Most leadership teams have a rough answer ready when someone asks about cybersecurity. The IT lead handles it. There's a review every year. The business passed its last audit. Insurance is in place.
That is not a cybersecurity posture. That is a filing system for reassurance.
The distinction matters because the decisions that determine how badly a cyber incident damages a business are not technical decisions. They are leadership decisions. Which suppliers hold sensitive customer data. Which operational processes have no manual fallback if systems go down. What the business would actually say to clients, staff and partners during an incident, and who would say it. These are not questions for the IT lead alone. They are questions for the people who run the business, and in most UK SMEs, those questions have never been asked out loud.
The framing problem
Cybersecurity has been allowed to sit in the wrong conversation for too long. It gets discussed in the context of software, firewalls, password policies and, occasionally, the annual insurance renewal. All of those things are real and worth attending to. None of them is where the meaningful leadership exposure lives.
Consider what actually happens during a ransomware incident. Systems become unavailable. Data may be inaccessible or compromised. Staff cannot do their jobs. Customer commitments cannot be met. Communications become urgent and improvised. Decisions need to be made, fast, by people who are unprepared, under pressure, without good information.
The technology has already failed at that point. What happens next is entirely a leadership and operational problem.
The average operational downtime following a ransomware incident now exceeds 21 days. For a business with 30 or 50 people, three weeks of degraded or absent capability is not a technical inconvenience. It is a trading crisis. Contracts slip. Customer relationships fracture. Revenue stops. The question is not whether the business has the right antivirus software. The question is whether the leadership team has ever genuinely rehearsed what they would do.
Most have not.
What the commercial environment is starting to require
There is a practical urgency here that goes beyond prudence. The Cyber Security and Resilience Bill, which cleared its Commons stages in June 2026 and is now in the House of Lords, expands the UK's regulatory perimeter for cyber obligations. Among its provisions is a requirement for regulated organisations to assess and manage cyber risk across their supply chains.
That last part is what catches smaller businesses.
If your organisation supplies a regulated business, or even a larger commercially cautious one, expect to see contractual cyber requirements arriving with more frequency and specificity than before. Not vague questions on a supplier questionnaire. Actual requirements about how you handle data, how you would respond to an incident, what your continuity arrangements look like. Passing those conversations by pointing to an annual IT review is going to become increasingly awkward.
Ransomware groups are also, deliberately and methodically, targeting SMEs. The reasoning is straightforward: smaller organisations are less likely to have robust incident response capabilities, more likely to pay quickly, and more likely to have been overlooked in terms of basic security hygiene. Global ransomware attacks have increased 56% over the last two years. SMEs are not collateral damage in this landscape. They are a target demographic.
The leadership decisions hiding inside technical language
Here is where the framing issue becomes genuinely costly. Because cybersecurity is treated as a technical subject, a number of decisions that are fundamentally about risk, operations, and commercial judgement get made by default rather than deliberately.
Which third parties have access to your customer data? In many SMEs this question produces a thoughtful pause followed by an approximate list. The actual answer, including every SaaS tool, cloud platform, payment processor, accountancy system, HR tool and shared inbox, is usually longer and less examined than anyone expects. Deciding which of those relationships introduces acceptable risk and which does not is not a technical call. It is a commercial and governance call that happens to involve technology.
Which processes would continue, in a degraded form, if your primary systems were unavailable for a week? Most organisations have not mapped this. And I mean mapped it properly, not assumed the answer. The process of identifying which operations have a viable manual or offline fallback, and which simply stop, is unglamorous work. It is also the work that determines whether a disruption is survivable.
How would you communicate, and what would you say? During an incident, the communications decisions made in the first 24 hours tend to have consequences that outlast the incident itself. Who speaks for the business? To whom? In what order? With what message? These are not questions with a technical answer.
The counter-argument, taken seriously
The obvious objection is resource. A founder or managing director of a 40-person business is not going to become a security specialist, and asking them to treat cybersecurity as a leadership priority alongside everything else feels like one more demand on an already stretched agenda.
That objection is correct in one direction and wrong in another.
No one is suggesting that business leaders need to understand the technical architecture of a modern threat actor's approach. They do not. The argument is narrower: that the decisions listed above, about suppliers, processes, communications and continuity, are decisions the leadership team is already responsible for in every other context. Cybersecurity is simply the lens that reveals how much of that decision-making has been left unexamined.
A 40-person business that has never discussed what an operational shutdown would look like in practice has a gap in its risk management, not a cybersecurity gap specifically. Naming it as a leadership responsibility rather than an IT one is not adding to the burden. It is placing the conversation where the decision-making authority actually sits.
Where to start, practically
The most useful starting point is not a tool, a certification, or an audit. It is a conversation.
Specifically: a structured exercise in which the leadership team works through a realistic scenario. Not a presentation about threat statistics. A simulation in which the systems are down, the phone is ringing, a client has noticed, a decision needs to be made, and the options available are worse than anyone hoped. That kind of exercise reliably exposes three things: which decisions have genuinely been made in advance, which ones everyone assumed someone else had made, and which ones no one had considered at all.
Scenario testing of this kind does not require expensive tooling or a large project. It requires a cleared diary, a facilitator willing to make the scenario uncomfortable, and a leadership team prepared to be honest about what they find.
The certification and the audit can follow. They will be considerably more useful once the leadership team has a genuine understanding of where the real exposure lies, rather than working backwards from a compliance checklist.
If your team has never had that conversation, that is where to start. Not because a bill is moving through Parliament, not because a supplier questionnaire arrived last week, but because the decisions involved are yours to make, and right now, in most organisations, they simply are not being made.
That is the gap worth closing first.