A new report from Gallagher finds that a significant proportion of UK SMEs are exposing themselves to severe and lasting impacts of a crisis incident, through lack of preparation, protocols protection and review.
Crisis Resilience

Crisis incidents, such as cyber-attacks, extortion, industrial espionage and terrorism, are costing UK SMEs billions of pounds a year.Furthermore, subsequent trading paralysis is putting thousands at risk of collapse in their aftermath.

According to research by Gallagher, UK SMEs paid out an average £6,416.50 last year to deal with crisis incidents. This equates to a combined business cost of £8.8bn in 2018 alonei.

Launched today, Gallagher’s report — SMEs In An Age Of Crises: The need to bolster resilience to protect the UK’s economic heartland — examines the scale of crisis incidents affecting UK SMEs; the time and cost impact of these events; the risks and vulnerability created by complacency; the key role played by crisis protocols, response planning and specialist insurance protection; and the importance of proactive planning to aid recovery.

In a poll of 1,120 UK SMEs, nearly a quarter (24%) confirmed they were affected by a crisis event last year, equating to 1.4 million across the country – a 5% increase from 2017. One in six (17%) SMEs affected by a crisis spent £10,000 or more to combat crises, with nearly one in 10 (9%) paying out in excess of £20,000.

A quarter of SMEs (23%) said they would survive for less than a month if rendered unable to trade by a crisis incident. Based on these findings, we estimate that nearly 57,000 UK SMEs could be at risk of collapse this year if unable in the aftermath of a crisis event.

Commenting on the findings, Paul Bassett, Managing Director of Crisis Management at Gallagher, said: “Our research illustrates the scale of the challenge facing UK SMEs. When it comes to crises, cyber and IT security clearly represent a “soft underbelly” of businesses that together account for more than 99% of private sector firms. Given that the UK economy is heavily tilted towards services, cyber-attacks and data breaches evidently present a growing and grave threat to small and medium-sized businesses.

“Alongside regularly reviewing their crisis preparedness, response plans and forms of protection, such as insurance, it is critical UK SMEs also assess their ability to survive in the event of a major crisis incident when the risk of serious disruption and protracted recovery process is very real.

“The cost of a crisis is by no means the only consideration. Duration is key — especially with a quarter (23%) of UK SMEs admitting they could survive for less than a month if unable to trade following an incident. For companies with tight margins and limited working capital, even a relatively short-term denial of access to premises or systems paralysis could be a crippling, possibly fatal, blow.

“We urge all businesses to ensure they have the crisis cover and plans in place to strengthen their ability to anticipate, prevent, respond and recover from a major security incident —but also have access to emergency funds, 24/7 crisis response consultants, post-incident counselling and business recovery advice, in order to stay solvent and help them and their people recover quickly.”

The most prevalent crisis experienced by UK SMEs last year was a cyber-attack, data breach or cyber extortion incident, which accounted for 15% of all events. Financial services sustained the highest number of attacks by a significant margin. More than a quarter (27%) of financial services SMEs surveyed were hit by this form of crisis in 2018.

Cyber-attacks, data breaches and cyber extortion also represent the areas of greatest concern for companies in 2019. Half (50%) of UK SMEs are most concerned about a cyber crisis taking place this year. Denial of access and business interruption was the second most concerning area, with one in 10 (11%) citing this as a major risk.

Commenting on the epidemic of cyber incidents, Tom Draper, Cyber Practice Leader at Gallagher, said: “The prevalence of cyber-attacks against UK SMEs has reached a tipping point – companies ignore these risks at their own peril. Ransomware has become relatively commonplace and pay outs to demands are often met simply in order to resume trading. Failure to comply can result in a crippling period of business interruption, which in many cases, leads to businesses collapsing.

“Data breaches leading to compromised customer data are also proving a major issue for small businesses. Such incidents are damaging in themselves, due to possible cyber fraud and the significant reputational fallout from having to inform customers of a data breach, but SMEs may also find themselves facing significant fines under GDPR. The best way to survive - and thrive - in the aftermath of a cyber incident is to have planned ahead, to ensure that you are able to respond swiftly to an emerging crisis, and to purchase effective cover through a broker to protect your assets and provide expert counsel in the event of an incident.”

View the report here

i There were 5.7 million SMEs in the UK in 2018 according to government statistics published on 12 December 2018. 24% experienced a crisis event, equating to 1.4 million companies.

*About the research

The research cited in this release is based on quantitative online surveys, run by YouGov on behalf of Gallagher, canvassing the views of 1,120 senior decision makers from small and medium-sized enterprises (defined as having 0 to 250 employees). The fieldwork was conducted between 2nd and 18th January 2019.