A phishing email lands in an inbox on a Tuesday afternoon, dressed up as an invoice query from a supplier everyone recognises. Someone in the finance team almost clicks it, catches themselves at the last second, and mentions it to a colleague over coffee. Nothing happens this time. But across London, similar moments play out every week in small businesses that never thought of themselves as a target, right up until the point they were.
This guide sets out the cyber security risks London small businesses face most often, why they get missed, and the practical steps that reduce them without a dedicated security team. It is written for owners and office managers rather than IT specialists, and it looks specifically at cyber security in London for small businesses, where fast growth, hybrid working and tight budgets often collide.
TL;DR
Most cyber security risks facing small businesses in London come from a handful of familiar sources: phishing emails, weak or reused passwords, unpatched devices, and access that nobody has reviewed in a while. None of these need an enterprise-sized budget to fix, but they do need someone paying attention to them regularly. Left unchecked, these gaps are usually what turns a routine phishing attempt into a costly, disruptive incident.
Key takeaways
- Phishing remains the most common way small businesses in London are targeted, so staff awareness matters as much as any technical tool.
- Weak or shared passwords and missing multi-factor authentication, MFA, an extra check when you log in such as a code sent to your phone, make it easier for one mistake to turn into a full account takeover.
- Backups are only useful once they have been tested, not just switched on.
- Reviewing who has access to your systems, especially after someone leaves or a role changes, closes one of the most common and avoidable gaps.
- Hybrid working across London’s cafes and co-working spaces adds risk that is easy to overlook unless devices and connections are properly protected.
Why these risks slip under the radar in growing businesses
Most small businesses in London are not ignoring cyber security on purpose. It grows the way the rest of the business does: quickly, and around whatever is urgent that week. A laptop gets set up in a hurry for a new starter, a shared login gets created because it is faster than doing it properly, and a supplier is granted access because a project needs to move. None of these decisions feel risky at the time, but they stack up into gaps nobody has looked at in months. For a closer look at the internal security gaps many providers overlook, PC-MAC Support has covered common patterns in London SMEs before.
Risks that show up in everyday IT use
These are the risks staff run into simply by doing their jobs, and they are usually the easiest to reduce quickly.
Staff cannot always tell a genuine email from a scam
This looks like a normal email asking for an invoice to be paid, a password to be confirmed, or a link to be opened, often appearing to come from a real supplier, client or even a colleague. Phishing remains the most disruptive and most reported type of cyber-attack among UK businesses, cited by 85% of those that experienced a breach or attack in the past year, according to the government’s Cyber Security Breaches Survey 2025 from the Department for Science, Innovation and Technology, available at https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025. A single click can hand over login details or install malicious software without anyone noticing straight away. Make it simple and normal for staff to report anything suspicious, and review PC-MAC Support’s guide to getting to grips with email security for the settings and habits that reduce how many scam emails reach an inbox in the first place.
The same password turns up in more than one place
This looks like staff reusing a work password for other accounts or writing passwords down because there are too many to remember. If one account is compromised, an attacker often tries the same details elsewhere. The 2025 breaches survey found that only 40% of UK businesses have any requirement for two-factor authentication on their networks or applications, leaving a large majority relying on passwords alone. Encouraging staff towards using a password manager makes strong, unique passwords realistic without adding to everyone’s mental load, and enforcing MFA on top closes most of the remaining gap.
Devices are still running months-old updates
This looks like laptops that prompt for an update and get postponed, repeatedly, because there is never a convenient moment. Software updates often fix known security weaknesses, and the longer a device goes without them, the longer that weakness stays open to anyone who knows how to look for it. According to the same government survey, only 32% of UK businesses have a policy to apply software security updates within 14 days. Setting a simple patching schedule and having someone responsible for chasing up devices that fall behind, closes this gap without needing new hardware or software.
Risks in how the business is protected
These risks are less visible day to day, but they decide how quickly a business recovers when something does go wrong.
Nobody has tested whether backups restore
This looks like backups running quietly in the background, with everyone assuming that means the business is covered. A backup that has never been restored is unproven. It might be missing key folders, only partly capturing cloud data, or not working the way anyone expects. Running a test restore and confirming exactly what is and is not backed up, turns an assumption into something the business can rely on.
It is unclear who still has access to old systems or files
This looks like accounts still active for people who have left, or contractors who finished a project months ago but were never removed from shared folders. Old access is rarely used maliciously by the original person, but it is an easy route in if their login details are ever compromised elsewhere. A short, regular process to review who has access to your systems, and to remove it when it is no longer needed, is one of the simplest ways to reduce risk. PC-MAC Support’s cyber security services are built around keeping this kind of access under control on an ongoing basis, rather than as a one-off check.
Risks tied to growing in a city like London
Fast growth and flexible working bring their own set of risks, particularly common among London’s small businesses.
New starters get access before anyone checks it is needed
This looks like a new employee being given the same broad access as everyone else on day one, simply because it is the quickest way to get them working. It happens especially fast in growing professional services firms, including law firms across London taking on new staff at short notice. Giving someone more access than their role needs increases what is exposed if that account is ever compromised. Setting up access based on role, and reviewing it a few weeks in, keeps this manageable without slowing down onboarding.
Staff connect from co-working spaces and cafes without a second thought
This looks like team members working from shared desks, client sites or coffee shops across the city, connecting to public Wi-Fi without a second thought. Shared networks make it easier for someone else on the same connection to intercept unprotected traffic. Encouraging staff to use a mobile hotspot or a secured connection when working outside the office, with device security controls switched on by default, reduces this risk without changing how or where anyone works.
Cyber security risks at a glance
Use this table to check which of these signs sound familiar in your business, and what a sensible next step looks like for each one.
| Sign | What it could mean | Next step |
| Staff struggle to spot scam emails | Phishing is likely to succeed eventually | Make reporting easy and review email security settings |
| Passwords are reused or shared | One breach can expose several accounts | Introduce a password manager and enforce MFA |
| Devices are behind on updates | Known weaknesses stay open longer than they should | Set and monitor a patching schedule |
| Backups have never been restored | Recovery may not work when it is needed | Run a test restore and document the process |
| Old accounts are still active | Unused access is an easy route in | Review and remove access on a regular schedule |
| New starters get broad access by default | More is exposed if an account is compromised | Base access on role, then review it |
| Staff work from public Wi-Fi regularly | Traffic can be intercepted on shared networks | Use secure connections and keep device controls on |
Is my small business really a target for cyber criminals in London?
Yes, and size is rarely the deciding factor. Small businesses often hold the same kind of valuable information as larger ones, such as customer data, payment details and supplier relationships, while typically having fewer dedicated defences in place. Government research shows that a significant proportion of UK small businesses identify a cyber breach or attack every year, with phishing behind most of these. Criminals frequently target businesses at scale rather than individually, scanning for whichever accounts and devices are easiest to get into, so being small does not mean being overlooked.
What is the quickest way to reduce cyber security risk without a big budget?
Start with multi-factor authentication and a review of who has access to what, since these two steps close the gaps that are most commonly exploited. Both can usually be set up using tools a business already has, such as Microsoft 365, without new licensing costs. From there, a simple patching schedule and a tested backup process cover most of the remaining ground. The exact priorities depend on the number of users and systems involved, which is exactly what a short security review is designed to establish.
Turning these risks into a manageable plan
None of the risks covered here require a large security budget or a dedicated in-house team to reduce. What they do need is someone checking them regularly rather than assuming they are fine, whether that is enforcing MFA properly, testing a backup, or reviewing who still has access to what. Getting the fundamentals right consistently does more to reduce risk than any single tool ever will.
PC-MAC Support works with small businesses across London, and its security reviews look at exactly the areas covered in this guide, from Microsoft 365 identity and access settings through to device patching, backup coverage and email security. If you recognise any of these signs in your own business, book a security review with PC-MAC Support to get a clear, prioritised view of where to focus first.