Do Small Businesses Really Need Penetration Testing?

by Rebecca Sutton

Yes, penetration testing for small business owners in the UK is usually worth it. It is rarely about proving you are hack-proof. It is about showing a customer, an insurer or your own board that someone independent tried to break in. You get to say exactly what they found.

“We’re too small to be a target” is the wrong way round

Owners often assume attackers go after big names with big data. The government’s Cyber Security Breaches Survey 2025/2026 says otherwise. It found that 46% of small businesses and 42% of micro businesses reported a breach or attack in the past twelve months. That is close behind medium and large firms. The survey also flagged a rising trend of supply chain attacks. Criminals increasingly target a smaller, less defended supplier as the easiest way into a bigger client’s network.

Put plainly, being small is not protection. Being connected to bigger customers, holding their data or having access to their systems is what makes you interesting. Most small businesses have exactly that.

A small business owner working at a laptop after a penetration testing engagement

When a test is genuinely necessary right now

A few situations move penetration testing from “nice to have” to “do this soon”:

  • A customer’s procurement or security team has asked for evidence of testing, directly or through a supplier questionnaire.
  • You are pursuing Cyber Essentials Plus, which involves technical verification beyond a self-assessment questionnaire.
  • Your systems process payment data, health records or other sensitive personal information at any scale.
  • You have just shipped a new customer-facing website or portal that nobody outside the development team has checked.
  • Your cyber insurance renewal now asks whether, and how recently, you have tested your systems.

Any one of these is enough on its own. If two or three apply, treat it as urgent, not something to revisit next quarter.

When you can reasonably wait, or start smaller

Not every small business needs a full penetration test this month. Say you have no internet-facing systems beyond email and basic hosting, and nobody has asked for evidence of testing. In that case, a vulnerability scan plus a tidy-up of the basics will do more for your risk than a premature test. Think patching, multi-factor authentication and sensible access control. Save the deeper engagement for once you have something worth attacking properly. That means a live application, a customer portal, or genuine sensitive data on the network.

What “proportionate” actually means

The National Cyber Security Centre describes penetration testing as gaining assurance in a system’s security by attempting to breach it. It uses, in its own words, “the same tools and techniques as an adversary might.” The NCSC is also explicit that testing should validate your existing security work, not replace it. For a small business, that means scoping the test to what you actually expose to the internet. Think your website, your remote access, your customer-facing application. It does not mean paying for a sweep of infrastructure that does not exist yet.

A tester worth hiring will ask about your business model before your IP addresses. They will also push back on an oversized scope that burns your budget without matching your real risk.

The real cost of skipping it

The Breaches Survey found that among small and micro businesses, the costliest breaches, the top 5% of cases, ran to £4,000 or more. Reported revenue loss and reputational damage from breaches both rose year on year. Those figures do not capture the lost contract when a larger client’s due diligence turns up nothing to show them. For a small supplier, that can be the bigger loss. A scoped test, priced to what you actually need rather than a generic package, costs a fraction of that. Knowing what to budget for a penetration test before you ask for quotes makes it easier to compare providers fairly. It also gives you a report you can hand to a client or insurer.

The gap between exposure and preparation

What makes the case hard to argue against is not just the breach numbers. It is how far behind preparation still sits. The same survey found only 41% of small businesses had done a formal cyber risk assessment in the past year. That is down from 48% the year before. Just 22% had reviewed the cyber risk posed by their immediate suppliers, and board-level ownership of cyber security sat at 37% for small businesses. None of that is a criticism, most small firms are stretched thin and security competes with everything else. But it does mean something practical: penetration testing for small business owners is often the fastest way to close a gap that internal resource has not got to yet.

There is a genuine upside too. Micro businesses using an external cyber security provider rose from 39% to 44% year on year. Two-factor authentication adoption among micro businesses climbed from 35% to 43% over the same period. Small businesses are visibly getting better at this. A penetration test is simply how you find out whether your improvements are holding up. It shows whether they survive a real attempt to break them.

This is exactly the gap Aardwolf Security spends most of its time closing for small UK businesses. We run a scoped, CREST-aligned penetration test sized to what you actually use, not a template built for a much bigger organisation. If you want an honest read on where you stand, get in touch. We will talk you through it before you commit to anything.

What to ask before you sign anything

Before agreeing a scope or a price, ask a prospective provider four things. First, what qualifications the individual testers hold, not just the company’s accreditation. Second, ask what a sample report looks like. A report you cannot act on is worth little, regardless of how thorough the testing was. Third, whether a retest of critical and high findings is included or charged separately. Fourth, how they handle anything urgent they find, rather than waiting for the final report. A provider who answers all four clearly, without pushing a bigger scope than you asked for, is usually a safe bet. One who dodges the qualifications question is not.

Frequently asked questions

Do UK small businesses have to do penetration testing by law?

Generally no, not as a direct legal duty. It is often required indirectly, through contracts, Cyber Essentials Plus or insurance conditions.

Is a vulnerability scan enough instead?

For a business with minimal internet-facing systems and no specific requirement, a scan plus good basic hygiene can be enough for now. Once you have something worth attacking, a proper test earns its cost.

How do I know if my business is a realistic target?

Hold customer data, connect into a larger organisation’s systems, or run a public-facing website or app, and you are a realistic target. Headcount does not change that.

Will a penetration test disrupt my business?

A well-scoped test is agreed in advance with your provider, including timing. Day-to-day operations are not affected, and anything higher-risk is flagged and scheduled around your needs.

What should I do with the report once I have it?

Triage findings by real-world risk. Assign an owner to each fix. Then book a retest of the serious issues once they are patched, rather than filing the report away.

Does a clean report mean I am now secure?

It means the tester found no exploitable path on the day of testing, within the agreed scope. New vulnerabilities appear constantly, so annual retesting, alongside ongoing patching and monitoring, matters more than any single clean report.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like