When we talk about cyber scams and attacks on SMEs, we concentrate on threats from cyber criminals because, quite simply, they are not just the perceived threat, but often the actual threat.  However, there is another category which we tend not to connect with SMEs, but rather with the corporate and government worlds, and that is the nation state threat. With what’s happening in the world today, maybe we should be keeping a weather eye on that potential threat.

Let’s take Iran for example, research suggests that they have been far more successful at espionage and disruption than at causing strategic damage.  Since the conflict escalated (initial Israel-Iran fighting in June 2025, followed by direct US-Israeli operations against Iran in February 2026), Iran’s cyber organisations have launched thousands of attacks against Israel, the US and Western allies. However, most have been contained, short-lived, or psychological in effect rather than strategically decisive. Cyber defences have largely prevented catastrophic infrastructure failures. This suggests that there hasn’t been much to worry about, from an SME perspective.  However, there is much more to it than that.

For UK SMEs, this is one of the biggest shifts in cybersecurity over the past 2–3 years.  Nation-state actors are no longer just targeting governments and FTSE 100 companies. They’re increasingly targeting SMEs because SMEs are the easiest route into larger organisations, valuable data, and critical UK supply chains.

The UK National Cyber Security Centre (NCSC) has repeatedly warned that the most serious cyber threats facing the UK now come from Russia, China, Iran and North Korea, and that businesses of all sizes need to prepare for attacks linked to geopolitical conflict.

The Nation-State Cyber Threat Landscape for UK SMEs (2026)

A Board-level takeaway is that your business is probably collateral damage, not the primary target.  You’re the route into your larger customers.  SMEs are targeted because they are easier to compromise than large enterprises and often have trusted access into customers, suppliers, and public-sector organisations.

What SMEs worry aboutWhat nation states actually do  
Steal money with ransomwareSteal credentials, intelligence, disrupt supply chains, prepare infrastructure for future conflict, and sometimes use ransomware as cover  
‘We’re too small’‘You’re connected to someone bigger’  
Only defence companies are targetsLaw firms, accountants, manufacturers, MSPs, logistics, healthcare, charities, fintech and engineering SMEs are all regularly targeted.  

The UK Government’s Cyber Security Breaches Survey 2025 found that 43% of UK businesses experienced a cyber breach or attack in the previous year, around 612,000 businesses.  OK, but why would a nation state target a 25-person business?

The “supply chain attack” model

Think of your SME as a trusted key into someone else’s business.

SME TypeWhy it’s attractive  
Managed Service ProvidersAccess to hundreds of customers through remote management tools  
Law firmsM&A documents, litigation, intellectual property, government contracts  
AccountantsFinancial records, payroll, tax credentials  
ManufacturersDefence supply chains, engineering drawings, OT systems  
Financial AdvisorsHigh-net-worth client information and payment systems  
Healthcare SMEsSensitive patient information and NHS connectivity

This is exactly why Cyber Essentials and the upcoming Cyber Security & Resilience Bill place greater emphasis on supply-chain security.

So which nation states pose the biggest risk to UK SMEs?

Comparison at a glance

ActorPrimary ObjectiveSME Targets  
ChinaEconomic espionageManufacturing, legal, biotech, technology, universities, MSPs  
RussiaDisruption, espionage, influenceEnergy suppliers, logistics, transport, IT providers, defence supply chain  
IranRetaliation, disruption, hacktivismUtilities, local government suppliers, legal firms, critical infrastructure suppliers  
North KoreaFinancial theftCryptocurrency, fintech, software companies, payroll providers  

Firstly China, regarded, by UK intelligence, as the most capable long-term cyber espionage threat against UK business.  They typically look at SME targets involved in:

  • Aerospace.
  • Advanced manufacturing.
  • Robotics.
  • AI.
  • Pharmaceuticals.
  • Universities.
  • Defence subcontractors.
  • Typical techniques

Why SMEs are targeted and why it matters:

A 20-person precision engineering company supplying parts into aerospace may unknowingly possess intellectual property valuable to a foreign state. This is particularly relevant to manufacturing SMEs like CNC engineering suppliers.

Russia is known for Supply Chain attacks and Disruption, their objectives:

  • Intelligence gathering.
  • Political disruption.
  • Critical infrastructure preparation.
  • Supply-chain compromise.

They may target:

  • MSPs.
  • Logistics firms.
  • Energy suppliers.
  • Transport providers.
  • Engineering consultancies.

The war in Ukraine has shown Russia routinely targets organisations supporting infrastructure rather than infrastructure alone.

Back to Iran, an increasing threat to UK Businesses.

Following escalating conflict involving Iran, Israel and the US, UK authorities warned businesses to prepare for Iran-linked cyber activity, including attacks against smaller organisations connected to essential services.  A recent UK example is a small UK gas-fired power plant that was temporarily shut down by suspected Iran-linked hackers, prompting government action to strengthen supply-chain cyber regulation.

They are known for:

  • Website defacement.
  • Credential theft.
  • Ransomware.
  • Industrial control system attacks.
  • Destructive malware.

Energy contractors, water suppliers, engineering companies, local authority suppliers and MSPs supporting infrastructure, are all targets.

North Korea is a little different as it is suspected that cybercrime funds the state, and unlike China and Russia, North Korea often attacks businesses primarily for money.

Fintech, cryptocurrency firms, payroll providers, software companies and defence contractors, are the main targets.

What do we need to on guard against and to look out for.  It is assessed that the most likely Nation-State attack paths into an SME are often related to:

Microsoft 365 is a common battlefield for SMEs.  Microsoft 365 identities are now the most commonly targeted asset because compromising M365 gives attackers:

  • Email.
  • OneDrive.
  • SharePoint.
  • Teams.
  • Contacts.
  • MFA reset opportunities.

Next comes AI which has changed Nation-State attacks.  For example, AI-powered phishing is now industrialised.  Before AI:

  • Poor grammar.
  • Obvious phishing.

But now:

  • Perfect English.
  • Company branding copied.
  • Deepfake voice messages.
  • Fake Teams meetings.
  • Fake invoices.

Attackers now impersonate CEOs, Solicitors, Bank staff, IT support and suppliers. NCSC has warned AI is increasing the sophistication and scale of attacks.

Nation state threats influence how Cyber Essentials maps to nation-state tactics and why v3.3 matters. The executive declaration requiring continuous assessment reflects the reality that attackers exploit newly introduced weaknesses throughout the year, not just during annual certification.

For UK SME Leaders the conversation has changed.  Cybersecurity is no longer just about avoiding ransomware. Nation-state activity means SME directors should think about the NCSC’s message that hostile-state cyber activity is increasing alongside geopolitical tensions, and SMEs are increasingly part of that threat landscape rather than outside it. I hope this helps somewhat in understanding just how much the threat landscape has changed and how much it is affected by world events. 

Leave a Reply

Your email address will not be published. Required fields are marked *

Scroll to top