TL;DR:
- The NCSC issued a July 2026 warning that hostile state actors are deliberately targeting UK SMEs to gain access to the larger organisations in their supply chains
- 43% of UK businesses experienced a cyber breach in the past year; ransomware incidents doubled in 2025; SMEs are disproportionately targeted because they have valuable supply chain access but weaker defences
- Cyber Essentials certification provides the baseline controls that make SMEs significantly harder targets — and many of the gaps are fixable without a large security budget
Small businesses often assume nation-state hackers aren’t interested in them. That assumption is wrong, and the NCSC’s July 2026 advisory is unambiguous about why.
Hostile state actors — attributed primarily to Russia, China, North Korea, and Iran in NCSC reporting — are systematically working their way into UK supply chains by compromising the smaller suppliers and contractors that serve as trusted third parties to larger targets. The attack doesn’t need to touch the Ministry of Defence or a FTSE 100 company directly. It finds the 12-person engineering consultancy that has VPN access to the defence prime’s network, or the accounting firm that processes invoices for a critical infrastructure operator.
If your business supplies services, software, or physical goods to a larger organisation, you have supply chain value. That makes you a target.
The Current Threat Landscape
The numbers from 2025 and early 2026 are stark. Ransomware incidents affecting UK businesses doubled over the 2024 baseline, with SMEs comprising the majority of victims by count (though enterprise incidents attract more coverage). The Cyber Security Breaches Survey 2026 found 43% of UK businesses experienced a cybersecurity breach or attack in the past twelve months — a figure that has been stubbornly resistant to improvement despite years of awareness campaigns.
For SMEs specifically, the most common attack vectors remain:
Phishing and spear phishing. Emails crafted to impersonate known contacts, suppliers, or authority figures (HMRC, Companies House, a client’s IT department) that direct recipients to credential-harvesting pages or deliver malware. Nation-state actors invest more heavily in personalised spear phishing than opportunistic criminal groups — your business’s LinkedIn presence, website, and public contracts can all inform a targeted attack.
Credential stuffing and password reuse. Credentials from historical data breaches are routinely tested against business email, VPN, and cloud service accounts. If your employees reuse passwords across personal and work accounts, and those credentials appeared in any of the major consumer data breaches, your accounts are being tested right now.
Vulnerable remote access. VPNs and remote desktop services with unpatched vulnerabilities, default credentials, or no multi-factor authentication are a primary entry point for both criminal ransomware operators and state-aligned actors. The number of internet-facing UK business systems with known, unpatched vulnerabilities is consistently high in NCSC’s scanning data.
Software supply chain compromise. For businesses in the technology or software sector: your development dependencies, build pipelines, and software distribution channels are targets. The SolarWinds and 3CX incidents showed how a single compromised supplier could propagate malware across thousands of customers.
What “Supply Chain Entry Point” Actually Means
The mechanism of supply chain attacks is worth understanding clearly, because it shapes which controls matter most.
When an attacker compromises an SME to use as a stepping stone, they’re typically after one of three things:
Trusted access. Your business has a VPN connection, a managed service agreement, or remote support capability into a larger client’s network. Once the attacker is inside your systems, they can use your legitimate access to enter the client’s environment — bypassing the client’s perimeter controls entirely because the connection comes from a trusted supplier.
Lateral movement and persistence. The attacker establishes a foothold in your systems and waits, collecting credentials and mapping your client relationships, before using your position to launch further attacks. The dwell time on these intrusions is often measured in months.
Impersonation and BEC. Access to your email system enables the attacker to impersonate your business in communications with your clients — requesting payment changes, sending malicious attachments from a trusted sender, or setting up man-in-the-middle positions in ongoing contract negotiations.
The NCSC’s Baseline: Cyber Essentials
The NCSC’s July 2026 advisory reiterates its long-standing position: Cyber Essentials certification addresses the controls that would prevent the majority of common attack vectors. The five control areas are:
- Firewalls — ensuring internet-facing services are appropriately restricted and only necessary ports are open
- Secure configuration — removing default credentials, unnecessary software, and services that expand attack surface
- User access control — applying least privilege, removing unused accounts, and controlling administrator access
- Malware protection — endpoint protection and controls on code execution
- Patch management — applying security updates to operating systems and software within 14 days of release (or within 2-3 days for critical patches)
Cyber Essentials costs between £300 and £500 for the basic self-assessment certification. Cyber Essentials Plus — which adds independent technical verification — runs higher, but many government and defence supply chain contracts now require it.
The NCSC’s data consistently shows that organisations with Cyber Essentials certification are significantly less likely to suffer common cyber attacks. This isn’t because the certification is perfect — it’s because a large proportion of attacks exploit exactly the gaps it addresses.
What to Prioritise if You’re Starting From Zero
If your business hasn’t done a formal security review, the highest-impact changes are:
Multi-factor authentication everywhere. Email, cloud services, VPN, remote access — every account that could be used to access your systems or your clients’ systems needs MFA. This alone stops the majority of credential-based attacks.
Patch your internet-facing systems first. Routers, firewalls, VPN appliances, and email gateways are the most common targets. If you’re more than one month behind on patches for any internet-facing system, that’s an urgent fix.
Review third-party access to your systems. Know which suppliers, contractors, and managed service providers have access to your network and on what terms. Revoke any access that isn’t actively needed. Ensure access that remains is MFA-protected.
Train staff on spear phishing. The sophistication of AI-assisted spear phishing has risen sharply. Generic “don’t click links” training is insufficient. Specific, scenario-based training — here’s what a convincing spear phishing email looks like, here’s what to do if you’re unsure — is demonstrably more effective.
The NCSC’s report is a warning, but it’s also a clear statement of what’s preventable. The businesses that are compromised as supply chain entry points are, in most cases, businesses where basic controls were absent. The baseline isn’t hard to achieve — it just has to actually be done.