Cyber Resilient Scotland 2025 – 2030: What It Means for Your Business

Police Scotland recorded 14,120 cyber crimes in 2024–25. Here's what Scotland's new Cyber Resilient Scotland 2025–2030 framework means for your business.

Person in a dark hoodie typing on a laptop in a dimly lit setting, with a blue glow from the screen.

We’re based in Perth. Have been since 2009. In that time I’ve watched cyber threats go from something that happened to other people – banks, big corporations, government departments – to something that happens to the kind of businesses we sit across a table from every week. Accountancy firms. Solicitors. Manufacturing companies. And more.

In November 2025, the Scottish Government published its latest national cyber strategy: the Cyber Resilient Scotland 2025–2030 framework. Police Scotland recorded 14,120 cyber crimes in the same reporting year. That’s nearly double 2019’s figure, and it doesn’t include the incidents that go unreported because the business was too embarrassed, too unsure who to call, or too busy firefighting to log a complaint.

This guide isn’t just about a 2025 framework, it’s about what cyber security and resilience ACTUALLY means for businesses in 2026.

The framework, in plain language

Scotland’s vision: “to thrive by being a digitally secure and resilient nation.”

The framework has seven outcomes. Most of them are about public sector bodies, government systems and national infrastructure. But Outcome 5 is specifically about businesses, and it’s worth quoting directly: the government wants Scottish businesses to “recognise the cyber risks and are well prepared to manage them.”

Prepared. Not compliant. Not certified. Prepared. There’s a gap between those things that the framework doesn’t quite close – and it’s the gap most Scottish SMEs are sitting in right now.

The document acknowledges something that anyone working in managed IT already knows: only 27% of businesses have board-level responsibility for cyber resilience. Not IT responsibility. Board responsibility. The other 73% are treating it as a technical problem, which means it’s treated as someone else’s problem, which means it isn’t actually being treated at all.

What the framework gets right is framing cyber resilience as a business risk, not a technology risk. What it doesn’t say loudly enough is that for most Scottish SMEs, the most effective route to that preparedness is working with a certified managed IT provider – not trying to build an in-house security team that the business can’t afford.

The four things worth understanding in 2026

AI isn’t just helping your team – it’s helping whoever’s trying to attack you

The phishing email used to be easy to spot. Odd formatting. Generic greeting. Spelling mistakes that felt almost deliberate. Those tells are gone. Mostly because anyone can use AI to write a convincing email now, and attackers figured that out before most businesses did.

According to the Cyber Breaches Survey 2025, 85% of UK businesses encountered fraudulent emails or websites in the previous twelve months. The Scottish Government’s own framework calls out AI-enabled cybercrime as one of the primary drivers of increased threat complexity. Ransomware-as-a-Service has lowered the barrier to entry to the point where a sophisticated attack no longer requires a sophisticated attacker – it just requires someone willing to pay a subscription fee to a criminal group.

For example, it can be as scary as this: a finance director receives what appears to be an email from their IT firm. Correct name, correct tone, a request to process an invoice payment urgently. It had been generated using information scraped from the website and LinkedIn. Completely personalized – it includes what they were up to at the weekend…Because the AI found that information from their LinkedIn. Without the correct training and security measures to get a second authorisation, that could easily become a huge cyber security mistake.

The good news is that AI tools are also being used on the defensive side. Detection, monitoring and automated response are improving. The question is whether your IT provider is using them – or whether you’re relying on staff training alone to hold a line that’s getting harder to hold every quarter.

If your team is using AI tools, you need a policy

This one comes up repeatedly when we onboard new customers. Someone in the team is using ChatGPT or a similar tool for work tasks – drafting client emails, summarising documents, pulling together proposals. Fine. Useful, even. The problem is they’re using a personal account, and sensitive company information is leaving the organisation without anyone realising.

Consumer AI tools are not enterprise data environments. When an employee pastes a client contract or financial document into a personal session, that data is being processed by a third party under consumer terms. Most of the time, that’s a data governance problem. In some cases – particularly if it involves client data or commercially sensitive information – it could be a breach.

An AI usage policy doesn’t need to run to thirty pages. It needs to answer three questions: which tools are approved for work use, what information can go into them, and who reviews that list as tools change. Most businesses don’t have one. They should have had one two years ago.

Trust no device by default

When we audit a new customer’s security posture, the thing we find most often isn’t a catastrophic gap. It’s accumulated drift. Devices that were added to the network without being properly configured. Accounts that were set up for contractors years ago and never decommissioned. Patches that got dismissed because they interrupted a meeting and never got rescheduled.

The baseline in 2026 is not complicated, but it does require discipline to maintain: multi-factor authentication on every account, device management on every device used for work, conditional access policies so that only properly managed devices can reach company data, and a zero trust approach that doesn’t assume anything on your network is safe just because it’s on your network.

None of that is novel technology. MFA has been standard guidance from the NCSC for years. The Microsoft study that found MFA prevents over 99.9% of automated account compromise attacks is from 2022. The barrier isn’t technical. It’s organisational – it requires someone to actually own the process and make sure it stays in place as the business changes. That’s where most SMEs fall down – and we get it, there’s SO much to do as an SME.

It’s not just your own risks you need to think about

The carousel slide we posted on this says it well: if your biggest supplier was hit by ransomware tomorrow, would your business still operate?

Supply chain cyber risk is the one that tends to catch Scottish businesses off guard, because it feels abstract until it isn’t. You’ve done everything right internally. Your own systems are patched, your staff are trained, you’ve got MFA enforced. And then a payroll provider, or a logistics platform, or a key piece of software gets compromised – and the damage lands on your desk anyway.

The Scottish Government framework specifically identifies supply chain vulnerabilities as a persistent risk. Larger businesses in sectors like finance and utilities have been managing third-party supplier risk for a while. Smaller businesses mostly haven’t started. The question isn’t whether this matters to you – it does, regardless of your size, because you are someone else’s supplier too. The question is whether you’ve had the conversation.

So what can you do?

Start with Cyber Essentials

Cyber Essentials is the UK government-backed certification covering five core security controls: firewalls, secure configuration, user access control, malware protection and patch management. Achieving it doesn’t mean you’re immune to attack. But it does mean you’ve addressed the controls that protect against the vast majority of common attacks, and you can demonstrate that to clients, insurers and procurement teams who are increasingly asking to see evidence.

Public sector contracts regularly mandate it now. Cyber insurers are pricing policies differently depending on whether you hold it – or whether you don’t. And if you’re a supplier to a larger business in any regulated sector, the expectation is tightening.

We’re Cyber Essentials Plus certified, which is the independently audited tier. We help our customers achieve it as part of the managed IT service. The audit process isn’t punishing – for most businesses, the work involved is getting the five controls properly in place, which they should have been anyway. The certification is a side effect of doing it right.

Our final thoughts

Most of the cyber incidents we’ve seen affect Scottish SMEs aren’t the result of sophisticated, targeted attacks. They’re the result of gaps that have been there for months or years – unpatched systems, accounts that weren’t properly managed, staff who weren’t sure what a phishing email looked like anymore. The gaps the framework is trying to close. It’s why having an outsourced IT team is critical for SMEs, because our entire job is keeping you secure, running, and up to date – including training.

If you’re unsure on where to start, just book an IT audit with us for free.

Sources: