Too Big for a Cyberattack?
"We're too small to interest a hacker": that's exactly what makes SMBs vulnerable. Here's why size is never a form of protection.
Company A spends 500 million euros to find a vaccine for disease X. A group of hackers, hired for $50,000, goes and gets Company A's data on that vaccine. The product ships, gets patented under another name, and enjoys 10 years of exclusive sales rights — without ever spending the 500 million. The profit margin is extraordinary.
That's the kind of risk — industrial espionage aimed at intellectual property rather than cash — that hangs over any company investing heavily in R&D. Bayer got a real taste of it a few years back, when the global chemical and pharmaceutical giant was hit by a cyberattack. The tool used, Winnti, is widely linked to state-sponsored groups running exactly this kind of industrial espionage campaign.
Bayer's IT team's quick instincts let them catch the infection early and remove it from the network. According to their analysis, there were several simultaneous points of infection, which usually points to a targeted attack rather than an opportunistic one.
"We're too small to interest a hacker"
It's the reasoning heard most often among SMBs — and it's exactly what makes them vulnerable. The reality is different: most attacks aren't aimed at the Bayers of the world. They target smaller, less protected organizations, often chosen not for their individual value but because they're simply easier to compromise.
An SMB can be a direct target (for its customer data, its intellectual property, or simply for ransom) or a stepping-stone target — an entry point toward a larger client, supplier, or partner further up its business chain. Either way, company size isn't protection.
What actually makes the difference
Even though the Bayer story sounds like it's straight out of a movie, a targeted attack — or an untargeted one — remains very real for any organization. The good news is that basic security measures remain remarkably effective: you can generally prevent the vast majority of attacks with a reasonable investment in employee training and a company's core security tools.
Concretely, that means:
- Access limited to what each employee actually needs
- Two-factor authentication enabled everywhere possible
- Updates applied without excessive delay
- Monitoring that catches abnormal behaviour before it turns into a major incident
None of these measures require an enterprise-sized budget. What they require is not putting off security by telling yourself you're "too small for anyone to bother with."
— Matt, MMO Techno