Back to all articles
Cybersecurity

Your Business Attack Surface: What Automated Attackers Scan For First

Toi 'n' Moi® Team
9 September 2026

Most small and medium businesses assume they are too small to be worth attacking. That assumption is the vulnerability. Modern cyber attacks are not carried out by a person who chose your company — they are carried out by software that scans the entire internet looking for a weakness, and finds a small business with an unpatched website on the same day it finds a large one.

The UK Government's Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses reported a cyber security breach or attack in the previous 12 months. It is not rare, and it is not only the big names: while medium (65%) and large (69%) businesses are hit most, 42% of micro businesses and 46% of small businesses reported one too.

"Untargeted" is the word that matters

The National Cyber Security Centre (NCSC) draws a clear line between targeted and untargeted attacks. In its guidance Common Cyber Attacks: Reducing the Impact, it describes untargeted attacks plainly: attackers "indiscriminately target as many devices, services or users as possible… They do not care about who the victim is." One of the named techniques is "scanning — attacking wide swathes of the Internet at random."

The NCSC's conclusion is blunt, and it applies to every business with a website or an email domain: "every organisation connected to the Internet should assume they will be a victim." Your attack surface — everything of yours that faces the internet — is being probed whether or not anyone has ever heard of you.

What that attack surface actually is

"Attack surface" sounds abstract. In practice it is a short, concrete list:

  • Your website — missing security headers, files and folders left exposed, an outdated CMS or plugin with a known vulnerability.
  • Your email domain — whether a criminal can send email that looks exactly like it came from you (see our guide to SPF, DKIM and DMARC).
  • Your public services and DNS — open ports, forgotten subdomains from an old project, and DNS records pointing at services you no longer run.
  • Your cloud and Microsoft 365 / Google Workspace — over-broad sharing, admin accounts without multi-factor authentication, and stale accounts nobody closed.
  • The devices on your network — the router, the Wi-Fi, the printer that quietly exposes a web admin panel.

The gaps are boringly consistent

The same survey shows where UK businesses are weakest, and it is not exotic. Only 34% of businesses have a policy to apply software security updates within 14 days — patching, the single most effective defence against automated exploitation, is the least-adopted basic control. Fewer than half (47%) use any form of two-factor authentication. Meanwhile phishing remains the most common attack by far, reported by 38% of businesses, followed by people impersonating your organisation in email (12%).

These map almost exactly onto the NCSC's five Cyber Essentials controls — firewalls, secure configuration, security update management, user access control and malware protection. An attacker's automated scan is, in effect, a test of whether you have done those five things. The internationally-focused Verizon 2025 Data Breach Investigations Report found the exploitation of vulnerabilities as an initial way into a breach had grown to 20%, with internet-facing edge devices and VPNs a fast-rising share — a direct consequence of running unpatched services.

Why "we've never had a problem" is not evidence

The Breaches Survey now reports the median cost of the most disruptive breach as low — £0 for most businesses, because most detected incidents are phishing attempts that were spotted. But the same data shows a long, expensive tail: the 95th-percentile cost reaches £4,000 for a typical business and £10,000 for a medium or large one, and the previous edition put the average disruptive breach at £1,600. "Nothing has happened yet" tells you about the attacks you noticed, not the exposure you have.

What to do about it

You cannot fix what you have not mapped. A Security Posture Review looks at your business the way an automated attacker's scan does — website, email, public services, Wi-Fi, cloud — and produces one prioritised list: the most serious gaps first, each with a specific, plain-English fix. It is a review, not a penetration test: we identify and rank the weaknesses rather than exploiting them, which is the right first step for almost every SMB (we explain the difference in why an independent audit beats a checklist).

If you would like to know exactly where your business is exposed before someone else finds out, book a free scoping call for a Security Posture Review. We will tell you honestly whether it is worth your money.

This article is general information about cyber security, not specific security advice for your business. All security testing we carry out is done only with your signed authorisation.

Start Your Digital Journey.

From polished brand websites to private AI-powered business platforms, we build digital systems that look premium, perform reliably, and scale with your business.

Start Your Project

Stay in the loop

Occasional updates on new features and what we're building — no spam, unsubscribe anytime.