
Ricardo Ferreira at Fortinet asks how SMEs should be supported in the light of the UK’s Cyber Security and Resilience Bill
Cyber-crime is a growing threat, prompting governments to introduce legislation to help combat potentially large-scale attacks. The EU’s NIS2 law, for example, aims to enhance the cyber- resilience of critical infrastructure and networks across the EU in energy, transport, water, banking, finance and healthcare.
Similarly, the UK’s Cyber Security and Resilience Bill will strengthen protections, but it may disproportionately impact smaller businesses – which make up 99% of the UK’s companies – potentially causing more harm than good.
The Bill aims to improve the UK’s defences, ensuring essential digital services and critical infrastructure are protected. With cyber-attacks now targeting critical sectors, such as healthcare, defence and public services, the Bill’s focus on the public sector will be key to protecting the nation as a whole.
The Bill will also help to expand the remit of regulation to protect more digital services and supply chains, filling critical defence gaps. This will prevent attacks, similar to one which recently impacted NHS trusts and exposed patient data, and further strengthen the UK against the growing cyber- security threat.
While the UK government has made strides to protect critical sectors and strengthen overall defence methods, its focus has primarily been on large businesses and government-funded organisations, such as the NHS. This has left small and medium-sized enterprises (SMEs) increasingly vulnerable, despite their crucial role in the economy.
Cyber-security legislation often fails to provide clear, actionable guidance on how businesses should implement new rules, meaning SMEs must navigate challenges on their own.
For SMEs, this is more than just a compliance issue – it’s a wider business challenge. With limited resources in terms of funding, staff and training, many smaller businesses are struggling to create and execute a cyber -security strategy that meets regulations and suits their systems.
The high costs associated with implementing robust cyber-defences and hiring trained personnel often prove prohibitive. A lack of funds also disproportionately impacts any SME faced with non-compliance fines, unlike larger businesses which have more financial flexibility.
SMEs are also challenged with skills and resourcing gaps. Often having paired back IT teams and limited legal support, many face difficulties in meeting the demands set out by new legislation – the Cyber Security and Resilience Bill is no different.
SMEs need help – something the UK government must immediately acknowledge, especially as the Cyber Security and Resilience Bill comes into full effect. With many businesses unprepared for the legislation, a one-size-fits-all approach won’t work.
Businesses of all sizes face unique compliance challenges and the government must take proactive steps to help SMEs prepare by providing practical resources and assistance, for example, toolkits, financial backing and dedicated support channels.
One key area where the government can make an impact is awareness and training. Many SME owners lack a technical background and may struggle to understand the complexities of new regulations.
As such, the government and industry bodies have a responsibility to organise free or subsidised sessions to educate business owners on the specifics of the Cyber Security and Resilience Bill. These sessions should outline simple and actionable steps tailored to different industries, and clear guidance on how to implement these into a business. This will provide SMEs with the tools they need to ensure compliance.
Additionally, compliance with the new legislation should be financially supported. While larger corporations have legal teams to translate the technical terms of the legislation and large IT and cyber-security functions to detect and report incidents, SMEs lack these capabilities – particularly as many cut spending in the current macroeconomic climate.
Grants and subsidies must be on offer to help small businesses invest in the right cyber-security infrastructure and training. If failure to comply with the regulations could lead to fines, financial aid is crucial in ensuring SMEs are not left behind.
Overall, there is still work to be done ahead of the Cyber Security and Resilience Bill coming into full force. With many small businesses not having the right infrastructure, teams, talent or funding, the UK government must ensure it is properly equipping them to meet the necessary standards.
Ricardo Ferreira is EMEA Field CISO at Fortinet
Main image courtesy of iStockPhoto.com and Supatman
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543