Insights

"We are too small to be a target" — and other cyber myths

Most attacks are not targeted — they are automated, and they find whatever is exposed. We unpick the most common myths that leave smaller businesses at risk.

Talk to enough small businesses and you hear the same reassuring beliefs. Most of them are wrong, and a couple are actively dangerous. Here are the myths we hear most, and what is really going on.

Myth 1: "We are too small to be a target"

This is the big one, and it is backwards. Most attacks are not aimed at a specific company at all. They are automated: tools sweep the entire internet looking for a known weakness — an unpatched server, a default password, an exposed login — and hit whatever they find. The attacker often has no idea who you are until they are already in.

Being small does not make you invisible. It usually just means fewer defences standing in the way of the same automated attack. Size is not a shield.

Myth 2: "Our IT company handles all that"

Maybe they do. But "handling IT" and "managing security" are not the same job, and the assumption is worth checking rather than trusting. Ask a direct question: are multi-factor authentication, prompt patching, least-privilege access and monitored backups actually in place — and can they show you? A good provider will welcome the question. Cyber Essentials is a useful framework here precisely because it turns vague reassurance into specific, checkable controls.

Myth 3: "We would know if we had been breached"

Often, no. Attackers who get in usually want to stay quiet — to harvest data, sit in wait, or pick their moment. Dwell times of weeks or months are common. The absence of an obvious problem is not evidence that all is well; it is frequently just the absence of anyone looking.

Myth 4: "A firewall and antivirus are enough"

They are necessary, not sufficient. Modern incidents routinely involve phished credentials, reused passwords, and misconfigurations that a firewall never sees. Defence today is about layers: strong authentication, disciplined patching, sensible access control, and knowing what an attacker could actually reach.

Myth 5: "Security is too expensive for a business our size"

The controls that stop the majority of attacks are strikingly affordable — often free. Turning on multi-factor authentication costs nothing. Patching promptly costs nothing. Removing unused accounts costs nothing. These unglamorous basics are exactly what Cyber Essentials formalises, and they deliver far more protection per pound than any single expensive product.

Small is not the same as defenceless. The gap is rarely budget — it is usually just knowing which few things to get right.

The reassuring truth

Here is the good news buried under the myths: the fundamentals that stop most attacks are achievable for any organisation, whatever its size. You do not need an enterprise budget or a security team. You need the basics done properly, and proof that they are.

That is what we help with. If you would like to know where you stand, start with our free Cyber Essentials readiness checklist, read our plain-English guide to Cyber Essentials, or get a fixed-price quote and we will take it from there.

Talk to a tester

Put this into practice.

Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.

← All insights