
When we talk about cyber scams and attacks on SMEs, we concentrate on threats from cyber criminals because, quite simply, they are not just the perceived threat, but often the actual threat. However, there is another category which we tend not to connect with SMEs, but rather with the corporate and government worlds, and that is the nation state threat. With what’s happening in the world today, maybe we should be keeping a weather eye on that potential threat.
Let’s take Iran for example, research suggests that they have been far more successful at espionage and disruption than at causing strategic damage. Since the conflict escalated (initial Israel-Iran fighting in June 2025, followed by direct US-Israeli operations against Iran in February 2026), Iran’s cyber organisations have launched thousands of attacks against Israel, the US and Western allies. However, most have been contained, short-lived, or psychological in effect rather than strategically decisive. Cyber defences have largely prevented catastrophic infrastructure failures. This suggests that there hasn’t been much to worry about, from an SME perspective. However, there is much more to it than that.
For UK SMEs, this is one of the biggest shifts in cybersecurity over the past 2–3 years. Nation-state actors are no longer just targeting governments and FTSE 100 companies. They’re increasingly targeting SMEs because SMEs are the easiest route into larger organisations, valuable data, and critical UK supply chains.
The UK National Cyber Security Centre (NCSC) has repeatedly warned that the most serious cyber threats facing the UK now come from Russia, China, Iran and North Korea, and that businesses of all sizes need to prepare for attacks linked to geopolitical conflict.
The Nation-State Cyber Threat Landscape for UK SMEs (2026)
A Board-level takeaway is that your business is probably collateral damage, not the primary target. You’re the route into your larger customers. SMEs are targeted because they are easier to compromise than large enterprises and often have trusted access into customers, suppliers, and public-sector organisations.
| What SMEs worry about | What nation states actually do |
| Steal money with ransomware | Steal credentials, intelligence, disrupt supply chains, prepare infrastructure for future conflict, and sometimes use ransomware as cover |
| ‘We’re too small’ | ‘You’re connected to someone bigger’ |
| Only defence companies are targets | Law firms, accountants, manufacturers, MSPs, logistics, healthcare, charities, fintech and engineering SMEs are all regularly targeted. |
The UK Government’s Cyber Security Breaches Survey 2025 found that 43% of UK businesses experienced a cyber breach or attack in the previous year, around 612,000 businesses. OK, but why would a nation state target a 25-person business?
The “supply chain attack” model

Think of your SME as a trusted key into someone else’s business.
| SME Type | Why it’s attractive |
| Managed Service Providers | Access to hundreds of customers through remote management tools |
| Law firms | M&A documents, litigation, intellectual property, government contracts |
| Accountants | Financial records, payroll, tax credentials |
| Manufacturers | Defence supply chains, engineering drawings, OT systems |
| Financial Advisors | High-net-worth client information and payment systems |
| Healthcare SMEs | Sensitive patient information and NHS connectivity |
This is exactly why Cyber Essentials and the upcoming Cyber Security & Resilience Bill place greater emphasis on supply-chain security.
So which nation states pose the biggest risk to UK SMEs?
Comparison at a glance
| Actor | Primary Objective | SME Targets |
| China | Economic espionage | Manufacturing, legal, biotech, technology, universities, MSPs |
| Russia | Disruption, espionage, influence | Energy suppliers, logistics, transport, IT providers, defence supply chain |
| Iran | Retaliation, disruption, hacktivism | Utilities, local government suppliers, legal firms, critical infrastructure suppliers |
| North Korea | Financial theft | Cryptocurrency, fintech, software companies, payroll providers |

Firstly China, regarded, by UK intelligence, as the most capable long-term cyber espionage threat against UK business. They typically look at SME targets involved in:
Why SMEs are targeted and why it matters:
A 20-person precision engineering company supplying parts into aerospace may unknowingly possess intellectual property valuable to a foreign state. This is particularly relevant to manufacturing SMEs like CNC engineering suppliers.

Russia is known for Supply Chain attacks and Disruption, their objectives:
They may target:
The war in Ukraine has shown Russia routinely targets organisations supporting infrastructure rather than infrastructure alone.

Back to Iran, an increasing threat to UK Businesses.
Following escalating conflict involving Iran, Israel and the US, UK authorities warned businesses to prepare for Iran-linked cyber activity, including attacks against smaller organisations connected to essential services. A recent UK example is a small UK gas-fired power plant that was temporarily shut down by suspected Iran-linked hackers, prompting government action to strengthen supply-chain cyber regulation.
They are known for:
Energy contractors, water suppliers, engineering companies, local authority suppliers and MSPs supporting infrastructure, are all targets.

North Korea is a little different as it is suspected that cybercrime funds the state, and unlike China and Russia, North Korea often attacks businesses primarily for money.
Fintech, cryptocurrency firms, payroll providers, software companies and defence contractors, are the main targets.
What do we need to on guard against and to look out for. It is assessed that the most likely Nation-State attack paths into an SME are often related to:

Microsoft 365 is a common battlefield for SMEs. Microsoft 365 identities are now the most commonly targeted asset because compromising M365 gives attackers:
Next comes AI which has changed Nation-State attacks. For example, AI-powered phishing is now industrialised. Before AI:
But now:
Attackers now impersonate CEOs, Solicitors, Bank staff, IT support and suppliers. NCSC has warned AI is increasing the sophistication and scale of attacks.
Nation state threats influence how Cyber Essentials maps to nation-state tactics and why v3.3 matters. The executive declaration requiring continuous assessment reflects the reality that attackers exploit newly introduced weaknesses throughout the year, not just during annual certification.
For UK SME Leaders the conversation has changed. Cybersecurity is no longer just about avoiding ransomware. Nation-state activity means SME directors should think about the NCSC’s message that hostile-state cyber activity is increasing alongside geopolitical tensions, and SMEs are increasingly part of that threat landscape rather than outside it. I hope this helps somewhat in understanding just how much the threat landscape has changed and how much it is affected by world events.