance and security readiness with other SMB operators, that's exactly what we cover inside skool.com/aiforbusiness.
FAQ
What caused most cyber incidents in UK small businesses according to ESET?
Basic security failures, not sophisticated AI attacks. ESET's 2026 SMB Cyber Risk Report found that 49% of UK small firms experienced an incident, and the common causes were things like missing MFA, unpatched software, weak passwords, and staff with no phishing training. These are preventable with low-cost controls most businesses already have access to.
Is MFA really enough to protect a small business from cyber attacks?
MFA alone isn't a complete defense, but it's one of the highest-impact single controls you can deploy. Microsoft has reported that MFA blocks over 99% of automated credential attacks. It won't stop every threat, but it eliminates the easiest and most common entry point. Treat it as the floor, not the ceiling, of your security posture.
How much does it cost to fix basic cybersecurity gaps in a small business?
Less than most operators assume. MFA on Microsoft 365 or Google Workspace is included in existing licenses. A password manager like Bitwarden runs $3–$5 per user per month. Phishing training tools start around $10–$25 per user per year. A written security policy and incident response plan cost internal time, not budget. Most SMBs can close the core gaps for under $500 per year total.
Want this running in your business?
The Skool community is where we show the full builds, share the templates, and help you implement. Three tiers, from team training to fractional AI expert.
- Weekly Q&A with Alex and Cameron
- Templates and frameworks you can steal
- Real builds, running in real businesses
More on Governance
Fake HR Apps Are Stealing Payroll Access From SMBs
Hackers built AI-powered fake clones of US HR and payroll platforms to trick staff into downloading remote access tools. Here is how to spot and block it.
Vibe-Coded Phishing Kits: What Okta's Threat Chief Says Lock Down Now
Attackers build custom phishing kits in days using AI. Okta's Jeremy Kirk explains stolen sessions, AI-assisted attacks, and why passkeys are non-negotiable.
AI Agents Are Opening New Doors Into Your Business Data
AI agents expand your attack surface while making phishing and ransomware cheaper to run. Here's what SMBs need to do right now to stay protected.