Research reveals UK industry sectors most vulnerable to cyber-attacks

A new research report reveals how technology decision makers at UK SMEs are prioritising cyber security to ensure business continuity and growth…
cyber attacks

Share this article:

A new research report reveals how technology decision makers at UK SMEs are prioritising cyber security to ensure business continuity and growth.

The report also highlights newer technologies such as robotics and AI that SMEs plan to adopt, how SMEs are using technology to power remote workforces and what technologies they are adopting for growth.

Cyber security features heavily in the report with respondents revealing attack frequency, cyber strategy status and employee training to combat hackers.

The vast majority of UK SMEs (81%) confirmed that they had suffered a data breach or cyber-attack, with a considerable two in five (37%) admitting they had suffered multiple breaches.

Industry verticals had a significant bearing here, with the healthcare, IT & telecoms and legal industries topping the list of those suffering multiple attacks.

The top six verticals where respondents had more than one breach, by vertical:

Industry attacks

One respondent said his SME suffered at least eight attacks.

Reasons to attack key industries

Healthcare

Public sector healthcare providers are particularly susceptible to supply chain attacks that exploit the chain of trust, targeting the valuable personal data which healthcare providers store and process. Suppliers can be seen as more vulnerable and an easier route for attackers to gain access to a more lucrative target. Hospitals store an incredible amount of valuable, confidential patient data which hackers can sell on easily – making any supplier to the industry a target.

IT & Telecoms

Some IT companies may store large amounts of sensitive customer data, while cloud storage and computing service providers, developers of security software, or file-sharing solution providers, are often the targets of supply chain compromise attempts.

Direct attacks seek to access the organisation’s network operations and data while indirect attacks target subscribers within the telecoms sector. SME suppliers may be a gateway into the network – once inside, cyber criminals can easily access data and intercept calls, as well as control and impersonate subscribers.

Legal 

The legal sector is particularly vulnerable to cyber-attacks due to the volume of data, sensitive information, financial responsibility and authority held. If a law firm specialises in corporate or property law, they are at increased risk, as the potential for financial gain is greater. Although the main reason law firms are targeted is for financial gain, there is also a growth in bad actors using cyber-attacks to achieve political, economic or ideological goals.

HR & Recruitment

Payroll fraud, recruitment scams, corporate espionage – cyber-attackers have found numerous routes into organisations via HR. Any identifiable information is valuable to criminals, and payroll and other HR systems are a treasure trove of names, addresses and bank details. If this is compromised, not only can it affect individual employees, it also gives attackers more ammunition with which to increase the likelihood of a successful attack on other parts of the business.

Additionally, recruitment agencies are prime targets for malware. If hit by a data breach, employment agreements and sensitive documents such as passport scans and visa details are all left exposed.

Manufacturing 

The manufacturing sector, which includes automotive, electronics, and pharmaceutical companies, has always been a vulnerable industry when it comes to cyber-crime and security breaches. This is because intellectual property is incredibly valuable, and often manufacturing firms rely on highly specific software packages that are difficult to patch against recent exploits, making them highly vulnerable to attack.

Financial 

The threats facing organisations working directly and indirectly with the finance sector go far beyond simple theft. Cyber threats facing banks, insurance companies, asset managers and similar organisations range from basic consumer-grade malware all the way up to highly targeted attacks from organised criminals and state-sponsored actors. Financial service providers are a hacker’s favourite, given the nature of the private information held by those organisations.

Further cyber trends highlighted in the report:

  • The vast majority of SMEs confirmed that they were increasingly worried, with 81% more fearful of a cyber-attack or data breach
  • 81% of UK SMEs confirmed that they had suffered a data breach or cyber-attack
  • Nearly 1 in 5 (17%) IT decision-makers surveyed have no cyber strategy in place
  • 76% agree that they are nervous about moving from an on-premise IT infrastructure to a cloud infrastructure due to fears of data security
  • 98% of IT decision-makers in SMEs educate employees about how to identify a cyber threat, with the most popular approach being a combination of external and internal training (32%)
  • SMEs in the financial sector were more likely to suffer three or four breaches than any other sector at 50%, while healthcare and IT & Telecoms sectors were most likely to suffer two breaches at 75%.

Colin Dennis, Head of Technical Operations, OGL Computer, said: “Cyber security has been front of mind for SME customers for some time now, as awareness of cyber-risks continues to rise. Proactive management of IT requirements is in many ways connected to this trend, as businesses of all sizes look to compliance requirements as well as asset protection and disaster recovery.”

For more security news visit here.

 

 

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

PaxLock Pro2 - securitybuyer.com

Paxton officially launches PaxLock Pro2

Paxton the security technology manufacturer has launched a brand-new re-engineered PaxLock which is built to protect straight
KentixONE data centre - securitybuyer.com

Data centre security with KentixONE

Prior1 develops container data centers to meet the highest security and energy efficiency standards. Their containers require
Chubbsafes - securitybuyer.com

Chubbsafes explores certified storage for jewellery and precious metals

Chubbsafes, part of Gunnebo Safe Storage, has launched a new technical discussion guide examining when certified
Mercury trends report - securitybuyer.com

New Mercury Research Finds Growing Cybersecurity Gap

2026 Trends in Access Controllers Report finds interoperability, cloud connectivity and AI are reshaping long-term controller strategies.
Chris Carroll - securitybuyer.com

Comelit-PAC Promotes Chris Carroll as Sales Director

Comelit-PAC has appointed Chris Carroll as Sales Director, following an 18 year career with the company, seeing him progress
Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
OPTEX at Essen - securitybuyer.com

OPTEX to showcase perimeter solutions at Security Essen

OPTEX will present its latest perimeter and asset protection solutions at Security Essen 2026, one of Europe’s leading security trade fairs.
Dallmeier

Building Trust in Modern Video Security

Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology. 
Scroll to Top