So what are the most common ways that businesses get hacked?
I’ll save you the suspense.
It’s email.
Not some sophisticated hacking operation. Not someone in a hoodie breaking through your firewall at 3am. Not a zero-day exploit that even the security vendors haven’t figured out yet.
It’s an email. Sent to someone in your business. That looks just real enough for them to click on it.
That’s how 93% of all cyber crime against UK businesses starts.
The numbers are staggering
The UK Government’s Cyber Security Breaches Survey for 2025/2026 lays it out in black and white:
38% of all UK businesses experienced a phishing attack in the last 12 months
69% of businesses that suffered any kind of breach rated phishing as their most disruptive incident
51% of breached businesses experienced phishing as the only type of attack. Nothing else. Just email.
93% of businesses that experienced a cyber crime said phishing was involved
Read that last one again. Ninety-three percent.
If your business gets hit by cyber crime this year, there’s a 93% chance it starts with a phishing email. Not malware. Not ransomware. Not a brute-force attack on your passwords. An email.
And the qualitative research from the same survey? Respondents said phishing attacks are getting easier for criminals to commit and harder for staff to spot. AI is making it worse. The days of dodgy spelling and Nigerian prince stories are long gone. Modern phishing emails are polished, personalised, and devastatingly effective.
Why email is such a massive vulnerability
Think about what email is in a modern business.
It’s how you communicate with customers. It’s how invoices get sent and paid. It’s how contracts get signed. It’s how your bank talks to you. It’s how new suppliers introduce themselves. It’s how your staff reset passwords and access internal systems.
Email is the front door to everything. And in most small businesses, that front door has a flimsy lock.
Here’s what a typical phishing attack looks like in practice:
Someone in your accounts team gets an email that looks like it’s from a supplier. The branding is right. The email address looks close enough. It says there’s been a change to their bank details and could you update your records before the next payment.
Your accounts person, who’s busy, who’s processing 30 invoices that week, updates the details and sends the next payment. Except the email wasn’t from the supplier. The money goes to a criminal’s account. It’s gone.
Or someone in your team gets an email that looks like it’s from Microsoft. Their password is expiring. They need to click a link to update it. They click, enter their credentials, and now the attacker has their username and password. From there, they’re inside your email, your files, your customer data. They can send emails as your employee. They can intercept invoices. They can deploy ransomware.
This isn’t hypothetical. This is happening to UK businesses every single day. Over 10.9 million suspicious emails were reported to the NCSC’s reporting service in the last year alone. That’s 30,000 a day.
Why most businesses are still wide open
Because most businesses rely on one thing: their people. And people make mistakes.
I don’t say that to blame anyone. Your staff are busy doing their actual jobs. They’re not security analysts. They’re not trained to spot the difference between a real Microsoft email and a fake one that’s been crafted using AI to look identical.
The traditional approach to phishing is “train your staff to spot it.” And that’s important, it genuinely is. But if training is your only line of defence, you’re relying on every single person in your business, every single time, to make the right call on every single email they receive.
That’s not realistic. It never has been.
Only 18% of UK businesses run simulated phishing exercises with their staff.** The rest are hoping for the best. And even with training, people still click. Because the emails are getting better, and people are human.
The one thing that actually works
If I could only do one thing to protect a business, and I genuinely had to pick just one, it would be this:
Proper email security.
Not the basic spam filter that comes with Microsoft 365 or Google Workspace. That catches the obvious stuff, the classified ads and the clearly fraudulent nonsense. It doesn’t catch the sophisticated, targeted phishing emails that are designed to get past it.
Proper email security means a dedicated layer that sits in front of your inbox and analyses every incoming email for:
Impersonation attempts. Is someone pretending to be your CEO, your bank, your supplier? Even if the email address looks right, is the sending infrastructure legitimate?
Malicious links. Not just known bad URLs, but links that redirect, that use URL shorteners, that lead to convincing fake login pages.
Dangerous attachments. Files that contain macros, scripts, or embedded malware. Not just .exe files, but weaponised PDFs, Word documents, and spreadsheets.
SPF, DKIM, and DMARC validation. These three records verify that an email actually came from who it claims to be from. Without them configured on your domain, criminals can send emails that look like they’re from your business. With them enforced, those fakes get blocked.
This is the layer that catches the 80% of attacks your staff training will miss.
But email security alone isn’t enough
I’d be lying if I said it was. Proper protection is layered. Email security is the most important layer because it’s where the attacks start, but you need the others too:
Multi-factor authentication (MFA) on everything. If a phishing email does steal someone’s password, MFA means the attacker still can’t log in without further work. This single control neutralises the consequence of a stolen credential. It should be on every cloud service, every email account, every remote access point.
Endpoint detection and response (EDR). If something does get through to a device, EDR watches what’s happening in real time and responds automatically. It’s not antivirus. It’s a step beyond, watching for behaviours that indicate an attack, not just scanning for known files.
Security awareness training with simulated phishing. Yes, I just said you can’t rely on people alone. But trained people plus proper technology is far stronger than either one on its own. Regular simulated phishing exercises keep it front of mind and show you who’s most vulnerable so you can target your training.
DMARC, SPF, and DKIM on your own domain. This protects your customers and suppliers from receiving fake emails that look like they’re from you. If your domain doesn’t have these records properly configured, anyone can impersonate your business via email. You can check your score for free and can read our previous post about this here
What this costs
Because I know that’s what you’re thinking.
For a business with 10 to 25 employees, a proper email security and endpoint protection, our MXDR and email security bundle starts from £15 per user per month**.
For a 15-person business, that’s roughly £225 a month for managed, monitored, layered protection against the attack that accounts for 93% of all cyber crime against UK businesses.
Compare that to the cost of a successful phishing attack. A single redirected payment. A single data breach. A single ransomware incident. You’re looking at thousands, tens of thousands, potentially hundreds of thousands of pounds in damage.
£225 a month isn’t a Cyber Security budget. It’s common sense.
What to do right now
Three things. Today. This afternoon.
1. Check your email domain security. Go to [tools.sendmarc.com](https://tools.sendmarc.com) and enter your domain. If your score is below 40, your email can be spoofed. That’s your first problem.
2. Ask your IT provider what email security you have. Not “do we have spam filtering?” but specifically: “What’s protecting us against targeted phishing, impersonation, and credential theft?” If they can’t give you a clear answer, you have your second problem.
3. Get a Cyber Security review from us. We’ll check your email security, your endpoint protection, your DMARC configuration, and your overall exposure. Takes about 30 minutes. Costs £50 but we refund this if you take up our services. No jargon, no obligation, just a clear picture of where you stand.
Because the most common cyber attack in the UK isn’t clever. It isn’t sophisticated. It’s an email that somebody clicks on and it’s entirely preventable.
Get in touch today or call 0300 124 5005

