In mid-2023 attackers exploited a zero-day flaw in Progress Software's MOVEit Transfer product. Because MOVEit is used by payroll providers, outsourcers and public bodies to shift bulk files, the fallout reached organisations that had no direct relationship with the product at all. In the UK, staff data from a number of large employers was exposed through a payroll bureau.
The lesson for smaller firms
You can have tidy patching, MFA everywhere and good backups, and still have your employees' bank details published because your accountant's software had a bug. Third-party risk is the part of security small businesses most often skip.
What's actually practical
- Know who holds your data. Payroll, accountancy, HR, CRM, marketing lists. Write the list down — it's also a GDPR requirement.
- Ask them one question: what happens, and how quickly will you tell us, if you have a breach? A supplier who can answer clearly is usually a supplier who has thought about it.
- Minimise what you hand over. Old employee records sitting in a portal you no longer use are pure liability.
- Have your own incident contacts ready — ICO reporting is 72 hours, and that clock is unforgiving.
Cyber Essentials certification covers a lot of this ground and is increasingly asked for by customers and insurers.