CyberSecurity SEE

Average Annual Cybersecurity Spending of UK SMEs

In the United Kingdom, the issue of cybersecurity spending among small and medium-sized enterprises (SMEs) remains a complex and somewhat nebulous topic. Official data on this subject has been sparse since the UK Government ceased collecting detailed figures after its 2019 survey. The absence of up-to-date statistics has led to questions regarding how much SMEs should reasonably allocate for cybersecurity in the current digital climate.

The last significant survey revealed that micro and small businesses were spending an average of £3,490 annually on cybersecurity, yet the median spending was found to be considerably less at just £200, with around one-third of businesses reporting that they invested nothing in this area. This wide disparity highlights the different approaches that SMEs take in combating cybersecurity threats, reflecting a range of strategies, needs, and priorities across this sector.

To accurately gauge cybersecurity needs in 2026 and beyond, it is essential to consider what aspects an SME must protect. Cybersecurity investments encompass various facets, including email security, website protection, mobile devices, cloud software such as Microsoft 365 or Google Workspace, backup systems, firewalls, endpoint protection, and vulnerability management. Furthermore, strategies for staff training, penetration testing, cyber insurance, and specialized IT or security services also fall under this budgetary umbrella.

Considering all these factors, a typical UK SME should aim to budget between £5,000 and £15,000 annually for cybersecurity, particularly if it is a larger entity with increased digital dependencies. Nonetheless, it is vital to note that there is no one-size-fits-all percentage or fixed amount that is universally applicable; the cybersecurity needs of a ten-person consultancy handling limited customer data will vastly differ from those of a 50-person manufacturing firm employing internet-connected systems and managing sensitive intellectual property.

The crux of the issue lies in ensuring that the cybersecurity budget comprehensively addresses the entire attack surface instead of merely focusing on traditional antivirus software. For instance, an organization can possess exceptional endpoint protection yet remain vulnerable through a compromised Microsoft 365 account, a poorly protected website, weak passwords, or an employee falling victim to a phishing attack.

A well-rounded cybersecurity budget should ideally encompass protection for people, devices, applications, websites, emails, and data. For email systems, this can entail robust spam and phishing protection, multi-factor authentication, and continuous monitoring for unusual account activities. Businesses should ensure that laptops and desktops are safeguarded through endpoint protection, device encryption, regular patching, and secure configurations.

Websites and online applications also necessitate stringent safeguards that include vulnerability scanning, web application security, secure hosting, domain protection, SSL certificates, and regular updates, alongside appropriate penetration testing when necessary. In addition, the review of cloud software and business applications is crucial, as a security incident involving a third-party platform could exert a negative impact on the SME.

Backup systems constitute another critical dimension of the cybersecurity budget. Maintaining secure and tested backups is vital, as they serve as a safety net against ransomware attacks or unintentional data deletion, both of which can lead to catastrophic business interruptions.

Over the past five to ten years, there has been a notable uptick in cybersecurity spending among UK SMEs, although precise metrics remain elusive due to the lack of continuous official records detailing annual spending figures. In 2018, the UK Government estimated that micro and small businesses would spend, on average, around £2,400 annually on cybersecurity. However, by the 2019 Cyber Security Breaches Survey, this figure had risen to £3,490. The government itself noted that spending varied significantly across organizations, indicating a diverse landscape of cybersecurity investments.

The overall cybersecurity market in the UK has surged dramatically, with government analysis indicating that the number of security firms jumped from 846 in 2017 to 2,091 in 2023. This growth has also been reflected in cybersecurity-related revenue, which rose from £5.68 billion to £11.86 billion during the same period.

More than ever, SMEs are grappling with a more challenging and intricate digital threat landscape compared to five or ten years ago. The dependence on cloud software, remote working arrangements, online payment systems, customer databases, and email communication has introduced additional vulnerabilities within organizations. According to the latest government survey, a staggering 43% of UK businesses experienced a cyber breach or attack within the past year, with the figure climbing to 50% among small enterprises.

In response to this escalating pressure, many businesses are adjusting their budgets accordingly. The latest Cyber Security Longitudinal Survey revealed that 37% of organizations had raised their cybersecurity budgets either moderately or significantly, while an additional 18% had done so in line with inflation.

Determining the appropriate cybersecurity budget for an SME thus becomes an exercise in understanding specific vulnerabilities rather than adhering to an average number. For most SMEs, an annual range of £5,000 to £15,000 constitutes a feasible starting point, especially when that budget includes protections for everything from emails and endpoints to cloud applications and backups.

Organizations managing sensitive personal information, processing payments, or operating critical systems may find it necessary to allocate even greater resources toward cybersecurity. It is crucial to frame cybersecurity as an ongoing business expense rather than a one-off IT purchase. Ultimately, the question is not whether a company can afford to spend on cybersecurity, but rather whether it can afford to leave its digital assets, customer information, and operational integrity inadequately safeguarded.

Source link

Exit mobile version