An open laptop with a big padlock image on its screen plus network pathways all in shades of blue to represent cyber security

Cyber-attacks might make the headlines when they affect major corporations, but cyber security isn’t only a big-business issue. Small and medium-sized enterprises (SMEs) are targets too – and the consequences can include operational disruption, financial loss and damage to important business relationships.

According to the Government’s latest Cyber Security Breaches Survey, 46% of small businesses and 65% of medium-sized businesses identified a cyber security breach or attack during the previous 12 months, with phishing by far the most commonly reported type.

Technology plays an important part in keeping businesses secure, but so do the everyday decisions made by the people using it. Read on to find out what SMEs and their employees should be looking out for – and what simple steps we can all take to reduce the risk?.

Why SMEs need to take cyber security seriously

Almost every modern business relies on digital technology in some form. Emails, online banking, cloud storage, document sharing, accounting systems and mobile devices have made the way we work faster and more connected – but they also provide potential access routes into a business.

And sometimes it only takes one mistake – clicking a malicious link, responding to a fraudulent payment request or approving an unexpected login. Any of these could potentially give a criminal access to information or systems they shouldn’t be able to reach.

For SMEs, one of the challenges is that they may not have the same level of dedicated IT and cyber security resources as larger organisations. However, in its latest guidance, the National Cyber Security Centre (NCSC) makes the point that cyber security shouldn’t be left to one individual. Everyone within an organisation has a part to play.

Four common scams and risks to watch out for

Cyber threats continually evolve, but many attacks still rely on something relatively simple – persuading someone to take an action they otherwise wouldn’t. Here are four areas employees should be particularly alert to.

1. Phishing emails

Phishing messages are designed to persuade you that a communication is genuine so you’ll click a link, open something, provide information or take another requested action.

Warning signs can include unexpected login prompts, messages claiming a password is about to expire, fake document-sharing notifications and requests to verify your identity. The sender’s email address may also have been altered very slightly to resemble a genuine address.

Unfortunately, spotting them isn’t always as easy as looking for bad spelling or an obviously suspicious email. Scam messages are becoming increasingly convincing and professional. That makes a simple rule particularly useful: if you weren’t expecting it, stop and check before clicking.

2. Invoice and payment fraud

A message appearing to come from a supplier, colleague or senior manager might request an urgent payment, provide an updated invoice or tell you that bank details have changed.

When money is involved, don’t rely on the email alone. Verify requests independently using contact details you already know to be genuine. A quick telephone call could prevent a very expensive mistake.

3. Unexpected authentication requests

Multi-factor authentication (MFA) and two-step verification provide an important additional layer of protection for online accounts. But an unexpected authentication request should never simply be approved.

One tactic involves repeatedly sending authentication prompts in the hope that the recipient eventually approves one by mistake or simply to make the notifications stop.

If you receive an authentication or login request that you haven’t initiated, don’t approve it and report it through your company’s normal process.

4. Remote working and personal devices

Working remotely and across different devices is now commonplace, but it can introduce additional risks.

Personal or unmanaged devices may not have the same security controls, software updates or protection as company-managed equipment. Employees should therefore follow their organisation’s rules about which devices can be used to access company systems and information.

Simple steps can make a big difference

Cyber security can sound highly technical, but many of the things employees can do to help protect a business are surprisingly straightforward, including:

  • Using MFA or two-step verification on important accounts
  • Using strong, unique passwords
  • Keeping devices and software updated
  • Using only approved devices for work
  • Independently verifying payment and bank-detail changes
  • Maintaining reliable backups of important data – and knowing how to restore them
  • Reporting suspicious emails or login requests promptly

Building cyber awareness at Sheriff

At Sheriff Construction, we’re taking steps to strengthen cyber awareness across our business.

One member of our team is currently completing Cyber Essentials training and has responsibility for sharing relevant information about emerging risks and good practice with colleagues.

Alongside this, we’re making sure everyone keeps up to date with their own cyber security training. The aim is not to turn everyone into a cyber security expert, but to give our people the knowledge and confidence to recognise potential warning signs and understand what they should and shouldn’t do.

Stop, think and check

Cyber criminals will continue to adapt the ways they target businesses, so there is unlikely ever to be a point where organisations can simply declare the job finished.

For SMEs in particular, good cyber security is therefore about developing good habits and keeping awareness fresh.

Be cautious with unexpected communications. Keep devices and accounts secure. Verify unusual requests independently. Don’t approve something simply because it appears urgent. And if something doesn’t feel right, report it.

Sometimes taking a few extra moments to stop, think and check could be enough to prevent a much bigger problem.

For further practical guidance on protecting a small or medium-sized organisation, visit the National Cyber Security Centre’s cyber security guidance for SMEs.

23.09.2026

Feature image: Magnific