Small businesses in Stone face the same cyber security risks as larger companies, from phishing emails to compromised accounts and fraudulent payment requests.
Any Stone business using online ordering and card payments, managing invoices by email, or taking bookings online is potentially vulnerable. The risks extend to any operation that stores customer information, booking details, invoices, supplier records or access to banking and payment services online.
How common are cyber attacks?
The latest UK Government Cyber Security Breaches Survey, published in April 2026, found that 43% of businesses had identified some form of cyber security breach or attack during the previous 12 months. Among micro businesses with fewer than ten employees, the figure was 42%.
Phishing remained the most commonly identified type of attack. It was experienced by 38% of businesses overall and by 88% of businesses that had identified any type of breach or attack.
Common attack methods
Phishing attempts are designed to persuade someone to open a link, reveal information, make a payment or sign into a fake website. They can imitate messages from suppliers, delivery companies, banks, technology providers or colleagues.
While some phishing emails contain poor spelling and obvious warning signs, convincing phishing emails can look much like ordinary messages arriving during a busy working day.
Supplier emails present another risk. A fraudulent message that appears to come from a genuine supplier could ask a business to use different bank details for its next payment.
Multiple routes for unauthorised access
Most businesses now rely on a mixture of email, websites, online accounts, payment systems and cloud services. Each account is another potential route for someone attempting to gain unauthorised access, particularly if passwords are reused or software and website systems are not kept up to date.
Personal phones and other devices used for work can also make security harder to manage if there is no agreed approach to passwords, updates and access to business accounts.
Staff reporting and IT responsibility
Having a simple process for staff to report suspicious messages can be as important as the technical measures being used.
A small business will not necessarily have a dedicated member of staff responsible for its technology or cyber security. The latest government survey found that just 3% of micro businesses had somebody specifically in an IT role looking after cyber security. Some businesses instead relied on owners, managers or outside providers.
Businesses should know in advance who should be contacted if an account is compromised or something unusual happens, and which systems are most important to protect.




