Top 5 IT and cyber concerns we're hearing from Midlands SMEs
By Tom Sykes · 9 September 2026 · 5 min read

In short
Across recent conversations with SMEs in Telford, Shropshire and the wider Midlands, five concerns come up again and again: hard-to-spot phishing, ransomware recovery, ageing IT systems, the lack of a clear incident plan, and confusion around Cyber Essentials. None needs enterprise-level complexity to fix. Each has a practical, proportionate answer.
Over the past week we have spoken with dozens of SMEs across the Midlands, at local events and in everyday business conversations. Every organisation is different, but the same worries about IT and cyber security kept coming up.
These are not abstract or hypothetical risks. They are real, day-to-day issues that affect productivity, reputation and the ability to keep trading. The UK Government’s 2025/26 Cyber Security Breaches Survey found that 43% of UK businesses, and 46% of small businesses, had experienced a cyber breach or attack in the previous 12 months, with phishing by far the most common type.
Below are the five concerns we hear most often, why each one matters, and the practical steps that reduce the risk without overcomplicating things.
1. Phishing emails that are harder than ever to spot
Phishing is still the most common way attackers get in, and SME owners know it. It is the single most prevalent type of attack in the UK: in the same government survey, 38% of businesses reported a phishing attempt in the past year. What has changed is how convincing these emails now look. The worries we hear most are:
- Emails that appear to come from a trusted supplier or a colleague
- Fake invoice requests and payment-change notifications
- Messages that slip past spam filters and land straight in the inbox
For many businesses the concern is not just whether a phishing email will arrive. It is whether someone will spot it in time.
Why it matters: a single click can hand over a password, compromise an account, or open the door to ransomware.
The practical fix: strong email security, multi-factor authentication (MFA) and short, regular awareness training cut the risk sharply, without getting in the way of how people work.
2. Ransomware, and “what if we couldn’t recover?”
Ransomware is no longer seen as a problem only for large corporations. Midlands SMEs increasingly understand that they are a prime target. The biggest worry we hear is rarely the attack itself. It is what happens afterwards:
- Would we get our data back?
- How long would systems be down?
- Could we keep trading?
Most businesses have backups, but many are not confident those backups are properly protected, regularly tested, and kept separate from live systems.
Why it matters: a backup that does not work under pressure is as risky as having no backup at all.
The practical fix: secure, monitored backups combined with a recovery plan that has actually been tested give a business the confidence to survive an incident, not just react to one.
3. Ageing IT systems creating hidden risk
Legacy systems came up again and again. The common issues are familiar:
- Devices running on unsupported operating systems
- Software that has not been updated but is “too critical to change”
- Older infrastructure that no one fully understands any more
These systems often still work, which is exactly why they get left alone. Quietly, they introduce security gaps and reliability problems.
Why it matters: outdated systems are easier for attackers to exploit and more likely to cause unplanned downtime.
The practical fix: you do not need a full IT overhaul. A phased review that tackles the highest-risk systems first reduces exposure while keeping the budget under control.
4. No clear incident response or cyber plan
One of the most honest comments we heard was, “if something serious happened, I am not sure we would know what to do first.”
Most SMEs do not lack commitment to security. They lack clarity. The questions come up often:
- Who do we call if there is a breach?
- How do we isolate the affected systems?
- What do we tell customers and suppliers?
Why it matters: in an incident, confusion costs time, and time costs money.
The practical fix: a simple incident response plan, even a short one, gives a team structure and confidence in a stressful moment. It does not need to be complex. It needs to exist.
5. Confusion around Cyber Essentials and compliance
Cyber Essentials came up in almost every conversation, often with some uncertainty attached. Businesses told us they were not sure whether it applied to them, what was actually involved, or whether it was a tick-box exercise or a real improvement.
For some it is driven by supply-chain pressure or a specific contract. For others it is about demonstrating good practice to customers.
Why it matters: Cyber Essentials is not really about the certificate. It is about putting proven baseline controls in place that block the most common attacks.
The practical fix: with the right guidance, Cyber Essentials becomes a structured way to improve security, reduce risk, and build trust with customers and partners.
Turning concern into confidence
The clearest takeaway from these conversations is this: Midlands SMEs are not ignoring cyber security. They are looking for clarity, simplicity and reassurance.
Strong resilience does not require enterprise-level complexity. It starts with understanding your real risks, getting the basics right, and having clear support on hand when you need it.
At Stiperstone Group we work with Midlands businesses to turn uncertainty into confidence, across managed IT, cyber security and digital transformation, with practical next steps that make sense for your organisation.
Not sure where your biggest risks are?
If any of the concerns above sound familiar, you are not alone, and you do not have to work them out on your own. A short, no-pressure IT and cyber health check quickly highlights where your main risks sit today, what needs attention now versus later, and how to strengthen your security without disrupting the business.
Frequently asked questions
We are a small business in Shropshire. Where should we start?
Book a no-pressure IT and cyber health check
A short review that shows where your main risks sit today, what needs attention now versus later, and how to strengthen your security without disrupting the business.
Book your health check
