My business is too small to be targeted by hackers
A small business owner looks at a modest office and sees a local operation. The staff is few, the turnover is steady, and the profile is low. To this person, the idea of a sophisticated cyber attack seems absurd. Why would a criminal spend time and effort trying to break into a firm that sells industrial valves or manages a small fleet of taxis? There is a sense that the business is simply too insignificant to be noticed on a global map of targets.
The human element#
This belief is not unfounded. For many years, hacking was a manual process. It required a person to sit at a keyboard and make a conscious decision about who to target. In that era, attackers behaved like traditional thieves. They looked for the biggest prize with the lowest risk. A bank or a government department offered far more reward than a local accounting firm. The logic was simple: an attacker has limited time and energy. It makes sense to spend those resources on a high-value target rather than wasting them on a small business. In this context, being small was a genuine form of defence.
The digital dragnet#
The world changed when the human element was replaced by automation. Most modern attacks are not targeted strikes. Instead, they are automated sweeps. A sweep is a piece of software that scans millions of internet addresses in search of a specific vulnerability. A vulnerability is a flaw or a hole in a piece of software that allows an attacker to get inside.
The bot performing the scan does not know who owns the server it has found. It does not care about the size of the organisation, its location, or whether it sells valves or cupcakes. The bot simply looks for a specific open door. If the door is open, the bot enters and installs malware. Malware is malicious software designed to steal data or lock files for ransom. To an automated script, every single device connected to the internet is a potential target. Size is irrelevant because the cost of the attack has dropped to almost zero.
The side door#
Even when attacks are targeted, small organisations remain at risk. This happens through the supply chain. A supply chain is the network of partners and suppliers that a large company relies on to function. Large corporations often have formidable defences. Their digital walls are high and well-guarded. However, those corporations still need to work with smaller firms for maintenance, logistics, or specialised consulting.
An attacker who cannot get through the front gate of a global bank may instead look for a way in through the bank’s small payroll provider or its office cleaning contractor. If the smaller partner has weak security and a trusted connection to the larger firm, it becomes a perfect bridge. The small organisation is not the final prize, but it is the path to the prize. The attacker uses the smaller firm as a stepping stone to reach the larger target. In this scenario, being small does not offer protection; it makes a business an attractive point of entry.
The result of believing in the safety of insignificance is often a lack of basic maintenance. Software remains unpatched and passwords remain simple. This creates a paradox where the firms that feel safest are often the easiest to compromise.
To reduce this risk, keep all software updated immediately when patches become available. Use a password manager to ensure every account has a unique, complex key. Enable multi-factor authentication on every possible service, which requires a second confirmation from a mobile device before granting access. These steps stop the majority of automated sweeps and remove the easiest paths for supply chain attackers.
Frequently asked questions#
Do hackers target small businesses?
Modern cyber attacks often use automated software to scan the internet for vulnerabilities regardless of a company's size. These bots do not distinguish between a global corporation and a local shop; they simply look for open doors to install malware. This means any device connected to the web is a potential target for criminals.
What is a supply chain attack?
A supply chain attack occurs when a criminal targets a smaller partner or supplier to gain access to a larger organisation. Because big corporations have strong defences, attackers find it easier to enter through a less secure side door provided by a trusted third party, such as a payroll provider or consultant.