By Russell Lawson, ISO consultant, lead auditor and founder of The Compliance Companion - the practical platform that helps businesses build ISO 9001, ISO 14001, ISO 45001 and ISO 27001 systems using real-world templates, AI-powered tools and guided support. Through years of consultancy and audit work, Russell has seen that the businesses most exposed to risk are often not the largest or most complex, but the ones that assume they are too small to be targeted.
For a lot of small businesses, cyber security still feels like something that matters more to big brands, large public bodies or highly regulated sectors. It can seem like a specialist issue for someone else. But the current direction of travel says otherwise.
The UK government warned business leaders in April 2026 that AI-driven cyber threats are changing the risk landscape and called on every business to strengthen basic cyber hygiene and leadership oversight.
At the same time, the NCSC continues to position practical cyber resilience as essential for small and medium-sized organisations, not just enterprise-scale firms.

That message matters because many smaller organisations are still underestimating their exposure. The government’s Cyber Security Breaches Survey 2025/2026 found that only 41% of small businesses had carried out a cyber security risk assessment, down from 48% the year before.
That is a worrying number in its own right, but it becomes even more significant when set against the wider push from government and the NCSC for stronger resilience in the face of fast-evolving threats.
This is exactly why cyber risk assessment is becoming such an important topic. Not because it sounds good in a policy document, but because it is one of the clearest ways for a business to move from vague concern to sensible action.
In my experience, this is where many organisations either gain real control over their information security or realise they have been relying too heavily on assumptions.
A cyber risk assessment should not be treated as a paperwork exercise. It is not there to make an auditor happy, and it is not just another spreadsheet to update once a year. Done properly, it is the process that helps a business work out what it needs to protect, where the real weaknesses are, what could go wrong, and what should be prioritised first.
That is why it sits so naturally within ISO 27001. The standard is not really asking you to predict every possible cyber event. It is asking you to understand your risks in a structured way and make sensible, proportionate decisions in response.
One of the reasons small businesses avoid this is because they assume a cyber risk assessment has to be highly technical. In reality, the starting point is often much simpler. What systems do you rely on most? What data would cause the most damage if it was lost, leaked or unavailable? Which suppliers or cloud tools create dependency? Who has access to what, and how often is that reviewed? What happens if someone clicks on the wrong link, uses a weak password, or leaves the organisation unexpectedly? Those are management questions as much as technical ones.
That is one of the biggest misconceptions I come across in both consultancy and audit work. Cyber security is often treated as an IT department issue, but weak information security controls usually reflect wider management system weaknesses. A business may not know what its key assets are. It may not have defined ownership properly. It may not review access often enough. It may have backups in place, but no confidence that recovery will work. It may use third-party platforms heavily without ever having carried out proper supplier review. None of that is unusual. But all of it becomes much more visible once a business starts assessing risk honestly.
The recent government messaging around AI-driven threats makes this even more relevant. The April 2026 open letter to business leaders made the point that the steps organisations should take against AI-driven threats are the same cyber hygiene measures recommended for traditional cyber threats.
In other words, businesses do not need to panic and reinvent everything overnight, but they do need to make sure the fundamentals are genuinely in place. That means leadership attention, sensible controls, and a clearer understanding of where the business is actually exposed.
For smaller businesses, that is where a good risk assessment earns its keep. It helps separate the real issues from the noise. Not every risk needs the same level of treatment. Not every system is equally critical. Not every supplier presents the same level of exposure.
A structured assessment helps you decide what matters most, which is often the difference between a system that is practical and one that becomes bloated with generic controls no one really uses.
This is also where a lot of businesses discover that their current controls are weaker than they assumed. The NCSC’s small organisations guidance continues to focus on core themes such as backing up data, protecting devices, securing accounts and defending against phishing and malware.
Those may sound basic, but they remain central precisely because many organisations still have gaps in them. The fact that these issues continue to feature so prominently in official guidance tells you a lot about where real-world weaknesses still sit.
A good cyber risk assessment also improves decision-making beyond ISO 27001. It helps with supplier approval, staff awareness, training priorities, investment planning and incident preparedness. It also gives leadership something more useful than vague reassurance.
Instead of saying “we take cyber seriously,” the organisation can say what the main risks are, what controls are in place, what has changed recently, and what needs further attention.
That is especially important now because commercial expectations are shifting too. Even where businesses are not directly regulated in a cyber-specific way, more customers are asking security questions, more tenders require evidence of control, and more insurers expect sensible cyber hygiene. A business that cannot explain its main cyber risks is increasingly going to look underprepared.
From a practical point of view, the best cyber risk assessments I see are the ones that stay grounded in the business itself. They are not copied from a generic template and left untouched. They reflect the actual systems, people, suppliers and information the business relies on. They are reviewed when things change. They link clearly to treatment actions. And they are understandable enough that management can actually use them.
That is why this subject feels particularly useful right now. Small businesses are being told, rightly, that cyber resilience matters more than ever. But many still need a practical way to start.
Risk assessment is usually that starting point. It gives shape to the conversation. It helps leadership focus. And it supports a much more useful ISO 27001 system than one built around generic wording and assumptions.
If you’re exploring certification and want a clearer, more cost-effective route, you can see how The Compliance Companion works here:
https://the-compliance-companion.co.uk/harness-the-future-of-iso