Updated 28 September 2026 · By Yann Davies, Managing Director, ABCOM IT Solutions (supporting Sussex businesses since 1996)
The short version
- 43% of UK businesses had a cyber breach or attack in the last year. Phishing is still the cause most of the time.
- Cyber Essentials is the best-value first step. Certified organisations are 92% less likely to make a cyber insurance claim, and the rules got stricter in April 2026.
- AI is the new gap. 71% of UK employees have used unapproved AI tools at work, and most businesses using AI have no controls for it.
- Before switching on Microsoft Copilot, fix your permissions. Copilot can find anything a user already has access to.
- Start with the 10-step action plan below.
This guide is for owners and managers of small and medium-sized businesses and charities who want to understand the real risks in 2026 and what to do about them, without the jargon. It’s based on the UK Government’s latest Cyber Security Breaches Survey, NCSC guidance, and what we see day to day supporting businesses across Sussex.
Chapter 1: The threat in numbers (2026)
The UK Government’s Cyber Security Breaches Survey 2025/2026 is the most reliable picture of what’s happening to UK organisations. The headline findings:
Source: Cyber Security Breaches Survey 2025/26, DSIT and Home Office.
- 43% of businesses and 28% of charities identified a cyber breach or attack in the last 12 months. That’s around 612,000 businesses.
- Small businesses aren’t safe because they’re small. 42% of micro businesses and 46% of small businesses were affected, rising to 65% of medium-sized firms.
- Phishing dominates. 38% of businesses experienced phishing, and it was the most disruptive type of attack for 69% of those hit. Interviewees said phishing has become easier for attackers, largely because of AI.
- 19% of businesses were victims of cyber crime (about 267,000), and 93% of those crimes involved phishing.
- Around 43,000 businesses lost money to fraud that started with a cyber attack, across roughly 130,000 fraud events.
Worryingly, basic protection among small businesses slipped back this year:
Only 41% did a cyber risk assessment (down from 48%), 52% had a formal cyber security policy (down from 59%) and 44% had a business continuity plan covering cyber (down from 53%). Source: Cyber Security Breaches Survey 2025/26.
Most incidents cost little. But the worst 5% cost micro and small businesses £4,000 or more, and that’s before lost time, lost clients and reputational damage.
Chapter 2: The attacks that actually hit small businesses
Phishing and email account takeover
A convincing email tricks someone into entering their Microsoft 365 password on a fake login page. The attacker then reads the mailbox, watches for invoices and quietly changes bank details. AI now writes these emails in perfect English, tailored to your suppliers and staff.
Stop it with: multi-factor authentication (MFA) on every account, a rule that bank detail changes are always confirmed by phone on a known number, and regular staff awareness training. Our free Email Hijack Guide walks through the warning signs.
Invoice and payment fraud
This is often the most expensive attack for small firms. It needs no malware, just a hijacked or look-alike email address and a busy accounts team.
Ransomware
Ransomware hit 1% of businesses in the latest survey, down from 3%. It’s rarer now, but when it happens it can stop a business completely for days. Good, tested backups kept separate from your main systems are the difference between an inconvenience and a disaster.
AI voice clones and deepfakes
Criminals can now clone a director’s voice from a short clip online and phone the finance team asking for an “urgent, confidential” payment. The same verify-by-call-back rule protects you here.
Unpatched software and remote access
Old firewalls, unsupported Windows versions and remote access left open to the internet are still an easy way in. Automatic updates and a supported, well-configured firewall close most of these doors.
Chapter 3: Cyber Essentials, the baseline every UK business should have
Cyber Essentials is the UK Government-backed scheme, run with the NCSC, that certifies you have five basic controls in place:
Why it’s worth it
Organisations with Cyber Essentials were 92% less likely to make a cyber insurance claim, based on claims data from the scheme’s insurer (NCSC).
- It works. Data from the insurer behind the scheme showed certified organisations were 92% less likely to make a cyber insurance claim (NCSC).
- Free cyber insurance. UK organisations with turnover under £20m that certify their whole organisation can opt in to cyber liability insurance with up to £25,000 of cover, including a 24-hour incident helpline (IASME).
- It wins work. Government contracts and more and more larger clients require it from suppliers.
- You’d stand out. Only 12% of small businesses hold it, even though about a quarter of businesses already have all five controls in place.
What changed in April 2026
The latest version of the Cyber Essentials requirements (known as “Danzell”, v3.3) applies from 27 April 2026 and is stricter:
- MFA must be switched on for every cloud service that offers it, even if it’s a paid extra. Missing it is now an automatic fail.
- Critical and high-risk updates must be applied within 14 days, and one missed patch can fail you.
- Cloud services that hold your data are always in scope. You can’t leave Microsoft 365 or your CRM out.
If you certified before April, your next renewal will be assessed against these rules. ABCOM guides clients through the whole process. See our Cyber Essentials service.
Chapter 4: AI and your security, the new gap
AI is now part of everyday work, but most small businesses haven’t caught up on the risks. The Government survey found that 31% of businesses are using or considering AI, and only 24% of those have any security practices in place to manage it.
Shadow AI: the risk you can’t see
“Shadow AI” is staff using AI tools the business hasn’t approved: pasting client emails into a free chatbot, uploading contracts to an AI summariser, or installing AI browser extensions. Microsoft research found:
- 71% of UK employees have used unapproved consumer AI tools at work, and 51% still do every week
- only 32% were concerned about the privacy of company or customer data they put in
- 28% said their employer doesn’t give them an approved option
Source: Microsoft UK research with Censuswide, October 2025 (2,003 UK employees).
It’s rarely malicious. People are just trying to get work done faster. But confidential or personal data can leave your control, which can breach UK GDPR and client contracts.
What to do:
- Find out which AI tools people already use.
- Give them a safe, approved option, such as Microsoft 365 Copilot Chat signed in with a work account.
- Write a short AI acceptable use policy that says what data must never go into AI.
- Block or monitor high-risk tools where needed.
- Train staff. Banning AI outright rarely works; people just use their phones.
Microsoft Copilot: fix permissions first
Microsoft 365 Copilot is secure by design. It keeps your data inside your Microsoft 365 environment and respects existing permissions. The catch is that Copilot can find anything a user already has access to. Most businesses have years of SharePoint sites, Teams and shared folders that are open far too widely. Salary spreadsheets, HR files and client contracts become one question away.
Before rolling out Copilot, you should:
- review SharePoint, Teams and OneDrive sharing and remove “everyone” access
- make sure MFA and Conditional Access are enforced
- label sensitive information so it can be protected
- set Copilot spending limits. Newer features like Copilot Cowork are billed per use, and from November 2026 new Copilot Business licences have usage billing switched on by default.
Read more in our AI and Microsoft Copilot FAQs.
The ABCOM AI Readiness Sprint
We built our four-week AI Readiness Sprint because so many businesses were switching on AI before the groundwork was done:
You receive an executive report, your AI Readiness Score, a Copilot readiness assessment, a risk register and a roadmap your team can act on. In one recent Sprint for a Sussex recruitment firm, we found staff already using ChatGPT with no policy, SharePoint permissions that were far too open, and gaps in MFA, all before Copilot had been switched on.
Chapter 5: Your 10-step action plan
- Turn on MFA everywhere, starting with email, Microsoft 365, banking and remote access.
- Get Cyber Essentials. It gives you a checklist, a certificate and free insurance.
- Keep everything updated, with critical patches applied within 14 days, and replace unsupported devices.
- Back up properly: automatic, separate from your main systems, and tested by actually restoring files.
- Agree a payment verification rule: any change of bank details is confirmed by phone on a known number.
- Train your people at least twice a year, with short phishing simulations in between.
- Tidy access: remove old accounts, limit admin rights and fix over-shared SharePoint and Teams sites.
- Write an AI policy and give staff an approved AI tool.
- Write a one-page incident plan: who to call, what to switch off, and how to reach clients.
- Review it every year, or sooner if you change systems, suppliers or staff.
Chapter 6: Policies and risk assessment made simple
Fewer than half of small businesses did a cyber risk assessment last year. It doesn’t need to be complicated:
- List what matters: client data, finance systems, email and key files.
- Ask what could go wrong: a stolen password, a lost laptop, a ransomware attack, a supplier breach.
- Rate each risk by how likely it is and how bad it would be.
- Decide the fix and who owns it.
Then capture it in short policies people will actually read:
- information security
- acceptable use, including AI
- passwords and MFA
- remote working and bring your own device (BYOD)
- backup
- incident response
We write these for clients as part of our cyber security service.
Chapter 7: Your people are your best defence
Most attacks start with a person clicking a link or approving a request. Good training is short, regular and practical:
- how to spot phishing and fake login pages
- why you verify payment changes by phone
- what not to paste into AI tools
- how to report something suspicious quickly, without fear of blame
Chapter 8: If the worst happens, the first hour
- Don’t panic, and don’t pay any ransom. Call your IT provider straight away. ABCOM clients call 01444 871200.
- Contain it: disconnect affected devices from the network, but don’t switch them off, so evidence is preserved.
- Secure accounts: reset passwords and revoke sessions for affected users.
- Check your insurance: Cyber Essentials policyholders have a 24-hour incident helpline.
- Report it: personal data breaches may need reporting to the ICO within 72 hours. Report cyber crime to Report Fraud (it replaced Action Fraud) on 0300 123 2040.
- Restore from clean backups and fix the cause before going back to normal.
- Learn from it: update your plan and training.
Chapter 9: Cyber insurance
47% of businesses now have some form of cyber insurance, rising to 55% of small businesses. Before you buy or renew, check what the policy requires. Most insurers expect MFA, backups, updates and staff training, and a claim can be refused if they’re missing. Cyber Essentials includes up to £25,000 of cover for eligible organisations, and ABCOM partners with a specialist insurer for higher limits.
Chapter 10: When to get outside help
Most small businesses don’t have a full-time IT security person, and they don’t need one. A good managed service provider gives you a whole team, 24/7 monitoring and a clear plan for a predictable monthly cost. Look for a provider that:
- holds recognised credentials, such as NCSC Assured Service Provider status and Cyber Essentials
- explains things in plain English
- can cover IT, security, Microsoft 365 and AI together, rather than leaving gaps between suppliers
ABCOM is an NCSC Assured Service Provider based in Burgess Hill, supporting businesses and charities across Sussex and the UK since 1996.
Frequently asked questions
What is the biggest cyber threat to small businesses in 2026?
Phishing. It was experienced by 38% of UK businesses in the Government’s 2025/2026 Cyber Security Breaches Survey and was the most disruptive type of attack for 69% of those affected. AI makes phishing emails more convincing, so MFA, a verify-by-phone rule for payment changes and regular staff training are the most effective defences.
Is Cyber Essentials worth it for a small business?
Yes. It is the UK Government-backed baseline, it wins contracts, and data from the scheme’s insurer showed certified organisations were 92% less likely to make a cyber insurance claim. UK organisations with turnover under £20m that certify their whole organisation can also opt in to free cyber liability insurance with up to £25,000 of cover.
What changed in Cyber Essentials in April 2026?
From 27 April 2026 the “Danzell” (v3.3) requirements apply. MFA must be enabled on every cloud service that offers it, critical and high-risk updates must be applied within 14 days, and cloud services holding your data are always in scope. Missing MFA or a critical patch is now an automatic fail.
What is shadow AI and why does it matter?
Shadow AI is staff using AI tools the business hasn’t approved, such as free chatbots or AI browser extensions. Microsoft research found 71% of UK employees have done this. It matters because confidential or personal data can leave your control, risking UK GDPR breaches. The fix is an approved AI tool, a short AI policy and staff training.
Is it safe to switch on Microsoft 365 Copilot?
Copilot keeps data inside your Microsoft 365 environment and respects existing permissions, but it can surface anything a user already has access to. Review SharePoint, Teams and OneDrive sharing, enforce MFA and Conditional Access, and label sensitive data before rollout.
What is ABCOM’s AI Readiness Sprint?
A four-week programme that gets your business ready to use AI safely: discovering current AI use (including shadow AI), securing Microsoft 365 and permissions, preparing an AI policy and staff guidance, and delivering a prioritised roadmap with a Copilot readiness assessment.
Not sure where your business stands?
Book a free IT and cyber security review with our Burgess Hill team, or ask about Cyber Essentials and our AI Readiness Sprint.
Sources
- UK Government: Cyber Security Breaches Survey 2025/2026
- NCSC Annual Review 2025: Cyber Essentials impact
- IASME: Cyber liability insurance with Cyber Essentials
- Microsoft UK: Rise in shadow AI tools
- NCSC: Small Business Guide
- Report Fraud (formerly Action Fraud)
Do not just read it. Act on it.
Reading is the easy part. Book a free IT review and we will tell you, in plain English, where your business stands and what to fix first.