On 21 November 2024, Teiss Talk host Thom Langford was joined by Steven Furnell, Professor of Cyber Security, University of Nottingham; Jean Carlos, VP of Information Security, AutogenAI; Stephanie Lynch-Ozanar, Education and Awareness Specialist, Co-Op; and Kev Eley, VP of UKI, Exabeam
Thames, the UK’s largest water and waste treatment company, is on a “knife-edge” according to sources, with its resilience in doubt because it depends on an array of creaking – often Victorian – infrastructure. Moreover, Thames confirmed that it still uses Lotus Notes, but a source close to the company said that it was only for “databases” and not “critical” systems. Another example for obsolete IT infrastructure is the fact that more than half of Windows in the UK are Windows10, which won’t be supported from next year on.
SME is a broad term that covers both micro businesses and dynamically growing fintechs with around 100 employees. Whether a business outsources cyber security or does it in-house depends on its size too. Small enterprises tend to do the latter, then they outsource it as they get bigger and, when they reach the medium enterprise size, they usually bring some of the most critical aspects back in-house. They may also have a different level of recognition about sensitive data, which also depends on how regulated the sector is where they operate. There are rich resources of cyber security guidance on the internet tailored to various levels of familiarity with the field ranging from awareness raising to actionable advice. It’s key for these messages to be jargon-free in order not to discourage SMEs from reading them. SMEs, however, tend not to deal with cyber security until an incident happens to them or if it becomes strategically key for them to comply – for example, with Cyber Essentials.
Thanks to their low margins, a cyber attack may have a devastating impact on the future of an SME. There is often a culture of fear in SMEs regarding cyber threats, so it makes sense to bring cyber security more to life for them. To make staff more confident, you need to make them aware that they will be supported in all circumstances. You don’t necessarily need a functional security programme to improve the business’s cyber security posture if you have a spirit of openness and transparency about it, which also encourages learning.
Often, just a general cyber hygiene can help in a micro or small enterprise to improve security posture, which are practices that employees can leverage in their personal lives too. It’s common that SMEs often can’t afford to have an incident response playbook either, although medium sized ones should already have some automated capabilities that can help them detect and respond to malicious activity to stay safe. To identify your crown jewels, make a list of the people, technology and processes that are key to generating your revenue.
Look out for early warning signs that suggest that you are going to be attacked.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543