The router sits in the storage room, the firewall is rarely noticed—and this is exactly where the cyber war begins for many companies. 43% of SMEs were hacked last year. It’s time to take this reality seriously and strategically realign IT security.
Cybercrime is no longer a fringe issue but a multi-billion-dollar shadow industry. For small and medium-sized enterprises (SMEs), the threat is particularly serious: nearly half of them were victims of an attack last year alone. Often, the problem isn’t targeted elite hacker attacks but outdated systems, missing security processes, and a false sense of safety.
In this article, we look at the current threat landscape, explain why SMEs are especially vulnerable, and show concrete measures you can implement immediately to improve protection.
Cybercrime 2025 – The Facts
Global losses from cybercrime are expected to reach USD 10.5 trillion in 2025. SMEs are particularly in focus:
- 43% of SMEs in the UK reported a cyberattack in 2024.
- 93% of simulated penetration tests (pentests) ended with successful system compromise.
- 83% of SMEs feel overwhelmed by AI-driven attacks.
The pace and scale are alarming: an attack occurs every 39 seconds, detection takes an average of 292 days, and the average loss per incident is around USD 5 million.

Why SMEs Are Especially at Risk
Many SMEs sit on outdated hardware, use routers and firewalls that haven’t been updated for years, and rely on passwords stored in Excel sheets. At the same time, budgets and resources for professional security measures are often lacking.
- Resource constraints: 52% still manage access with Excel or sticky notes.
- Lack of risk awareness: 83% have no cyber insurance.
- False sense of security: a subjective feeling of safety often masks serious vulnerabilities.
So what does that have to do with the router in the storage room?
Simple: the router is the gateway to the company network. If it sits in a storage room, the following often happens:
- Out of sight, out of mind: devices that aren’t visible are checked less often. Updates, security patches, or configuration changes are easily forgotten.
- Physical security: in unsecured rooms, the router can be physically tampered with or even swapped out.
- Outdated hardware: devices in storage rooms often run for years without replacement. Old firmware contains known vulnerabilities that hackers deliberately exploit.
- Lack of monitoring: isolated devices are rarely monitored actively. Attacks or anomalies go undetected longer. In short: a neglected, dusty router is like an unlocked back door for cybercriminals.
Immediate actions for SMEs – Simple & effective
-
- Manage routers & firewalls centrally — take them out of the storage room and into your security plan.
- Privileged Access Management (PAM) — ditch Excel and move to professional access-control tools.
- Employee training — social engineering remains the main attack vector (68% of all security incidents).
- Use updates and cloud solutions — regular security updates and cloud services minimize risk.
- Establish network hygiene — disable unnecessary access, automate backups, and define clear processes.
Strategic view: cybersecurity as a business strategy
Cybersecurity must not be seen as a purely IT issue. It’s a core business strategy—like quality assurance or finance. Those who treat IT security as an investment protect not only systems but also reputation, customer relationships, and the ability to operate.
Summary
Keeping the router in the storage room may seem convenient—but it isn’t secure. Cybercrime affects every company, no matter how small or large. SMEs must integrate technology, processes, and people equally into their security strategy. Cost-efficient tools, continuous training, and strategic planning are crucial to fend off attacks.
Reference library
- Positive Technologies – Pentest Research Report: https://pentest-tools.com/blog/penetration-testing-statistics
- Verizon DBIR 2024: https://www.verizon.com/about/news/2024-data-breach-investigations-report-vulnerability-exploitation-boom
- University of Maryland – “Hackers attack every 39 seconds”: https://eng.umd.edu/news/story/study-hackers-attack-every-39-seconds
- Cybersecurity Ventures – Cybercrime Cost Forecast: https://cybersecurityventures.com/cybercrime-damage-costs-10-trillion-by-2025/
- IBM Cost of a Data Breach Report 2024: https://www.ibm.com/think/insights/whats-new-2024-cost-of-a-data-breach-report
- TransUnion SMB Cybersecurity Gap 2025: https://www.transunion.com/blog/smb-cybersecurity-gap
- GOV.UK – Cyber Security Breaches Survey 2025: https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025

