What Cybersecurity Actually Looks Like Right Now

May 01, 2026By Jay Kells
Jay Kells

What I'm Actually Seeing Change

Ask anyone whether cybercrime feels closer to home than it did five years ago, and I'd put money on the answer being yes. I don't say that to alarm you, I say it because it's true and because the shape of the problem has shifted. It isn't just banks and government departments in the firing line anymore. It's the hairdresser taking bookings through an app, the family running a market stall from their phone, and the ordinary person doing the weekly shop online from the sofa.


Small businesses everywhere have grown into genuine tech and digital operations over the last decade, and that's brilliant news for local economies. More businesses online means more jobs and more opportunity. It also means more doors for criminals to try, which is the part nobody puts on the tourist board. What's changed most in the years I've been doing this isn't the sophistication of the scams themselves, it's how ordinary the targets have become. That shift matters because it changes who needs to be paying attention. Cybersecurity used to feel like something for IT departments and big corporations to worry about, and now it's genuinely something every business owner and every household needs a basic handle on, whether or not technology is their thing.


The Scams I'm Seeing Hit Local Businesses Hardest


The pattern I see most often with small businesses is invoice fraud. A criminal gets into an email account, watches quietly for weeks, then sends a fake invoice or a change of bank details message at exactly the moment a payment is due. It looks completely normal because it's sitting inside a real email thread. I've had clients nearly lose four figures to this exact trick, and the only thing that saved them was picking up the phone to double check before paying. If you want to know what these emails actually look like in the wild, I've broken it down properly in my guide to spotting a phishing email before you click anything.


Right behind invoice fraud is the fake courier text, the your parcel couldn't be delivered message that leads to a cloned payment page. I wrote a whole piece on the online shopping scams I warn shoppers about, and the delivery scam is still the one catching the most people out. What makes both of these so effective is timing, they land right when you're already expecting an invoice or a delivery, so your guard is down before you've even opened the message.


Why Small Businesses Are Still the Soft Target


Here's the uncomfortable truth. Bigger companies have IT teams, security budgets, and someone whose entire job is worrying about this stuff. A hairdresser, a plumber, or a small online shop usually has none of that. They've got a laptop, a phone, and a to-do list a mile long. Criminals know this, and they treat small businesses as the easy option rather than the interesting one.

Small Liverpool shop owner standing at her open shopfront, representing the independent businesses most exposed to cybercrime


I put together a longer piece on how I stay ahead of cybercriminals if you want the fuller picture, but the short version is that you don't need a security team to be well protected. You need a handful of habits done consistently, which is exactly what the next bit covers. Most of the small businesses I've worked with weren't hit because they did something reckless, they just never got round to the basics, and that's the gap I want to close in the rest of this piece.


The Basics I Keep Coming Back To


Whatever changes in the wider landscape, the fundamentals barely move, which is honestly good news because it means you don't need to relearn your entire approach every few months. A proper password manager, not sticky notes or the same password everywhere, closes off the single biggest door criminals walk through. Two factor authentication closes off most of what's left. If you're working from cafes, co-working spaces, or public wifi , a VPN like NordVPN keeps that traffic private on networks you don't control.


None of this is complicated once it's set up, and I go through all of it, along with securing a home network, step by step over in the Safety Toolkit. None of it takes long to set up, and once it's done you can mostly stop thinking about it, which is the whole point.


Where I Think This Is Heading


AI is going to make scam messages harder to spot, not easier, because the spelling mistakes and clunky phrasing that used to give the game away are quietly disappearing. That's the honest, slightly uncomfortable truth about where things are heading. The flip side is that the basics I've just covered still work regardless of how convincing the scam looks, because they don't rely on you spotting a fake, they rely on a criminal not being able to get in even if you do click the wrong thing.


If you want a proper national view alongside my mine, Get Safe Online is a solid, independent resource worth bookmarking. And if you'd rather just talk it through with an actual person instead of reading another article, get in touch and I'll point you in the right direction. Either way, the goal is the same: fewer people caught out, and a bit more confidence every time something lands in your inbox that doesn't quite sit right.