Fri, Apr 24, 2026
Text Size
Wednesday, 11 November 2015 14:28

KPMG warns SMEs need to address cyber security or risk losing work

Small and Medium Sized Enterprises (SMEs) risk being disqualified from bidding for work because of the lack of importance they are placing on looking after their valuable client data, according to a survey of procurement managers by KPMG.

The multisector KPMG survey of 175 procurement managers across the UK from organisations with over 250 employees revealed that the general consensus (70%) of procurement managers is that SMEs should be doing more to prevent cyber attacks and protect valuable client data.

 The vast majority (86%) of respondents said they would consider removing an SME supplier if they were hacked and nearly all of the respondents (94%) confirmed that cyber security standards are important when awarding contracts to SME suppliers.

 George Quigley, Partner in KPMG’s cyber security practice, commented:

“Cyber security is not just a technical issue anymore; it has become a business critical issue for the UK’s SMEs.  Larger companies are placing an increased emphasis on the cyber security of their suppliers and increasingly the onus is on SMEs to show that they are tackling this issue head on.”

 “Unfortunately many SME still take a blasé approach towards cyber security and mistakenly don’t see themselves as targets of cyber criminals. Unless these organisations take a more mature approach towards cyber security now, they face the risk of being frozen out of lucrative supplier contracts.”

 Already two-thirds of procurement managers ask their suppliers to demonstrate cyber accreditations (ISO27001, Cyber Essentials, IASME certifications or PCI DDS) as a part of their procurement assessment, with this number likely to increase in the near future. 

In addition, SMEs are increasingly being asked to self-fund their own accreditations. In the absence of accreditation, two-fifths (41%) of procurement managers expect their suppliers to pay for their own accreditations and reach a certain level of cyber maturity in the near future.

 George Quigley concluded:

“In order for businesses to be awarded some public sector contracts they already have to demonstrate a certain level of cyber maturity and this is increasingly becoming the norm in the private sector as well."

"Companies are also embedding cyber security in their supplier contracts with about half (47%) of existing contracts already stating that suppliers are contractually obliged to tell if they have been hacked. This means that if a SME supplier is breached and doesn’t deal with it appropriately, they could be looking at the termination of an existing supplier contract.”

The Government is already looking to increase the cyber maturity of UK businesses, with accreditations like the Cyber Essentials Scheme. KPMG said the UK could only expect the bar to be raised higher in the coming years. 

News Showcase

Sign up to receive the Waterbriefing newsletter:


Watch

Click here for more...

Login / Register




Forgot login?

New Account Registrations

To register for a new account with Waterbriefing, please contact us via email at waterbriefing@imsbis.org

Existing waterbriefing users - log into the new website using your original username and the new password 'waterbriefing'. You can then change your password once logged in.

Advertise with Waterbriefing

WaterBriefing is the UK’s leading online daily dedicated news and intelligence service for business professionals in the water sector – covering both UK and international issues. Advertise with us for an unrivalled opportunity to place your message in front of key influencers, decision makers and purchasers.

Find out more

About Waterbriefing

Water Briefing is an information service, delivering daily news, company data and product information straight to the desks of purchasers, users and specifiers of equipment and services in the UK water and wastewater industry.


Find out more