Recent cyberattacks on high-profile brands such as Marks & Spencer (IT systems disrupted, profit impact), Co‑op (retail-wide outages), and Adidas – plus incidents affecting supermarkets like Harrods – have dominated media coverage.
But while the spotlight remains on large firms, smaller businesses are in just as much danger – yet often less prepared when it comes to cyber security. At Dr Logic we believe it’s critical to resurface the story of Knights of Old, a 158‑year‑old UK logistics firm destroyed by ransomware in 2023, alongside evidence from other SME attacks. These cases stand as stark warnings: no business is too small – or old – to be targeted.
What happened to knights of old after a ransomware attack?
In late June 2023, Kettering‑based KNP Logistics, owner of the historic Knights of Old brand, was seized by the Akira ransomware group via stolen credentials and a brute-force attack. Akira not only encrypted vital systems but also threatened to publish internal company and customer data. Despite holding a £1 million cyber insurance policy, the company couldn’t restore operations, lost critical financial records, and entered administration by September 2023 with approximately 730 job losses.
Former director Paul Abbott recalled the chilling moment the ransom note appeared:
“If you’re reading this, it means the internal infrastructure of your company is fully or partially dead”
Despite compliance efforts and insurance, the breach left them unable to secure further funding or continue trading.
How did a ransomware attack disrupt Peter Green Chilled’s operations?
In May 2025, Peter Green Chilled – a Somerset‑based refrigerated food distributor supplying retailers including Tesco, Aldi and Sainsbury’s – was struck by ransomware. The attack encrypted order systems, prompting the company to pause new orders while continuing transport operations
Founder Wilfred Emmanuel-Jones, known as the Black Farmer, revealed around ten pallets of meat stock sat unused as time ticked away, risking up to £100,000 in spoilage.
IT security experts warn this case shows how supply-chain pressure forces attackers to escalate rapidly. “Once attackers find a way in, they can move laterally at speed, crippling systems…” noted Lee Driver of Ekco.
Which sectors are seeing the most cyberattacks?
Cybercriminals aren’t just hitting retailers. A look at wider incidents shows a growing focus on supply chains and infrastructure.
- In January 2023, Royal Mail’s export logistics were disrupted by LockBit ransomware, hindering SME shipments across the UK
- In 2025, distribution giant Ingram Micro was hit by SafePay ransomware, affecting thousands of MSPs and businesses through supply-chain disruptions
These attacks have knock-on effects, even if your own systems aren’t breached directly. That’s why supply chain security matters more than ever.
Why are SMEs increasingly targeted by cybercriminals?
Cyberattacks are rising fast – and SMEs are increasingly in the firing line.
Key stats from the DSIT Cyber Security Breaches Survey 2025/2026 (published April 2026):
- 43% of UK businesses experienced a cyber breach or attack in the last 12 months – extrapolating to approximately 612,000 businesses
- Revenue impact from breaches more than doubled year-on-year
- 69% of UK business boards are still not meaningfully involved in cyber security decisions
- Credential compromise remains the top attack vector
- Lack of MFA and poor password hygiene continue to fuel unauthorised access Many SMEs have no recovery plan or tested backup
In the case of Knights of Old, no usable restore point meant game over – even with insurance in place.
How can you strengthen your cyber defences in 2025?
Cyber resilience isn’t just about preventing attacks – it’s about surviving – it’s about surviving them.
Here’s what Dr Logic recommends as standard:
SME cyber defence checklist
| Area | Action |
|---|---|
| Access control | Enable MFA on all accounts, no exceptions |
| Passwords | Deploy a business password manager |
| Backups | Maintain tested, offline backups - verify restoration regularly |
| Patching | Apply OS and software updates promptly |
| Staff training | Run regular phishing awareness sessions |
| Incident response | Have a documented plan before you need it |
| Supply chain | Assess the security posture of key suppliers |
Final thought: cyber resilience is business resilience
The collapses of Knights of Old and Peter Green Chilled aren’t just cautionary tales – they’re signals of a shift in how and where cybercriminals strike.
It’s not just about headline brands anymore. It’s about vulnerable infrastructure, forgotten backups, and weak credentials.
Want to make sure your business doesn’t become the next headline?
At Dr Logic, we help businesses build layered defences, proactive recovery plans, and a culture of cyber awareness – whether you’re 50 or 500 strong.
Book a free security review with our team.
FAQs
Are SMEs really being targeted more than big brands?
Yes. Attackers see SMEs as easier targets – less protected, more reliant on vulnerable suppliers, and slower to detect breaches.
Does cyber insurance cover all ransomware attacks?
Not always. Many policies exclude costs like recovery, lost revenue, or third-party legal claims. Check the details.
How long does recovery usually take after a ransomware attack?
Without backups or a recovery plan, it can take weeks – or end in closure. With the right systems in place, recover can start in hours.



















































