Access inspiring articles and case stories | navigator

SMEs are more vulnerable than ever | kompasbank navigator

Written by Joachim Hancke | Nov 28, 2025, 9:08:11 AM

SMEs have increasingly become primary targets for hackers, precisely because they often have fewer resources and weaker security measures than larger organisations. A single ransomware attack – where hackers encrypt a company’s data and demand payment to restore access – can paralyse operations for days or even weeks and result in significant financial losses.

Yet, an analysis by the Danish Emergency Management Agency (December 2024) reveals that approximately 40% of Danish SMEs have a digital security level that does not align with their risk profile. At the same time, it reveals that 15% still have not implemented even the most basic security measures, such as regularly updating operating systems and performing routine data backups – measures that form the foundation of basic cybersecurity.

The cyber threat is accelerating – and anyone can be hit

The increasing digitalization has made the cyber threat both more complex and extensive. The financial sector, in particular, is experiencing massive pressure from cybercriminals, but this development is also increasingly affecting companies in other industries. According to Berthold Barodte, Senior Vice President in Mastercard’s security solutions division, Mastercard detects and mitigates around 200 cyberattacks per minute — a clear indication of the scale of the threat.

Barodte points out that artificial intelligence (AI) has significantly changed the rules of the game. The technology makes it easier for hackers to enhance the credibility, speed, and precision of their attacks, making each one increasingly sophisticated. At the same time, the phenomenon of cybercrime-as-a-service is growing, with cyberattack tools being offered on the dark web, making advanced attacks accessible to far more people.

A clear example of the severe consequences of a cyberattack emerged in late August 2025, when Jaguar Land Rover (JLR) was targeted by a large-scale attack. The company was forced to shut down its IT systems and halt production at its factories for nearly four weeks. The attack affected the entire organisation – from car manufacturing and spare parts to the dealer network. According to experts, it is considered the most economically damaging cyberattack in British business history, with estimated losses of around £1.9 billion (approximately DKK 16.5 billion).

This incident clearly shows how vulnerable even global industry leaders can be when cyber threats strike, while also underscoring the importance of robust security measures, contingency plans, and ongoing risk assessments.

Many SMEs lack basic security measures

The Danish Emergency Management Agency points out that many companies still face challenges in securing access to their systems. The report shows that many SMEs still use passwords that do not meet the recommended security requirements. This makes their systems significantly more vulnerable, as weak authentication gives cybercriminals much easier access to critical systems and sensitive data.

Even more concerning is that 60% of companies estimate that they would struggle to maintain operations if their core systems were hit by a cyberattack. This indicates that many still lack both effective contingency plans and adequate technical security measures to handle a serious attack.

Taken together, this combination of missing basic security measures, limited resources, and insufficient contingency planning makes small and medium-sized businesses particularly vulnerable to cyberattacks. At a time when digital risks are increasing rapidly, it is therefore crucial that SMEs prioritise cybersecurity strategically and establish a more systematic and long-term approach to digital protection.

Cybersecurity starts with people and a strong culture

Cybersecurity does not begin with technology; it begins with people. A security-aware culture, where employees understand their role in protecting the company’s data, is the first and most important line of defence. Training in IT security, increased awareness of phishing, and clear guidelines for handling data and access rights can make a crucial difference.

At the same time, companies should implement basic yet effective security measures, including two-factor authentication, continuous system updates, and regular backup routines. These do not require large investments, but they do require a deliberate decision to prioritize security as an integrated part of the company’s strategy.

Digital resilience is not only about preventing attacks, but also about the ability to quickly and safely restore operations in the event of an incident. At a time when trust and data security are crucial competitive parameters, cybersecurity is not just a technical necessity, but a prerequisite for growth and long-term success.

You can read more about how to increase the security level in your company here.