79% of SMBs are confident in their ability to identify a cyber attack, yet just over half (56%) are adopting cyber security tools well.
Babble has released further findings from its Technology Performance Index showing that too many UK SMBs could be overconfident in their business’s ability to identify, respond to, and recover from a cyber attack. With UK Government research finding over half had suffered a breach in the last year, SMB leaders are being warned to exercise more caution.
Babble’s Technology Performance Index surveyed 1,000 UK SMBs and assessed how confident leadership teams are when it comes to adopting technology. This identified three distinct groups; Tech Vanguards, businesses successfully embedding technology to drive growth and productivity; Emerging Adopters, organisations making progress but facing barriers to implementation; and Tech Bystanders, firms struggling to adopt new technologies and at risk of falling behind.
The survey found 79% of SMB leaders are confident in their ability to identify a cyber attack and 28% believe they could recover from a cyber attack within a week. This figure increases to 73% of businesses in the Tech Vanguard. Yet just over half (55%) have effectively adopted cyber security tools and integrated them across their entire business.
The NCSC states it can take several weeks to recover from a ransomware or malware attack even when an organisation is well prepared, suggesting this confidence could be misplaced. That concern is compounded by the fact that just 41% of SMBs report adopting business continuity and disaster recovery technology – an essential part in getting back up and running after an attack occurs.
A growing attack surface
Against this backdrop, AI has created an additional cyber security paradox. For cybercriminals, it is making attacks easier to create, harder to spot and possible to launch at far greater scale. The result for SMBs is not simply another potential point of attack, but a threat environment that is moving faster than traditional, largely manual approaches to cyber security can keep up with.
However, that same technology can also strengthen the defence. AI and automation can help businesses analyse activity across their systems, identify unusual behaviour and respond to potential threats at a speed and scale that would be difficult to achieve through people alone.
As attackers increasingly use AI, businesses need to engage with it too. Yet almost half (48%) are not currently using AI-enabled tools to improve their cyber security, leaving many on the wrong side of this escalating AI arms race.
The problem is further compounded by SMBs falling into the trap of believing that buying a cyber security solution automatically means they are protected. Fewer than half (45%) look for someone to actively manage, detect and respond to threats, while just 31% include employee education among their requirements. Additionally, only 28% call for proactive threat intelligence.
Mark Braund, Executive Chair of Babble commented, “The biggest cyber risk facing many SMBs today is a false sense of security. Our research suggests that many organisations believe they are more resilient than they actually are.
The consequences of getting it wrong can be severe. A cyber-attack can disrupt operations for months, causing significant financial and reputational damage. In the most serious cases, we have seen businesses pushed into administration or forced to cease trading altogether.
Cyber security is not a one-time investment or something that can simply be delegated and forgotten. It requires clear ownership, continuous oversight, and regular testing as threats continue to evolve. The organisations that manage cyber risk most effectively are not necessarily those with the most technology, but those that recognise cyber security for what it is: a board-level business risk requiring the same governance, accountability and oversight as any other threat to the future of the organisation."
Find out more about the Technology Performance Index.