Ross Asquith at Halcyon explains why ’We’re too small to be targeted’ is the most dangerous myth in cyber-security

When ransomware dominates the headlines, it’s usually because a household name has fallen victim. Major retailers, healthcare providers and critical infrastructure attract attention because the disruptions are visible and the financial impact is significant.
But focusing only on high-profile attacks creates a dangerous misconception for thousands of small and medium-sized businesses (SMEs): that cyber-criminals simply aren’t interested in them.
In reality, the opposite is becoming increasingly true. Many SMEs assume they are too small to be worth attacking. Limited budgets are understandably directed towards keeping the business running rather than investing in cyber-security. If ransomware is perceived as a problem reserved for multinational organisations, it is easy to see why security spending slips down the priority list.
However, the rise of AI and automation is fundamentally changing the economics of cyber-crime. Attackers no longer need to invest significant time targeting one large organisation. Instead, they can automate large parts of the attack process, casting a far wider net and compromising many smaller organisations simultaneously.
Rather than chasing one multimillion-pound payday, attackers can collect hundreds of smaller ransoms with far less effort. This shift makes SMEs increasingly attractive targets.
Unlike large enterprises, smaller organisations rarely have dedicated security operations teams or multiple layers of protection monitoring their environments around the clock. Many rely on a single security product and hope it will stop every threat.
The reality is that no single control catches everything. Cyber-resilience has always been about layers. If one defence fails, another should be there to detect, contain or recover from the attack before it becomes a business-ending incident. Larger organisations have spent years building those layers. Many SMEs simply haven’t had the resources to do the same.
The challenge is made worse by the fact that many smaller businesses still struggle with the cyber-security basics. Weak password policies, delayed patching, limited visibility across devices and stretched IT teams all increase the likelihood of an attacker gaining an initial foothold.
Ransomware is often the final stage of an attack, not the beginning. Once criminals gain access, encrypting systems remains one of the quickest and most profitable ways to monetise that access.
Another misconception is that the ransom itself represents the highest cost. In practice, it is often only a fraction of the overall damage.
Business interruption can leave staff unable to work for days or weeks. Systems need rebuilding. External specialists are brought in. Employees work overtime to restore operations. Customers lose confidence. New security investments become unavoidable after the incident. Even if an organisation chooses not to pay a ransom, the financial impact can still be severe.
For many SMEs, those costs are far harder to absorb than they would be for a large enterprise. Perhaps the biggest problem is that we rarely hear these stories. When a global company suffers a ransomware attack, it becomes national news. When a local manufacturer, engineering firm, charity or professional services business experiences the same thing, it often goes unnoticed outside its immediate community. Some recover quietly. Others never fully recover at all. That lack of visibility reinforces the false belief that these attacks are uncommon.
Governments are beginning to recognise the issue through new cyber-resilience initiatives and stronger reporting requirements. While additional regulation may initially seem like another burden for smaller organisations, better reporting ultimately benefits everyone. It helps authorities understand how attacks are evolving, provides better guidance for businesses and strengthens the collective response to ransomware.
Ultimately, ransomware resilience isn’t about assuming you will be targeted tomorrow. It’s about recognising that today’s attackers don’t discriminate in the way they once did. The question is no longer whether your business is large enough to attract attention. The question is whether your organisation is easier to compromise than the one next door.
For many SMEs, changing that mindset may be the single most important step they take towards becoming more resilient.
Ross Asquith is Solutions Engineering Director, Europe at Halcyon
Main image courtesy of iStockPhoto.com and da-kuk


© 2025, Lyonsdown Limited. Business Reporter® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543