Your accountant might be the last person you think of asking to protect your business from financial cybersecurity threats. But as Accountant and IT specialist Ross Nicol explains, they are exactly the right person to speak to in the face of increasing cybersecurity attacks on owner-managed SMEs.

Key takeaways: How SMEs can prepare for financial cybersecurity threats
- Owner-managed SMEs are targeted with financial cybersecurity threats because they often have fewer resources, less formal governance and weaker financial controls.
- Common financial cybersecurity threats are often preventable. This article demonstrates how issues such as misplaced trust in digital systems, weak internal controls, and limited staff training create risks.
- Reducing financial cybersecurity risk starts with strong financial processes. Practical measures can significantly reduce your business’s exposure to risk.
- Accountants can play a key role in countering financial cybersecurity threats through better business governance, financial controls, and by identifying vulnerabilities.
Why are owner-managed SMEs increasingly facing financial cybersecurity threats?
Assumptions increase risk, and that is especially true when it comes to financial cybersecurity threats. SME business owners and managers often assume that cyber criminals only target large businesses. In reality, small and medium-sized businesses are easier targets thanks to fewer resources and typically less formal business governance. Current data indicates that 50% of SMEs in the UK will experience a cyber attack of some form each year.
The challenge for owner-managed SMEs is how to combine technical cyber defences like anti-virus software with processes that safeguard financial data.
What are the common financial cybersecurity threats faced by owner-managed SMEs?
Though cyber attacks continue to become more sophisticated and elaborate, some financial cybersecurity threats are common to the majority of small and medium-sized businesses:
- Misplaced trust in digital systems: It is all too easy to assume anything digital, like an email, an invoice or a request to change bank details, is authentic (“It looked like a proper email”). Similarly, cloud-based accounting software has brought with it the assumption that they automatically protect against attempted fraud.
- Poor access management: With fewer resources, SMEs can often end up with poor access management. Think former employees still having access to financial systems because no one deleted them, or issues around shared user accounts (“Just use my login details”).
- A lack of internal controls and processes: As the previous examples highlight, without proper controls and processes in place, your systems can be wide open to financial cybersecurity threats because employees don’t know how to respond to them.
- Limited cybersecurity training and knowledge: A well-trained workforce is arguably a business’s strongest defence against financial cybersecurity threats. The opposite is most definitely true, and while the financial and time costs of training might feel painful, the alternatives are much worse.
Is your business’s financial data and transactions secure? Speak to the team at Drummond Laurie Chartered Accountants and let’s talk about how we can protect your financial data.
How can an accountant help protect my business against financial cybersecurity threats?
Good question, and the answer lies in why criminals are interested in your business in the first place. Simply put, they want your money and your financial data.

The key to understanding financial cybersecurity threats to owner-managed businesses lies in why criminals are interested in your business.
While we aren’t the right people to ask for advice about firewalls, we are the right people to help strengthen your financial systems. Drummond Laurie Chartered Accountants are experts in payment processes, financial controls and business governance. Meaning an accountant is exactly the right person to help identify weaknesses before they become costly mistakes.
How to deal with common financial cybersecurity threats
Based on the examples outlined earlier, here are some basic principles to follow if you are the owner of an SME:
- Digital systems do not automatically mean increased security: Consider this example: How would an email or text message request to amend bank details by a supplier be dealt with versus a phone call? Would the email/text message be assumed to be legitimate because it is digital? Would the phone call be considered a scam? Digital systems need to be approached with the same caution as more familiar threats.
- Get robust processes in place: Your employees need to know how to deal with cyber threats, and processes and procedures are the best way to achieve that. How should they deal with unsolicited requests for data? When can they divulge critical information, and what is the process? How do they report and respond to scam communications like phishing emails?
- Add basic controls: With processes and procedures in place, you can ensure basic controls are in place around financial data and transactions. Examples might include adding secondary approvals to transactions, double-checking with named supplier contacts if changes are requested, and enabling two-factor authentication.
- Train your team: Build the knowledge and awareness amongst your team about financial cybersecurity threats. Work with your accountant to establish proper financial processes and procedures. Consider the Cyber Essentials programme from the UK government or the free resources and advice provided by Cyber Scotland to boost knowledge.
Helping protect your business from financial cybersecurity threats
At Drummond Laurie, we continuously help clients face financial cybersecurity threats with confidence. Whether you want to establish new financial processes and controls, or revisit existing procedures, we are ready to help protect your financial data and transactions. We can also provide regular health checks of your financial processes and systems.
With experience built across a decade working with clients of all sizes – from sole traders to businesses with hundreds of employees – we are here to help you safeguard your business from financial cybersecurity threats.
For an initial discussion, get in touch with Ross Nicol.
Connect with Drummond Laurie Chartered Accountants on LinkedIn, Facebook and X.
About the author
Ross Nicol works closely with Drummond Laurie’s clients to support their accounting and financial systems and processes. An IT specialist with over 30 years of practical experience in accounting software, Ross is an expert on both Sage and Xero cloud accounting systems.