By Uditha Atukorala
AI has slashed the cost and skill needed to launch cyberattacks, turning small and mid-sized European businesses into cybercriminals’ most attractive targets.
When Marks & Spencer’s 2025 breach traced back to a supplier’s compromised credentials, many small business owners concluded they were too insignificant to be targeted. That assumption is wrong, and increasingly dangerous. Artificial intelligence has slashed the cost and skill required to launch attacks, and small and mid-sized businesses, with weaker defences and close ties to larger supply chains, have become cybercriminals’ preferred entry point. Uditha Atukorala, CEO of cybersecurity-as-a-service provider Felk, explains why this shift matters and what business leaders should do about it.
What Do the Numbers Reveal About the Scale of the Threat?
The statistics are stark. In the UK, 43% of businesses experienced a cyber breach or attack in the last 12 months, equivalent to roughly 612,000 organisations. ENISA’s Threat Landscape 2025 report analysed nearly 4,900 incidents across the EU and found that threat actors are actively industrialising their attacks, using AI to increase both the volume and impact of cyber attacks on businesses of every size.
Crucially, this is not indiscriminate fallout. Hiscox research found that 70% of cyber attackers deliberately target small businesses, which are three times more likely to be targeted than larger companies. This is a deliberate strategy, not collateral damage.
Yet awareness has not translated into action. ENISA’s 2025 NIS Investments report found that 63% of European SMEs had not carried out a single cybersecurity assessment in the past 12 months, and more than half take over three months to patch known critical vulnerabilities. Most successful attacks still exploit basic weaknesses, such as outdated software, weak passwords and poor governance, rather than sophisticated technical flaws.
Why Do Cybercriminals Prefer Smaller Businesses?
From an attacker’s perspective, the economics are simple. Cybercrime-as-a-Service platforms have industrialised attacks and removed the technical barrier almost entirely, while AI has pushed the time and cost involved close to zero. Most SMEs, through no fault of their own, lack the dedicated IT resource and incident response capability that larger organisations have built over years of investment. For criminals, that combination represents high reward for low effort.
Web-based software and customer-facing applications are a particularly attractive entry point, because they typically hold payment data, personal information and login credentials, yet are far less likely than enterprise systems to have real-time monitoring or vulnerability scanning in place. The World Economic Forum’s Global Cybersecurity Outlook found that 94% of corporate executives now identify AI as their top threat vector, and unlike large organisations, most SMEs have no dedicated function tasked with responding to it.
Supply chains compound the risk. Neither the M&S nor Co-op breaches in the UK began with those companies directly, and the pattern is repeating across Europe: a 2025 breach at Miljödata, a Swedish IT supplier, cascaded into 34 organisations and disrupted services for roughly 80% of Sweden’s municipalities. In each case, the point of entry was a smaller business in the supply chain. If your business supplies a larger company, you are part of its attack surface.
Could Your Business Already Be Compromised?
One of the most unsettling features of AI-driven attacks is their silence. Unlike disruptive ransomware incidents that make headlines, many of today’s most effective intrusions are designed specifically not to be noticed. Attackers increasingly target credentials, session tokens and application logic rather than triggering obvious alarms, using AI to probe systems continuously and move laterally through a network undetected.
By the time a breach becomes visible, whether data surfaces somewhere it shouldn’t or a customer reports suspicious activity, the attacker may already have been inside for weeks or months. In ENISA’s 2026 survey of European SMEs, just 11% said they felt confident about putting basic security requirements into practice without difficulty. Given the visibility gap in AI-enabled intrusions, that figure likely understates the real exposure.
What Does a Breach Actually Cost?
The financial consequences are severe, and for many smaller businesses, existential. A significant cyber attack now costs the average UK business almost £195,000, covering downtime, recovery, legal fees and reputational damage. For many SMEs, that is not a recoverable sum.
More than a third of the smallest European businesses have no incident response plan at all, and even among those that do, only 2% have ever tested or reviewed it. Hiscox’s 2025 Cyber Readiness Report found that 29% of attacked SMEs struggled to attract new business afterwards. In markets where reputation takes years to build, that loss can outlast the breach itself.
SME vs Large Enterprise: The Cybersecurity Readiness Gap
| Capability | Typical SME | Typical Large Enterprise |
| Dedicated cybersecurity function | Rare or informal | Standard practice |
| Tested incident response plan | 2% of those with a plan | Regularly reviewed |
| Confidence implementing basic security requirements | 11% (ENISA, 2026) | High, backed by dedicated teams |
| Real-time monitoring of customer-facing apps | Uncommon | Standard practice |
| Formal, role-specific security training | None reported (micro/small firms) | 12% of medium-sized firms |
What Can Businesses Do About It?
This is not primarily a technology problem; it is a business priority problem. ENISA’s guidance to business leaders, together with the EU’s NIS2 Directive, is explicit: cyber risk should be discussed regularly at leadership and board level, with named accountability as a business function, not left solely to the IT team.
In practice, this means:
- Moving from static, rule-based security tools to adaptive, real-time protection that operates at machine speed
- Implementing passkey-based authentication across all access points, one of the most effective barriers against automated attacks
- Conducting a proper vulnerability assessment of all public-facing systems
- Establishing a basic incident response plan, since businesses that recover fastest are those that already know what to do
- Running regular, role-specific cybersecurity training, given that none of the microenterprises or small companies surveyed by ENISA reported having formal training in place, and only 12% of medium-sized firms had reached that standard
That training gap is one that attackers are actively exploiting, through AI-generated phishing and social engineering campaigns now sophisticated enough to bypass traditional filters.
The Bottom Line
Small businesses do not need enterprise budgets or an internal IT department to protect themselves. They need the right tools, deployed correctly, by a trusted cybersecurity partner, at the right speed. AI is already being used against them; it can equally be used to defend them. The question for business leaders is no longer whether an AI-enabled attack will happen, but whether their organisation will be ready when it does.


Uditha Atukorala





