Could Your Small Business Recover from a Cyber Attack?

According to the National Cyber Security Centre, half of small businesses experience a cyber incident each year. Here are six practical questions that can help you understand how prepared your business really is.

By Lorenzo Mugnai · · Custom Software & Integrations · 4 min read

I was reading some recent guidance from the National Cyber Security Centre the other day, and one statistic really stood out.

Around half of small businesses experience some form of cyber incident each year.

Now, before you picture sophisticated hackers trying to break into your systems, I don't think that's actually the interesting part. What made me stop and think was a much simpler question.

If something happened tomorrow, how well could your business actually recover?

For many small businesses, technology quietly becomes part of everyday life. You stop thinking about it because it simply works. Your website brings in enquiries while you're busy elsewhere, invoices are sent from online accounting software, customer information lives in the cloud and files are shared between laptops, phones and tablets without a second thought.

It's only when one of those things suddenly stops working that you realise just how much the business depends on it. That's why I don't think cyber security is simply about preventing attacks. I think it's about understanding what your business relies on and making sure one unexpected problem doesn't bring everything to a standstill.

The conversation I'd be having

If somebody asked me where to start, I honestly wouldn't begin by recommending a security product. I'd probably start by asking a few simple questions instead.

The first would be about email.

For many businesses it's where everything happens. Customer enquiries arrive there, appointments are arranged, quotes are sent, invoices are chased and password reset emails all end up in the same inbox. Most of us don't really think about that until we suddenly can't get in. If your email account became unavailable tomorrow morning, how much of your business would grind to a halt before lunchtime?

From there I'd probably ask who actually has access to your systems.

It's surprisingly easy to lose track over the years. There might be a former employee, the web designer who built your first website, a freelance developer, a marketing agency or even a family member who helped set something up when the business first started. None of those people are necessarily a problem, but it's worth knowing exactly who can still access your systems today.

We'd almost certainly end up talking about backups as well. Most people will confidently tell me they have them, but the better question is whether they've ever restored one. There's a big difference between knowing a backup exists and knowing it will actually get your business back up and running when you need it.

The conversation would naturally move on to software updates. They're one of those jobs that's always easy to put off until next week because everything seems to be working fine. Unfortunately, that's exactly what criminals rely on. Many successful attacks don't involve sophisticated hacking at all; they simply take advantage of software that hasn't been updated.

I'd also ask whether you'd notice if something wasn't right. Most cyber incidents don't begin with alarms going off or dramatic warning messages. Sometimes it's just an unexpected login notification, an email that doesn't quite look right or a customer asking why you've sent them something you know you didn't send. Spotting those early signs can make a huge difference.

Finally, I'd ask one very practical question. If the worst did happen tomorrow, who would you call first?

It's surprising how many businesses haven't really thought about that. When you're under pressure isn't the best time to start searching Google for help.

Our view

I don't think small businesses need to become cyber security experts.

They do need to understand which parts of their business rely on technology, where the obvious risks are and whether they could recover if something went wrong.

In my experience, asking the right questions is usually a much better starting point than buying another piece of software.

How Mugnai Digital approaches security

One thing I never want Mugnai Digital to become is a business that claims it can do absolutely everything. We're not a cyber security consultancy, and I think it's important to be honest about that.

That said, whenever I'm building software or designing a website, security is part of the conversation from day one. It's not something that's bolted on at the end or only thought about when there's a problem.

Instead, I naturally find myself asking questions like: Who needs access to this? What happens if somebody leaves the business? How is customer information being stored? What would happen if this service became unavailable? Are we relying on one person's laptop for something important?

Those questions aren't really about cyber security in isolation. They're part of designing software that's reliable, resilient and doesn't leave a business vulnerable if something unexpected happens.

Sometimes the answers are straightforward. Other times it quickly becomes obvious that a cyber security specialist should be involved, and that's absolutely the right thing to do. I'd much rather have that conversation before there's a problem than when everyone is trying to recover from one.

If this article has made you stop and think about your own business, then it's done what I hoped it would. You don't need to solve everything overnight, but spending an hour asking a few sensible questions today could save a lot of stress further down the line.