The impact of a cybersecurity attack can be catastrophic for a small business. John Cradden outlines ways SMEs can offset the disruption, downtime, lost productivity and operational interruptions caused by cyberattacks.
When a major cyberattack happens, the damage it creates for any business or organisation can be hugely disruptive and costly. Witness the infamous HSE breach of 2021, when a phishing email from a Russian hacker triggered a system-wide shut down that lasted a staggering four months.
However, for small businesses the biggest headache created by cyberattacks is not the impact of major one-off breaches, but rather the repeated day-to-day disruption, downtime, lost productivity and operational interruption caused by multiple incidents throughout the year, according to research commissioned recently by Eir business.
“Backing up your data regularly and keeping it separate from your original data will help you out in a theft scenario”
Firms that experience cyberattacks typically report four to five incidents each year, with a median cost of €8,700 per incident, according to the research, which was supported by Microsoft and Kemmy Business School at the University of Limerick.
Even if your business has gotten off lightly to date in terms of attacks, SMEs are now a prime target for cybercriminals because they are more likely to have weaker defences and limited budgets. A 2025 survey by MTU and the National Cyber Security Centre (NCSC) revealed that more than three-quarters of Irish SMEs (78%) demonstrated inadequate cyber resilience, rising to 81% for micro-enterprises with fewer than 10 employees.
Protecting your business
The type of attacks being perpetrated on SMEs will likely be familiar to most owners and managers by now. These include ‘phishing’ emails or texts, password and data theft, scam calls and messages, etc.
The common thread in most cyberattacks now is that they seek to use human interaction as their way into your systems and, by extension, those of your suppliers and clients.
Protecting your business calls for a strategy that incorporates a range of measures. So where should you start?
6 essential first steps
A good first step is to contact the NCSC, which provides targeted cyber security supports to SMEs to build their resilience to cyberattacks.
The centre recently launched a new dedicated website aimed at providing SMEs with practical, accessible and free guidance on strengthening their cyber security awareness, preparedness and response capabilities.
It lists six important steps to protecting your business, starting with identifying what your essential digital assets are; the data that your company can’t do without, its IT systems and infrastructure, the equipment and devices used by your employees.
Making sure your software, systems and devices are up to date is the next step, as updates should fix security flaws and weaknesses, making it hard for cyber criminals to exploit. Basic protection is another essential step, such as anti-virus, anti-malware and encryption tools.
This can be augmented by multi-factor authentication to significantly enhance password security, which is said by Microsoft to prevent 99.9% of account attacks.
Backing up your data regularly and keeping it separate from your original data will help you out in a theft scenario, enabling you to at least retain key business and customer information. And last but not least, making it company policy to use strong and complex passwords is one of the easiest and most effective ways to safeguard your data.
Cyber insurance
You could also consider cyber insurance, which can provide cover for the costs of data breach responses, business interruption, ransomware incidents, data system recovery, legal defence costs, customer notification expenses, and PR support for incidents.
However, there can be a lot of variation between firms offering this type of cover, so it’s important to read the Ts and Cs carefully.
The cybersecurity tools worth paying for
Given the extent of the threat of cyberattacks on Irish SMEs and the lack of resources or in-house expertise to keep to up with ever-changing threats, the gaps in monitoring, threat detection and incident response required will often point the way to some kind of managed solution.
A managed detection and response (MDR) service can be one of the most effective ways Irish SMEs can enhance their defences.
MDR delivers full-time monitoring, rapid incident response, and expert analysis — without the need to build your own security operations centre. It will detect suspicious activity early, isolate threats, and provide forensic insight to prevent repeat incidents.
Other tools worth considering are some kind of advanced email security, identity and access management (which implements multi-factor authentication) and automated patch management.
Grants
Irish firms are also being encouraged to go much further with cyber security, not just for protecting them and their customers, but also as a value-add differentiator in the context of the international market.
Enterprise Ireland’s Cyber Review Grant is aimed at supporting an assessment of a company’s cybersecurity and produce a remediation plan. It will fund 80% of a clearly defined security review worth €3,000. The review is designed to meet the specific needs of Irish firms and encourage them to take the next step on their security journey.
It is expected that most of the steps recommended in the review will be structured so they can be implemented by your company directly.
Other supports
The NCSC ran a limited campaign last year for a Cyber Improvement Grant to help implement some of the recommendations of an EI review with a significant financial support of €60,000 or 80% of the project cost, whichever was the lesser.
While this is no longer available, it will be launching a free cyber security risk assessment tool aimed specifically at Irish SMEs.
In response to its own recent research findings, eir business has launched a new Cybersecurity Assurance service aimed at helping SMEs build resilience through continuous support rather than reactive interventions.
The subscription-based offering includes access to a virtual chief information security officer, ongoing advisory services, regularly updated incident response and business continuity plans, and rapid access to specialist response teams.
Microsoft Ireland has a handy downloadable resource entitled the Be Cybersmart Kit, comprising a number of guides around key cybersecurity themes, including spotting fake website scams, protecting yourself from phishing, and how to go further with securing your sign-in protocols.
-
Bank of Ireland is welcoming new customers every day – funding investments, working capital and expansions across multiple sectors. To learn more, click here
-
For support in challenging times, click here
-
Listen to the ThinkBusiness Podcast for business insights and inspiration. All episodes are here. You can also listen to the Podcast on:
-
Spotify
-
SoundCloud
-
Apple





