The report highlights widespread vulnerabilities. Over half of SME employees have never received cybersecurity training, while nearly a third of SMEs lack any form of cyber protection altogether. Almost 40% of small firms invest less than £100 annually in cybersecurity, and a significant portion allow employees to use personal devices when working from home. One in five remote workers has been targeted by cybercriminals, and in some cases, employees have been banned from remote work due to the associated risks.
Phishing remains the most common threat, followed by ransomware, distributed denial-of-service (DDoS) attacks, and water holing. Despite these growing risks, many SMEs are unprepared.
In response, Vodafone is recommending several policy changes. These include expanding the Cyber Local funding initiative, updating the outdated Cyber Essentials program, and embedding cybersecurity awareness into key business activities like tax filings or company registrations. For larger SMEs, Vodafone suggests mandatory compliance with security standards as part of existing reporting obligations.
Additionally, the company advocates for tax incentives to encourage cybersecurity investment, including R&D tax credits and full expensing of security-related hardware and software. Vodafone also calls for a dedicated capital allowance for cybersecurity to make accessing tax reliefs easier for SMEs. Stronger public-private partnerships are also needed, allowing smaller firms to benefit from the expertise of larger organizations with established risk management systems.
To help address immediate needs, Vodafone is offering SMEs a free one-month trial of CybSafe, a cybersecurity training platform that helps build employee confidence in detecting and handling threats such as phishing and ransomware.
Cybersecurity has become a critical issue for SMEs. With the right support and smarter policy decisions, businesses can be better equipped to defend themselves in an increasingly hostile digital landscape.
Source: Infosecurity Magazine
The European Cyber Intelligence Forum is a nonprofit think tank specializing in intelligence and cybersecurity, offering consultancy services to government entities. To mitigate potential threats, it is important to implement additional cybersecurity measures with the help of a trusted partner like INFRA www.infrascan.net, or you can try yourself using check.website.