Home  /  Publications  /  No. 051

BUSINESS·19 OCT 2022·3 min read

The Cyber Threats That Reach Businesses Like Yours

Most security writing describes threats aimed at large organisations. Here are the five that actually reach small and medium businesses, and what stops each.

Position as at August 2026

1. Supplier bank detail fraud

The most common, and the most expensive per incident.

An attacker gets into an email account somewhere in the chain, reads quietly for weeks, then sends a normal-looking message changing bank details for the next payment.

What stops it: verify every bank detail change by phone, on a number you already held. Two minutes, and it defeats the attack because the attacker has the email and not the phone.

2. Chief executive impersonation

An email that appears to come from the owner, to someone in finance, asking for an urgent payment. Usually while the owner is travelling and hard to reach.

The pressure is deliberate. So is the timing.

What stops it: a rule that any payment request arriving by email is verified by voice, regardless of who appears to have sent it, with no exception for urgency.

3. Ransomware

Your files get encrypted and payment is demanded.

Paying is unreliable and marks you as a business that pays. Your real options are decided by whether you can restore from backup, and that is decided months earlier.

What stops it: a backup that is not permanently connected, and that you have tested restoring. Anything permanently connected gets encrypted alongside everything else.

4. Credential theft through a fake login page

A convincing email leads to a convincing login page. You enter your password. They now have it.

What stops it: two-factor authentication, which makes a stolen password insufficient on its own. And checking the address bar before entering credentials anywhere.

5. The compromised website

Not an attack on your money. An attack on your reputation and your search rankings.

Attackers place hidden pages on legitimate business websites to rank for unrelated terms. The owner does not notice because their own pages look fine.

What stops it: keeping the website platform and its plugins updated, removing plugins you do not use, and periodically searching for your own domain to see what actually appears.

If you host with a shared provider, understand that a neighbouring site being compromised can affect you.

The pattern across all five

Four of the five arrive by email and depend on a person acting normally under mild time pressure.

The technical measures matter. The procedural ones matter more, because the attack is aimed at a routine task rather than at your systems.

What to have decided in advance

Who to call at the bank, and how fast recall has to be attempted. Where the backups are and who can restore them.
Who is told, in what order.
Whether you can operate at all while systems are unavailable, and for how long.

Deciding these during an incident wastes the hours that matter most.

What this means for your accounting data

Your ledger holds your customer list, margins, bank details and payroll. Treat access to it the way you treat access to cash.

Where we fit

We see the first two attempted against clients regularly. If the phone verification rule is not written down in your business, that is the highest value change available to you this week.

Have a question on this?

Ask a tax question. The law answers.

AskCALX searches the official corpus and answers with the article quoted, word for word.

Ask a tax question →

Let’s get startedYour engagement

One engagement letter. One file. Every deadline met.


Let’s talk!

Newsletter

Stay up to date with our newsletter.

Latest in UAE business, tax and technology, once a month.

Thank you, you are on the list.

Visit us

Office 1316, Aspin Commercial Tower
Sheikh Zayed Road, P.O. Box 10415, Dubai
Open in Google Maps →

© 2026 CALX International Auditing of Accounts L.L.C. · All rights reserved · Privacy