UKBA logo dark

Could Your SME Keep Trading After a Cyber Attack?

By Nick Shanagher

A cyber attack rarely arrives at a convenient moment. One minute, staff are answering emails, processing orders and serving customers. The next, systems are unavailable, files cannot be opened or someone is demanding money to restore access.

For many SME owners, cyber security still feels like an IT issue. But the real question is a business one: could the company continue trading if its technology suddenly stopped working?

UKBA members identify cyber security, data protection and technology risk as growing concerns for their clients. The danger is not limited to large organisations. Smaller businesses can be attractive targets because they often hold valuable information but have fewer controls and less specialist support.

The strongest response is not simply to buy more security software. It is to prepare the business to respond, recover and keep serving customers.

1. Nobody knows who takes control

When an incident begins, speed matters. Yet many businesses have never agreed who will make decisions, contact suppliers, speak to customers or authorise emergency spending.

If responsibility is unclear, valuable time is lost while people wait for the owner or assume someone else is dealing with the problem. A short response plan should name the people who will lead, the specialists who can help and the decisions they are authorised to make.

2. Email is your only communication channel

Most businesses rely heavily on email. If accounts are compromised or servers are unavailable, staff may suddenly lose access to customers, colleagues and suppliers.

Owners should consider how the team would communicate without normal systems. Do key people have secure alternative contact details? Can customers be updated through the website, telephone or another approved channel? The answer does not need to be complicated, but it should not be invented during a crisis.

3. You have backups but have never tested them

Many owners take comfort from being told that the business is backed up. The important question is whether those backups can actually be restored.

A backup may be incomplete, too old or connected to the same systems that have been attacked. Recovery may also take far longer than expected. Businesses should know what is being backed up, how often it happens and how long it would take to restore the information needed to trade.

4. Too much depends on one supplier or employee

A business may rely on one external IT provider, one system administrator or one experienced employee who understands how everything fits together. That dependence becomes dangerous when the person is unavailable or the supplier is overwhelmed.

Key access details, supplier contacts and recovery arrangements should not exist only in one person’s head. The aim is not to remove trusted relationships. It is to make sure the business can still act when one person cannot.

5. Staff are unprepared for fraud and manipulation

Many attacks begin with a convincing email, message or telephone call. Artificial intelligence is making fraudulent communications easier to produce and harder to recognise.

Employees need simple guidance on unusual payment requests, password resets, unexpected attachments and changes to supplier bank details. They should also know how to report a mistake quickly. A culture that punishes people for raising concerns may encourage them to hide a problem until it becomes more serious.

6. You have not considered the customer impact

A cyber incident can damage more than systems. Delayed orders, missed appointments and poor communication quickly affect trust. Customers may also worry that their information has been exposed.

The business should decide in advance how it will explain an interruption honestly without creating unnecessary alarm. Clear, timely communication often protects confidence better than silence or speculation.

7. Cyber risk is never discussed by the leadership team

Cyber security is often delegated entirely to an IT supplier. Technical expertise is essential, but leadership still owns the commercial consequences.

The management team should periodically ask what systems are critical, how long the business could operate without them and what has changed since the last review. Cyber risk belongs alongside cash flow, people and operational performance, not in a separate technical box.

Prepare for continuity, not perfection

No business can remove every risk. The objective is to reduce the chance of an incident, limit the damage and restore essential operations quickly.

Start with the activities the business must continue: communicating with customers, taking orders, paying staff, accessing key records and meeting legal obligations. Then identify what would be needed to keep those activities moving if normal systems were unavailable.

Many SMEs benefit from an independent review of their cyber and business continuity arrangements. Contact UKBA for a free initial consultation with an experienced business adviser.

Nick Shanagher – Sales & Marketing

Need advice & guidance?

We have advisors all over the UK. Get in touch today for expert guidance and support.