'For a smaller business, it can be genuinely existential' – why Gloucestershire SMEs should be aware of rising cyber threats

With the tell-tale signs getting harder to spot, and consequences that have the potential to last years, technical director at Gloucester-based expert System Force IT, Jez Walton, tells SoGlos why it's more important than ever for Gloucestershire SMEs to be resilient to cyber threats – and how a managed IT provider can help.

By Jake Chown  |  Published
Gloucester-based IT expert System Force helps ensure the SMEs it partners with have the level of cyber security they need, through thorough assessment and fully costed planning.
In partnership with System Force  |  systemforce.co.uk

Offering tailored IT support and services, including 24/7 support, cyber security, cloud solutions, VoIP and consulting, Gloucestershire-based System Force IT uses its 15 years of tech experience to ensure seamless operations through proactive, bespoke IT management for businesses and SMEs across the county and the rest of the UK.

From identifying the ways your business is vulnerable to attack, to learning what you can do about it when it happens, making sure your business is cyber secure can seem daunting to SMEs, which may not have the budget for their own in-house solutions.

SoGlos chats to Jez Walton, technical director at Gloucester-based managed services provider, System Force IT, about the threats small businesses face, the potential consequences, and why working with an IT partner is the most cost-effective way to make sure you're fully covered.

What are the biggest cyber threats SMEs face in 2026?

Phishing, still. It's been top of the list for years and it hasn't budged. It's the most common type of attack UK businesses report, and by a long way the one they find most disruptive.

What's changed is the quality of it. AI has stripped out all the tells we used to train people to look for – the bad spelling's gone, the clumsy phrasing's gone – we're now seeing emails that reference real projects, real people, real invoice numbers.

Close behind that is business email compromise. Somebody quietly gets into a mailbox, sits there for a few weeks learning how the finance team talks to each other, then intercepts a genuine invoice and changes the bank details on it. There's no malware involved, nothing for antivirus to catch. The first anyone knows about it is when a supplier rings up asking where their money is.

The third one I'd flag is supply chain. Small firms get attacked because they're the easy way into a bigger customer, and they also get badly hurt when a large partner goes down through no fault of their own.

And a newer one that's creeping up on people: staff using free AI tools with client data in them, because nobody's ever told them not to.

What impact can these incidents have, short and long term?

In the short term it's operational, and it's brutal. You can't get into your systems. Your staff are sat there unable to work but still on the payroll. Orders don't go out, invoices don't go out, and cash stops moving. For a smaller business, two weeks of that is genuinely existential. 

The Jaguar Land Rover attack is the clearest example we've had. It shut three plants for five weeks and the knock-on effects reached something like five thousand businesses, most of them small and medium-sized suppliers. Some of those owner-managed firms were talking about six months of cash flow difficulty afterwards. And here's the thing – not one of them was hacked. They just depended on somebody who was. 

Long term, the damage is commercial rather than technical. Customers ask much harder questions when the contract comes up for renewal. Insurers put your premium up. You start losing tenders because you can't tick a box on a questionnaire. And if personal data was involved, you've got the ICO to deal with on top of everything else. 

The incident lasts a few days. The consequences hang around for years.

Why should SMEs turn to a managed services provider for cyber security, rather than doing it in-house?

Honestly? Because the numbers just don't work at that scale. 

To do this properly you need someone watching around the clock, someone who genuinely understands how attackers are behaving this month, and you need proper tooling behind them. Hire one good security engineer and you've swallowed a huge chunk of an SME's entire IT budget on a single individual, who then takes holiday, gets ill, and eventually gets poached by someone paying more. And you still haven't bought the tooling, which on its own is out of reach for a 20-person business. 

What a managed provider does is spread that cost across a lot of clients. We run the same technology for a 10-user firm that we run for a 200-user one. And because we're watching a lot of businesses at the same time, when something new hits one client we've usually protected everybody else before it gets near them.

There's the paperwork side too, which people underestimate. Only about a quarter of businesses have a written incident response plan, so when something goes wrong, most of them are making it up on the spot at the worst possible moment. And increasingly your customers and your insurer want to see documented evidence of your controls, not just take your word for it.

How does System Force help Gloucestershire SMEs build resilience – what's the journey?

It always starts with an assessment, never with us trying to sell something. We go in and look at the business as it actually is – the devices, the cloud tenancy, the backups, who's got access to what, which suppliers are plugged into your systems – and we measure that against a recognised standard, usually Cyber Essentials or ISO 27001, depending on what the business needs.

You'd be amazed what turns up – a server nobody remembered was there, an account belonging to somebody who left two years ago, a backup that stopped running in March and nobody noticed because nothing ever failed. 

Out of that we produce a prioritised plan with real costs against it, phased so it fits the budget the business has rather than the one we'd like it to have. The client sets the pace, not us.

From there it goes one of two ways. Some clients want defined pieces of work – Cyber Essentials certification, a Microsoft 365 security tidy-up, ISO 27001 readiness, a network and firewall refresh. Others want us to take the whole thing on as an ongoing contract, so we're handling the monitoring, the patching, checking the backups actually restore, training the staff and being the people who pick up the phone at two in the morning. Plenty of clients start with the first and grow into the second.

We look after a few hundred client organisations across many sites and locations, and our engineers are based here in Gloucester and Kent so when something needs a human being on site, a human being turns up. The other thing I'd say is that we hold the standards we recommend. 

We're ISO 27001 certified and Cyber Essentials accredited ourselves, and we're a Microsoft Solutions Partner. We've sat through those audits. That's a very different thing from having read about them.

What would you say to SMEs who aren't sure what level they need, and are worried about overdoing it?

I'd say that's a completely fair worry, and it's our job to make sure it doesn't happen. Selling a business more security than it needs isn't clever salesmanship, it's bad advice. We tell clients to stop fairly regularly, that something's overkill for them and the money would do more good somewhere else. 

The way you avoid overdoing it is to start with the risk rather than the shopping list. What would actually hurt this business? For a manufacturer it's production stopping. For a solicitor or an accountant it's client confidentiality. For a charity it's donor data. Those three answers take you to completely different priorities, and none of them involve buying everything. 

For most SMEs, Cyber Essentials is the sensible floor. It's government-backed, it's achievable, and it covers the controls that stop the vast majority of opportunistic attacks. And yet only about five per cent of UK businesses actually hold it. That gap between 'basic and affordable' and 'actually done' is where nearly every incident I see ends up living. 

The last thing I'd say is this. Most businesses only make changes after they've been hit. Every single one of those changes could have been made beforehand, calmly, for less money. So get an honest assessment. And if the answer is that you're in decent shape already, we'll tell you that as well.

How can businesses access cybersecurity services from System Force?

Just pick up the phone and have a conversation with us – no obligation and no jargon. We're very happy to come out, take a look at where a business stands, and tell them honestly what does or doesn't need attention.

You can reach us on 0330 0167 681, or find us at systemforce.co.uk. We're based at Brearley Place on Baird Road in Quedgeley, so we're on the doorstep for most of the county. 

We're a local business supporting local businesses, and we're always glad to talk to fellow Gloucestershire firms – whether they end up working with us or not. 

We also have a blog and free resources available – no payment needed – at systemforce.co.uk/resources and systemforce.co.uk/blog/category/blog.

In partnership with System Force  |  systemforce.co.uk

More on System Force IT More

More on Gloucestershire More

More from Business More