Log in
Home / Publications / No. 051
Most security writing describes threats aimed at large organisations. Here are the five that actually reach small and medium businesses, and what stops each.
Position as at August 2026
The most common, and the most expensive per incident.
An attacker gets into an email account somewhere in the chain, reads quietly for weeks, then sends a normal-looking message changing bank details for the next payment.
What stops it: verify every bank detail change by phone, on a number you already held. Two minutes, and it defeats the attack because the attacker has the email and not the phone.
An email that appears to come from the owner, to someone in finance, asking for an urgent payment. Usually while the owner is travelling and hard to reach.
The pressure is deliberate. So is the timing.
What stops it: a rule that any payment request arriving by email is verified by voice, regardless of who appears to have sent it, with no exception for urgency.
Your files get encrypted and payment is demanded.
Paying is unreliable and marks you as a business that pays. Your real options are decided by whether you can restore from backup, and that is decided months earlier.
What stops it: a backup that is not permanently connected, and that you have tested restoring. Anything permanently connected gets encrypted alongside everything else.
A convincing email leads to a convincing login page. You enter your password. They now have it.
What stops it: two-factor authentication, which makes a stolen password insufficient on its own. And checking the address bar before entering credentials anywhere.
Not an attack on your money. An attack on your reputation and your search rankings.
Attackers place hidden pages on legitimate business websites to rank for unrelated terms. The owner does not notice because their own pages look fine.
What stops it: keeping the website platform and its plugins updated, removing plugins you do not use, and periodically searching for your own domain to see what actually appears.
If you host with a shared provider, understand that a neighbouring site being compromised can affect you.
Four of the five arrive by email and depend on a person acting normally under mild time pressure.
The technical measures matter. The procedural ones matter more, because the attack is aimed at a routine task rather than at your systems.
Who to call at the bank, and how fast recall has to be attempted. Where the backups are and who can restore them.
Who is told, in what order.
Whether you can operate at all while systems are unavailable, and for how long.
Deciding these during an incident wastes the hours that matter most.
Your ledger holds your customer list, margins, bank details and payroll. Treat access to it the way you treat access to cash.
We see the first two attempted against clients regularly. If the phone verification rule is not written down in your business, that is the highest value change available to you this week.
Have a question on this?
AskCALX searches the official corpus and answers with the article quoted, word for word.
Newsletter
Latest in UAE business, tax and technology, once a month.
Thank you, you are on the list.
Office 1316, Aspin Commercial Tower
Sheikh Zayed Road, P.O. Box 10415, Dubai
Open in Google Maps →