How Stone businesses can reduce their risk from cyber attacks

Cyber attacks are not something only large companies need to worry about. Small businesses can also find themselves dealing with phishing emails, compromised accounts, fraudulent payment requests and other attempts to gain access to their systems.

Cyber security

For businesses in Stone, that could mean anything from a café or retailer using online ordering and card payments to a trades business managing invoices by email, or an accommodation provider taking bookings online.

The latest UK Government Cyber Security Breaches Survey, published in April 2026, found that 43% of businesses had identified some form of cyber security breach or attack during the previous 12 months.

Among micro businesses, those with fewer than ten employees, the figure was 42%.

Phishing remained the most commonly identified type of attack. It was experienced by 38% of businesses overall and by 88% of businesses that had identified any type of breach or attack.

Where small businesses can be exposed

Most businesses now rely on a mixture of email, websites, online accounts, payment systems and cloud services.

Even a very small business may have customer information, booking details, invoices, supplier records or access to banking and payment services spread across several online accounts.

Each account is another potential route for someone attempting to gain unauthorised access, particularly if passwords are reused or software and website systems are not kept up to date.

Supplier emails can present another risk. A fraudulent message that appears to come from a genuine supplier could ask a business to use different bank details for its next payment.

Personal phones and other devices used for work can also make security harder to manage if there is no agreed approach to passwords, updates and access to business accounts.

Phishing remains a common threat

Phishing attempts are designed to persuade somebody to open a link, reveal information, make a payment or sign into a fake website.

They can imitate messages from suppliers, delivery companies, banks, technology providers or colleagues.

Poor spelling and obviously suspicious messages still exist, but they should not be relied upon as the main warning signs. A convincing phishing email can look much like an ordinary message arriving during a busy working day.

Having a simple process for staff to report suspicious messages can therefore be as important as the technical measures being used.

Small firms may have limited IT resources

A small business will not necessarily have a dedicated member of staff responsible for its technology or cyber security.

The latest government survey found that just 3% of micro businesses had somebody specifically in an IT role looking after cyber security. Some businesses instead relied on owners, managers or outside providers.

That makes it particularly useful to know in advance who should be contacted if an account is compromised or something unusual happens.

Businesses should also know which systems are most important to their day to day operation and who has access to them.

Simple steps that can reduce the risk

Improving cyber security does not necessarily require a large IT budget.

The National Cyber Security Centre provides guidance for small organisations, covering accounts, devices, backups and recognising scams.

Article continues after this message
Oktoberfest Stone 2026 Poster

Use multi factor authentication

Multi factor authentication adds an additional check when somebody signs into an account.

That means possession of a password alone may not be enough for somebody to gain access.

Businesses should particularly consider protecting email, banking, social media, cloud storage, website administration and other important accounts where the service supports it.

Check changes to payment details

Businesses can introduce a straightforward verification process for requests to change supplier bank details.

Instead of relying solely on the email containing the request, contact the supplier using contact details that are already known to be genuine.

That additional check can help protect against payment diversion fraud.

Make sure staff know what to report

Cyber security does not have to involve lengthy training sessions.

Staff should know what suspicious messages can look like, what they should avoid doing and who they should contact if they think they have clicked something they should not have.

Reporting a mistake quickly is more useful than leaving somebody unsure about what to do next.

Keep systems and accounts under control

Software, websites and plugins should be kept up to date.

Old user accounts that are no longer needed should be removed, and passwords should not be reused across different services.

Businesses should also keep backups of important data and regularly check that those backups can actually be restored.

When independent testing may be useful

The level of cyber security a business needs will depend on what it does, the systems it relies upon and the information it holds.

A sole trader with a handful of online accounts will have different requirements from an organisation handling large amounts of customer information or operating more complex systems.

For businesses requiring independent assessment of their systems, CREST penetration testing is one form of accredited security testing designed to identify vulnerabilities before they are exploited.

Formal testing will not be necessary for every small business, but organisations holding sensitive information or relying heavily on their digital systems may decide that independent assurance is appropriate.

Have a plan for when something goes wrong

Businesses should consider what they would actually do if an important account or computer was compromised.

That includes knowing who to contact, how to disconnect an affected device, where backups are kept and which passwords or accounts may need to be changed.

More than one person should know where this information is kept.

For many smaller businesses, the most useful improvements are relatively straightforward. Securing important accounts, checking unusual payment requests, keeping software updated, backing up essential information and making sure staff know what to do when something looks suspicious can all reduce the risk.

James Du Pavey - Stone

Leave the first comment

Stone Small Businesses