AI raises stakes for UK SME security
ESET's 2026 SMB Cyber Risk Report finds 49% of UK small businesses hit by incidents, with AI-powered attacks adding pressure despite core tactics staying the same.
Nearly half of UK small and medium-sized businesses have weathered a cyber incident in the past year, according to new survey data from security vendor ESET. The findings land as AI-assisted attack tooling enters the mainstream, prompting warnings that businesses already stretched thin on security basics could find themselves further exposed.
The 2026 SMB Cyber Risk Report, based on responses from 500 UK SMBs, paints a picture of a sector taking repeated hits while struggling to keep pace with the threats arrayed against it. The report also captures a widely shared expectation among respondents that conditions will worsen as criminals fold AI tools into their operations.
Nearly half report an incident
The headline figure from the ESET survey is stark: 49% of UK SMBs reported experiencing a cyber incident over the previous year. Within that group, roughly one in eight did not escape with a single event — 13% said they had endured more than one incident across the same period.
Those numbers describe a slice of the UK economy that carries outsized weight. SMBs account for more than half of turnover in the UK private sector, a sum the report puts at around £2.8 trillion. That combination of economic significance and constrained defensive resources is part of why smaller firms have long been viewed as attractive targets.
The survey did not simply count incidents. It also asked respondents to name their foremost security worry, and one answer rose to the top: AI-powered malware.
Familiar failures, new tools
Even with AI anxiety running high, the report's breakdown of how attacks actually succeeded reads like a roll-call of long-standing weaknesses. The most common causes identified were phishing, unpatched vulnerabilities, weak passwords, and a lack of monitoring.
None of those categories is novel. What is changing, according to the report's framing, is the speed and scale at which attackers can now operate — and the difficulty smaller organisations face in responding. The findings point to a widening gap between the threats SMBs confront and the internal capacity they have to meet them.
Respondents flagged several operational obstacles beyond the attacks themselves. Among them: difficulty keeping up with the latest cybersecurity threats, the challenge of matching the pace of new technologies such as AI, the demands of vulnerability and patch management, and a shortage of skills within the workforce.
That last item — skills — runs through much of the report's account of why basics slip. Security has to compete for attention against every other demand on a small business, and in some organisations it loses that contest.
Where the budget is heading
The report is not uniformly bleak. More than half of the SMBs surveyed — 55% — said they expect to increase their cybersecurity budgets over the next 12 months.
Where that money goes is telling. The top investment priorities named by respondents were employee training and awareness, alongside cloud security. Both choices suggest businesses are looking at the human and infrastructure sides of the problem rather than chasing a single technical fix.
Training and awareness map directly onto the attack methods the report identifies as most common — phishing foremost among them. Cloud security spending, meanwhile, reflects where a growing share of SMB operations now live.
Whether budget increases translate into fewer incidents is a separate question, and one the survey does not answer. What it does show is intent: a majority of respondents recognise the need to spend more, even as they describe struggling to keep pace.
The AI claim, in context
The report's central tension is that AI is simultaneously the top concern and, in the assessment of at least one ESET advisor, not a wholesale replacement for the tactics that have always worked.
“It’s true that AI will help cybercriminals to speed up their attacks against UK businesses. But the core tactics used like phishing or exploiting software vulnerabilities will largely stay the same,” explains Jake Moore, Global Cybersecurity Advisor at ESET.
— Jake Moore, Global Cybersecurity Advisor at ESET
Moore's assessment continues with a blunt diagnosis of why smaller firms remain vulnerable despite awareness of the threat:
“Until organisations can improve their security by locking down the basics, smaller businesses will be easy pickings for cybercriminals looking to steal sensitive data and turn a profit.”
— Jake Moore, Global Cybersecurity Advisor at ESET
Read together, those two statements frame the report's practical message: the tools are evolving, but the entry points are not. Phishing messages, unpatched software, weak credentials, and unmonitored systems remain the doors attackers walk through — and AI makes walking through them faster.
What the numbers add up to
The survey's key figures, as reported:
- 49% of UK SMBs surveyed had experienced a cyber incident in the past year
- 13% of those had experienced more than one incident in that period
- 500 UK SMBs took part in the survey
- £2.8 trillion — the approximate turnover SMBs represent in the UK private sector
- 55% of respondents expect to increase cybersecurity budgets over the next 12 months
The most common causes of attack cited were phishing, unpatched vulnerabilities, weak passwords, and a lack of monitoring. The top security concern named by respondents was AI-powered malware. Top investment priorities were employee training and awareness, and cloud security.
The basics problem
There is a quiet logic to the report's findings. The failures it describes are not exotic. They are the same categories that security advisories have flagged for years, which is precisely why Moore's point about "locking down the basics" carries weight.
For an SMB, that means patch management that actually runs on schedule, credentials that are not reused or guessable, monitoring that would notice something anomalous, and staff who can recognise a phishing attempt. The report indicates these are the areas where respondents feel least equipped — and where the skills gap bites hardest.
The survey also captures a structural mismatch. SMBs must track a threat landscape that shifts continuously, adopt new technologies including AI, manage vulnerabilities and patches, and find workers with the right skills — all while running the business. Any one of those tasks could consume more attention than a small team has to give.
That is the environment in which a 49% incident rate becomes easier to understand. It is not that SMBs are uniquely careless. It is that the volume of demands exceeds the capacity many of them possess.
What businesses should weigh
The ESET findings suggest that for UK SMBs, the practical question is not whether to worry about AI-driven attacks, but where to direct limited resources first.
The report's own data offers a partial answer. If phishing, unpatched vulnerabilities, weak passwords, and absent monitoring are the most common causes of incidents, then improvements in those areas address the incidents that are actually happening. Budget plans that prioritise training and cloud security align with that reading.
For small businesses assessing their position, the survey points to a few concrete areas worth examining: whether patches are applied promptly, whether passwords are strong and unique, whether systems are monitored closely enough to detect an intrusion, and whether employees would recognise a phishing message. Each of these maps to a cause the report identifies.
The AI dimension is real but, on ESET's account, secondary to those fundamentals. AI may accelerate attacks and lower the effort required to launch them, but it does not change what a successful attack looks like at the point of entry. A speeded-up phishing campaign still relies on someone clicking.
That framing matters for how SMBs allocate the budget increases many of them are planning. Spending on tools that do not address the underlying weaknesses would leave the same doors open. Spending that hardens the basics addresses the failure modes the report documents.
The wider picture for UK SMBs
The stakes extend beyond individual firms. With SMBs representing around £2.8 trillion in UK private-sector turnover, a persistent incident rate across the segment has consequences for supply chains, customers, and the broader economy.
The report's findings could also shape how the security industry talks to smaller customers. If 49% have experienced an incident and many name AI-powered malware as their chief fear, vendors and advisors may need to address that fear without letting it crowd out the less glamorous work of patching, monitoring, and training.
Moore's advice effectively makes that case. The core tactics will largely stay the same, he said, and until organisations improve security by locking down the basics, smaller businesses will remain easy pickings for criminals seeking sensitive data and profit.
For UK SMBs reading the survey, the takeaway is likely to be about sequencing: address the fundamentals that attackers still exploit, then layer on the protections needed as attack tooling grows more capable. The 55% planning to raise budgets have an opportunity to do both — provided the spending targets the weaknesses the report actually identifies.
Sources
- TechRadar Original source
Continue Reading
Chrome 154 Fixes 108 Flaws, 11 Critical
Google's latest stable release patches a wide swath of memory-safety bugs, but most bug bounty payouts remain undecided.
EU's Cyber Info-Sharing Falls Short
EU auditors say weak information exchange between national and bloc-level bodies is undermining detection and response to large-scale cyber incidents.
F5 zero-day hits BIG-IP APM deployments
F5 patched a critical BIG-IP APM zero-day exploited in remote code execution attacks, as CISA ordered federal agencies to secure networks by Friday.