Cyber Security · 1 October 2026 · 5 min read

Six Cyber Security myths that leave small to medium businesses exposed

October is Cyber Security Awareness Month, so let's have an honest chat about cyber security for small businesses.

Get insights
Cyber security myths written on a blue background

Here's the thing: what catches most businesses out isn't clever hacking straight out of a film. It's a handful of myths that quietly leave the door open. These are the six we hear most often, and what's really going on behind each one.

Why this matters for small businesses

Let's start by knocking down the biggest myth of the lot, that this is a big business problem. It really isn't. The UK Government's Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses had a breach or attack in the past year. That's roughly 612,000 businesses. at an estimated cost of £10,000-£25,000 per business.

This year's Cyber Security Awareness Month theme, "Don't make it easy for them", sums it up nicely. Most attacks don't work because the criminal is a genius. They work because someone left the door open.

And when it goes wrong for a smaller business, it usually stings more. You've got less room to absorb the downtime, the lost data or the knock to your reputation. So these myths are worth two minutes of your time.

Myth 1: We are too small to be a target

The reality: Attackers aren’t sitting there hand-picking their victims. Most attacks are automated. They scan the internet for weak spots and go after whoever’s exposed, and size barely comes into it. The 2025/26 survey found 46% of small businesses and 42% of microbusinesses had a breach or attack. 

If anything, smaller firms report slightly lower numbers, not because fewer happen; you simply don't notice. Being small doesn’t make you invisible. Quite often, it just makes you an easier target.

Myth 2: Antivirus is all we need

The reality: Antivirus is worth having, but on its own, it’s a bit like locking the front door and leaving the windows wide open. Most attacks these days go after your people, not your software. Convincing emails and scams often walk straight past traditional antivirus.

What actually protects you is a few layers working together. Multi-factor authentication, regular updates, email filtering, and advanced tools like EDR (your digital bouncer) protect your systems whilst you sleep, and importantly, a team that knows what to look for. 

Myth 3: Cybersecurity is the IT person’s job

The reality: Most breaches start with a person. A clicked link, a reused password, an email that looked legit. That’s usually all it takes. Which means everyone in the business is part of the defence, whether they realise it or not. 

That’s really what Awareness Month is all about. And honestly, the most effective upgrade most businesses can make is a team that recognises a scam and isn’t afraid to flag it.

Myth 4: Proper cybersecurity is too expensive for us

The reality: This one’s more understandable, but it still doesn’t hold up. The things that make the biggest difference cost little or nothing: enabling multifactor authentication, keeping software up to date, using a password manager, and training your team. 

Cyber Essentials, the scheme backed by the UK Government, is an affordable way to cover the basics, and more small businesses are getting on board, up from 5% to 12% in the latest survey. Set that against a week of downtime, and it’s not a close call.

Myth 5: We’d know straight away if we’d been breached

The reality: Often, you wouldn’t. Plenty of breaches sit undetected for weeks. Without something keeping watch, the first you hear of it is the damage: a payment that shouldn’t have gone out, files you can’t open, or a customer asking why you’ve sent them something strange.

Spotting it quickly matters just as much as stopping it. A lot of small businesses still have no plan for when something goes wrong, and that’s what turns a bad day into a full-blown crisis.

Myth 6: The cloud provider handles our security

The reality: Microsoft and Google keep their own systems secure, but the rest is on you: how it’s set up, who has access, whether multi-factor authentication is switched on, how accounts are managed and how the platform itself is configured. "Out of the box" configurations include very basic security; do not assume that once you are cloud-based, your security is strong.

Most cloud problems stem from a hacked account or a misconfigured setting, not from the platform itself failing. Moving to the cloud doesn't hand the responsibility over with it. 

So what should you actually do?

Here's the encouraging bit: none of the fixes is out of reach. If you only do a few things this month, make it these:

  • Turn on multi-factor authentication everywhere you can, every application that requires a login, starting with email and cloud accounts.
  • Keep everything updated, because that's how most gaps get quietly closed.
  • Help your team spot phishing, and make flagging it easy.
  • Back up your data, check that you can actually restore it and that you have a copy of the backup; business continuity cannot be ignored.
  • Work towards Cyber Essentials for a solid, recognised baseline. Know you are protected, don't just think you are.

None of that needs a big budget. What it needs is a bit of consistency, and ideally someone to keep it ticking over all year, not just in October.

The bottom line

Cybersecurity for small businesses usually isn't about fancy kit. It's about ditching the myths that leave the door open, then building a few simple habits that keep it shut. That's exactly what "Don't make it easy for them" comes down to.

If your business wants to get on top of its cybersecurity, we can help. We’re offering a no-obligation, free security assessment to show you exactly where you stand against today’s threats. Get in touch with the team today.

FAQs

Frequently asked questions.

Are small businesses really targeted by cyber criminals?

Yes. The UK Government's Cyber Security Breaches Survey 2025/2026 found 46% of small businesses had a breach or attack in the past year. Most attacks are automated and go after whoever's exposed, whatever their size.

What’s the most common type of cyber attack on small businesses?

Phishing, by a mile. These are emails or messages designed to trick your staff into handing over passwords, making payments or clicking something harmful. Training and multi-factor authentication are your best defences.

What is Cyber Essentials?

Cyber Essentials is a certification scheme backed by the UK Government that helps you get the core security controls in place. It's an affordable, recognised way for a small business to cover the fundamentals and show customers you take it seriously. As an IASME Certification Body and NCSC Cyber Advisor, we prepare and certify you, guiding you to a first-time pass.

How much does good cyber security actually cost?

Less than most people think. Many of the most effective steps, like multi-factor authentication, updates, and staff training, are free or nearly free. The cost of a breach, in downtime and lost trust, is usually far higher than the cost of avoiding one.

How can PrimaryTech help protect our business?

We provide managed cybersecurity for small businesses, from the fundamentals through to monitoring and Cyber Essentials support. You can see how we help on our cybersecurity services page.

Want advice specific to your organisation?

Articles are useful, but nothing beats a conversation about your actual setup. Start with a free health check.

Get Your Free IT Health Check