Last month, a small UK power plant was shut down for four days following a cyber attack. The plant was not a major power station. It was a small-scale generator, the kind of facility most people would consider too small to attract serious attention. Reports indicate the attack was linked to hackers affiliated with the Iranian regime.
The government confirmed the incident, and the Department for Energy Security and Net Zero wrote to power companies advising them about the risk. The National Cyber Security Centre was also involved. Officials confirmed that at no point was the wider energy system at risk.
That is reassuring for the public. For business owners, however, there is a different message buried in this story.
The target was small. The disruption was real.
A four-day shutdown is serious for any operation. It costs money, affects customers, and raises questions about reliability. And if a small-scale generator in the UK is considered worth attacking by a nation-state-linked group, that tells you something important: attackers are not limiting themselves to high-profile targets.
The assumption that your business is too small to be noticed is one of the most dangerous beliefs in cybersecurity. Automated attacks do not pick targets by reputation. Ransomware campaigns sweep across networks looking for vulnerabilities, not company names. Phishing emails are sent by the millions, not individually crafted for senior executives.
Why this matters for small businesses and nonprofits
Most small businesses and nonprofits that lack in-house IT support have never had a formal security review. Many are running on software that has not been updated in months. Some are using free consumer email accounts for business correspondence, with no multi-factor authentication in place.
None of these organisations would consider themselves targets. That is precisely why they are.
Attackers use automation to sweep for easy entry points at scale. An unpatched server, a weak password, an unprotected remote desktop connection: these are the things that get organisations compromised, not their size or their sector. A local charity holding donor personal data, a small accountancy firm with access to client financial records, a regional manufacturer with a connected production line: each carries data or systems that have real value to someone.
What a basic security posture looks like
You do not need an enterprise security operation to be meaningfully safer than you are today. The following steps address the most common vulnerabilities in small organisations.
Patch your software. Most successful attacks exploit known vulnerabilities that already have fixes available. Keeping operating systems and applications up to date closes the most obvious doors.
Use multi-factor authentication. MFA on email accounts, cloud services, and admin systems makes credential theft significantly harder to exploit. It is one of the single most effective protections available, and it costs nothing to enable on most platforms.
Control who has access to what. Not everyone in a business needs admin rights. Limiting access reduces the damage any single compromised account can cause.
Back up your data. Offline or cloud-based backups, tested regularly, mean that ransomware does not automatically mean permanent data loss. Many organisations discover their backups are incomplete or untested only after they need them.
Know what you would do if it happened. Many small businesses have no plan for what to do if they are attacked. Having a response plan, even a basic one, reduces recovery time significantly and can limit regulatory exposure under GDPR.
None of this is complicated. But it does require someone to sit down and do it properly, rather than assuming things are probably fine.
The broader picture
The UK government is currently updating its cybersecurity regulations and working on a new energy resilience strategy. That backdrop matters for businesses that operate in regulated sectors, supply larger organisations with security requirements, or hold client data subject to GDPR.
Cyber attacks on smaller targets are not just national security stories. They are a reminder that the threat environment has changed. Attacks are more automated, more widespread, and increasingly linked to geopolitical instability that businesses have no control over. The organisations that come through incidents without lasting damage are the ones that treated security as a routine operational matter rather than something to address after a problem occurs.
If you are not sure where your business stands, a basic IT health check is a practical first step. It does not take long, and it tells you what you are dealing with before someone else finds out for you.
