Most of the data security conversation is written for organisations that do not resemble the ones I spend my time with. It assumes a security team, a budget line with room in it, and a board that already treats risk as a standing agenda item. That is the world of the enterprise, and it is well served. The owner-managed business, the family firm turning over a few million, the founder-led company that has grown faster than its systems, is served far less well. It is also where a great deal of the economy’s data actually sits.
These businesses are not small versions of large ones. They have different constraints, different instincts, and a different relationship with risk. Pretending otherwise is why so much security advice bounces off them.
The mid-market is the soft underbelly
Attackers are commercially rational. They go where the return is highest for the effort involved, and the mid-market has become an obvious target. Large enterprises have spent a decade hardening themselves, and the smallest micro-businesses hold little worth stealing. The owner-managed firm sits in the awkward middle: enough data and money to be worth attacking, not enough defensive maturity to make it difficult.
The numbers bear this out consistently. Year after year, UK government breach surveys show that the majority of businesses experiencing a breach are not household names. They are ordinary companies whose exposure crept up on them while they were busy running the business. The manufacturer with decades of design files on an ageing server. The professional services firm holding client data it never catalogued. The distributor whose entire operation now runs through a handful of cloud accounts nobody has reviewed since they were set up.
What these businesses share is not carelessness. It is the absence of anyone whose actual job is to think about this. The finance director covers it when there is a spare afternoon. The IT provider handles what they are asked to handle and no more. Security falls into the gap between everyone’s remit, and gaps are exactly what attackers look for.
Why the standard advice fails here
Walk an owner-managed business through a full enterprise security framework and you will lose them by the second page. Not because they cannot follow it, but because it asks for resources they do not have and assumes a starting point they have not reached. The result is a common and damaging one: faced with advice that feels impossibly large, they do nothing at all.
This is the real failure in how our industry talks to smaller businesses. We present security as a destination that requires enormous investment to reach, when what these firms need is a sensible next step they can actually take. Perfect security is not on the table for anyone, at any size. Pretending it is only persuades a business owner that the whole thing is beyond them.
There is also a trust problem. Owner-managed businesses have usually been sold to badly at least once. They have been quoted for tools they did not need, frightened with statistics, and left with a contract they did not understand. By the time a genuine adviser reaches them, the scepticism is well earned. Rebuilding that trust means being honest about what matters and, just as importantly, what does not.
What “good enough” actually looks like
Good enough is not a lowering of standards. It is the recognition that a smaller business gets far more protection from doing the fundamentals properly than from buying sophisticated tools it cannot run. The unglamorous basics remain the ones that stop most attacks.
Multi-factor authentication across every account that offers it. This single control defeats the overwhelming majority of opportunistic attacks, and it costs nothing but the effort of turning it on. A patching routine that people actually follow, so known weaknesses are closed before they are exploited. Backups that are genuinely separated from the live environment and, crucially, tested, because a backup nobody has ever restored from is a hope rather than a plan. Sensible control over who can access what, so a single compromised account does not open the entire business. And enough awareness among staff that a suspicious email is questioned rather than clicked.
None of that is expensive. Most of it is a matter of discipline rather than spend. In the UK, the Cyber Essentials scheme captures these fundamentals well and gives a smaller business a clear, affordable target to work towards. I recommend it often, not as a badge for its own sake, but because it forces the basics into place and gives an owner a concrete sense of progress. It is a floor, not a ceiling, and it is the right floor for most.
The value of framing it this way is that it turns an overwhelming problem into a manageable one. A business owner who cannot contemplate a security programme can absolutely contemplate turning on MFA this month and sorting out backups the next. Momentum matters more than perfection.
Security as a business decision, not a technical one
The firms that get this right are the ones where the owner stops treating security as an IT issue and starts treating it as a business risk like any other. They do not need to understand the technology. They need to understand their own exposure: what data they hold, what it would cost them to lose access to it, and which handful of controls would move the needle most. That is a commercial judgement, and business owners make commercial judgements every day.
The role of a good security adviser in this market is not to sell fear or complexity. It is to translate. To take a genuine risk and express it in terms an owner can act on, then help them take the next sensible step rather than the entire journey at once. Do that honestly and the relationship compounds. The business that starts with the basics this year is the one ready for something more considered the year after.
The mid-market does not need to be told it is doing everything wrong. It needs to be shown that meaningful protection is closer, cheaper, and more achievable than it has been led to believe. Good enough, done properly and built on, is a perfectly respectable strategy. For most owner-managed businesses, it is the only one that will actually get done.

