For years, the honest answer to “how bad is cybercrime in Scotland?” was a shrug and a UK-wide statistic. That changed this year: Scotland’s Cyber Coordination Centre (SC3) published its first dedicated report on cyber activity across the Scottish public sector, and alongside insurer and industry data it gives us, for the first time, a genuinely Scottish picture. It is not a comforting one, but it is a useful one, because the patterns in it are exactly the ones a business can prepare against.
Here is what the 2026 picture actually shows, what the highest-profile Scottish incidents teach, and what it all means for an SME in Dundee, Perth or Glasgow rather than a government department.
The numbers now on record
Three findings from the current Scottish data stand out:
The tempo is rising sharply. SC3 and the Scottish Government have coordinated responses to 183 public-sector cyber incidents since 2018, and 43 of those came in 2025 alone: nearly a quarter of seven years’ incidents in a single year. Whatever the private-sector multiple of that figure is (most business incidents are never centrally reported), the direction is unambiguous.
Ransomware leads, as everywhere. Ransomware accounts for the largest share of serious Scottish public-sector incidents (37 in the SC3 data), matching the NCSC’s national assessment of it as the UK’s most pressing cyber threat. The attack pattern is the same one we describe elsewhere on this site: automated entry, quiet dwell, backups hunted, then encryption timed for maximum pressure.
The SME cost is quantified and mundane. Industry analysis puts the combined cost of cyber attacks to Scottish small businesses at roughly £386 million a year, an average of about £5,584 per affected firm. The averages hide the distribution: most incidents are survivable four-figure disruptions, and a minority are the business-ending kind, with the difference usually decided by backups and preparation rather than by the attacker.
What the Western Isles case teaches every business
The most instructive Scottish incident on public record remains the 2023 ransomware attack on Comhairle nan Eilean Siar (Western Isles Council), not because of how it started but because of how long it lasted. Follow-up scrutiny through 2025 found the council was still working through backlogs two years after the attack, had not been adequately prepared beforehand, and had implemented only half of the post-incident recommendations two years on.
Strip away the public-sector specifics and three transferable lessons remain:
- The recovery tail is the real cost. The headline outage lasts days; the backlog, rebuilding and trust repair last years. Every hour of prevention buys weeks of that tail. This is precisely what recovery objectives and tested restores exist to shorten.
- “Not adequately prepared” is the default state. The findings against the council (gaps in preparation, no rehearsed response) describe most Scottish SMEs today. The difference is that a council survives on public funding; a business survives on cash flow.
- Post-incident resolutions decay. Half-implemented recommendations two years later is not negligence so much as gravity: without an owner and a cadence, security work loses to urgent work every week. It is the strongest argument for security as a managed, standing arrangement rather than a project that follows a scare.
The threat picture for Scottish SMEs specifically
Nothing in the data suggests Scottish businesses face exotic local threats; they face the global commodity threats with local texture. Phishing and credential attacks remain the entry route for most incidents. Invoice and payment-diversion fraud continues to hit professional firms, with conveyancing and client-account work the sharpest example. Sectors with low downtime tolerance (manufacturing, food processing, care) remain preferred ransomware targets for the simple reason that they pay faster. And the newer wrinkle, AI-assisted fraud (cloned voices, deepfaked authority), has moved from conference talk to incident reports, which is why verification-by-second-channel now appears in our staff training and every sensible AI policy.
The policy environment is moving too: the Scottish Government’s Cyber Resilient Scotland framework (2025 to 2030) is pushing resilience expectations outward from the public sector, and the practical transmission mechanism is one this site documents repeatedly: supply-chain questionnaires and Cyber Essentials requirements flowing down from public bodies and large customers into SME contracts.
Free help worth knowing about
Scotland is unusually well-served with free resources, and using them is not an admission of anything: CyberScotland aggregates guidance and threat bulletins; the Scottish Business Resilience Centre (SBRC) offers incident support and advice aimed squarely at SMEs; and the NCSC’s small-business guidance remains the best free baseline anywhere. None of them will configure your MFA or test your backups, which is where the managed layer earns its fee, but a business that reads their bulletins is meaningfully harder to surprise.
The same conclusion, with local evidence
The Scottish data changes the evidence, not the advice. The controls that would have prevented or shrunk the incidents in this year’s reporting are the unglamorous set this site keeps arriving at: MFA everywhere, patched systems, monitored endpoints, immutable tested backups, trained staff, and a rehearsed response plan. What the local numbers add is the rebuttal to “it won’t be us”: 43 coordinated public-sector incidents in one year, in a country of five and a half million, before counting a single private business.
Frequently asked questions
How common are cyber attacks on Scottish businesses?
Common enough to be quantified: Scottish small businesses collectively lose an estimated £386 million a year to cyber attacks, and Scotland’s public-sector coordination centre handled 43 incidents in 2025 alone. Most business incidents are never publicly reported, so visible cases are the floor, not the ceiling.
What kind of attacks hit Scottish SMEs most?
The global pattern applies: phishing-led credential theft, ransomware (the most prevalent serious threat in Scottish public-sector data), and payment-diversion fraud against firms that move client money. Targeting is automated and indiscriminate.
Which Scottish sectors are most at risk?
Any sector with valuable data or low downtime tolerance: professional services holding client funds and records, manufacturers and processors where stoppage forces fast payment, and care and health settings holding special-category data. Risk follows leverage, not size.
Where can Scottish businesses get free cyber security help?
CyberScotland (guidance and bulletins), the Scottish Business Resilience Centre (SME-focused advice and incident support) and the NCSC’s small-business guidance. Free resources set the knowledge baseline; implementation and monitoring still need an owner.
What single change would most reduce our risk?
Enforced MFA everywhere remains the highest-value single control, with immutable tested backups the highest-value insurance. The full priority list is in our Cyber Essentials checklist, which doubles as the certification route many Scottish contracts now request.
How we keep this article current
This page tracks a moving picture: we review it quarterly against new SC3 and CyberScotland reporting, insurer data and notable Scottish incidents, and update the figures and cases as the record grows. The defensive advice changes far more slowly than the incident list, which is rather the point.
Get ahead of the next report
Every incident in next year’s statistics is happening to a business that assumed it had time. Our free IT health check measures your defences against exactly the patterns in this year’s data (entry controls, backup survivability, response readiness) with findings in plain English and fixes priced. Get in touch while yours is still a hypothetical.