Your Business Has a Cyber Security Problem Right Now. You Just Do Not Know About It Yet.

The average dwell time for a cyber attacker in a UK business network before discovery is 197 days.

That is six and a half months of undetected access. Six and a half months during which an attacker has had time to map the network, identify valuable data, establish persistence mechanisms, exfiltrate information, and position themselves to cause maximum disruption when they choose to act.

By the time most businesses discover a breach, the attacker has had longer in their network than a new employee's probation period.

What the attacker is doing for those 197 days

A sophisticated attacker does not immediately encrypt data or steal credentials and disappear. The more dangerous attacks involve patient, methodical reconnaissance.

In the early phase, the attacker is observing. They are learning the network topology, identifying high-value targets, and understanding the business's communication patterns.

In the middle phase, they are establishing persistence: creating backup access routes, ensuring that removing one entry point does not lock them out, and sometimes creating administrator accounts that look legitimate.

In the final phase, they act. Sometimes that means ransomware. Sometimes it means data exfiltration and a subsequent extortion demand. Sometimes it means both.

At the moment the business first knows something is wrong, the attacker has had six months of uncontested access.

The vulnerabilities most common in British SMEs

Unpatched software is the most reliable entry point. Known vulnerabilities in operating systems and applications are documented and exploited routinely. Businesses that do not apply security patches promptly are advertising known weaknesses to anyone looking.

Password reuse is the second. Credentials stolen from one service are systematically tried against every other service the same user might have. If someone uses the same password for their email and their banking, and the email provider suffers a breach, the banking account is now accessible to whoever bought the breach data.

Absence of multi-factor authentication means that a stolen password is sufficient to access a system. MFA raises the cost of a successful attack significantly.

Open RDP ports are a specific and serious vulnerability. Remote Desktop Protocol exposed directly to the internet is a well-known attack surface and the subject of continuous automated scanning.

Untrained staff remain the most reliable route into a business. Phishing attacks succeed at a high rate even in technically sophisticated organisations.

The cyber insurance problem

Cyber insurance has become increasingly important and increasingly difficult to obtain and maintain.

Insurers have responded to the scale of cyber claims by requiring specific security controls as conditions of coverage: MFA on email and remote access, regular patching, endpoint detection and response, employee security awareness training.

Businesses that do not have these controls in place are being declined coverage or finding that claims are rejected because the controls listed as requirements on the policy application were not actually in place.

This is not small print. It is the primary cause of disputed cyber insurance claims.

What the minimum viable security posture looks like

For a British SME in 2026, the minimum that represents a defensible security posture includes: MFA enforced on all cloud applications and remote access systems. Endpoint protection with monitoring on all devices. Current patching on all operating systems and applications. RDP not exposed directly to the internet. Regular, tested backups held offsite or in the cloud. Staff awareness training including phishing simulation. A documented, tested incident response plan.

None of these is complex. All of them are within the reach of any business. Most businesses that are compromised had the resources to implement these controls. They simply had not done so.

IT-Works provides cyber security assessments for businesses across the UK, covering vulnerability identification, security control review, and practical remediation planning. If your business has not had a security assessment in the last twelve months, that assessment is overdue.

IT Works cyber security assessment: enquiries@it-works.co.uk | 0121 270 0808 | https://it-works.co.uk/cyber-security/

Leave a comment

All comments are moderated before being published