Antivirus Isn’t Enough Part Three – Do You Know How Far a Cyber Attacker Could Get in Your Business?

In the first two parts of this series, we looked at why antivirus isn’t enough to protect your business, and how layering MDR, XDR, staff training and dark web monitoring gives businesses like yours a much stronger defence.
Unfortunately, however, cyber attack methods are evolving at such a rapid pace that even the most robust cyber security setup might not be able to provide 100% protection. But those businesses that are able to restrict potential damage fare much better than those who, once breached, give attackers free rein.
A simple question: do you know how far an attacker could get in your business? Penetration testing can give you the answer.
There’s a significant gap between ‘protected’ and ‘tested’
According to the UK Government’s Cyber Security Breaches Survey 2025/2026, 43% of UK businesses experienced a cyber breach in the last 12 months, despite many having cyber security measures in place. For example, 81% have up-to-date malware protection, 74% have network firewalls, and 47% have more sophisticated measures in place, such as two-factor authentication.
Yet only 13% of business test their cyber security through penetration testing. That’s a significant gap between how many businesses are being targeted, how many are taking some defence measures, and how many are checking how well (or poorly) their defences would cope if someone got in.
Even businesses with strong cyber security setups can develop blind spots over time. Every new tool, system change, or even new starter shifts your IT environment slightly. Regular testing is an effective way to catch those blind spots before someone else does.
The 2025 Co-op and M&S cyber attacks
In 2025, both M&S and Co-op suffered high-profile cyber attacks. Both are established businesses with significant investment in cyber security. Both also suffered damage at the hands of attackers, but one was much more significant than the other.
In comparison, Co-op detected and launched a response to the breach within an hour. Although Co-op suffered supply chain disruption, financial damage and the funeral business had to revert to paper-based systems for a number of weeks, it did not face a months-long shutdown.
Co-op’s CEO, Shirine Khoury-Haq, pointed to their routine investment in security and frequent testing as part of what allowed the business to respond so quickly.
How to test your cyber security: penetration testing
Penetration testing, often shortened to ‘pen testing’, is when qualified cyber security specialists attempt to break into your business’ IT systems in ways which businesses are fully aware of. Testers behave like an attacker in a safe and controlled way.
Unlike the ‘always on’ tools covered in part one and part two, a penetration test is a deliberate, human-led project. Rather than monitoring threats, it actively tries to find ways in. It then tells you how far an attacker could get if they found a vulnerability.
A good pen test is built around objectives that are agreed with you, are relevant to your business, and reflect what an attacker might try to achieve against you. This could be reaching customer data, compromising a critical system or escalating a standard account to full control (so they can then exert that control). The results will give you an understanding of the real-world risks associated with a breach, rather than a technical list of vulnerabilities.
What a pen test might reveal
Here’s a hypothetical example to help demonstrate some issues penetration testing can uncover, and potential next steps.
A business has trained staff, decent monitoring and antivirus in place. This is what many businesses consider a reasonable level of cyber security precaution.
However, a penetration test might reveal that an old, forgotten login page from a retired system is still live. From there, an attacker could work their way through to your customer database, without tripping any alarms.
Your training and monitoring tools haven’t failed as such because they weren’t designed to catch a vulnerability like this. However, the vulnerability can still damage a business’ ability to function, its reputation and its finances. If it’s caught by a pen test, the business gets a clear next step: patch the forgotten system or decommission it, before it’s ever exploited for real.
Testing your cyber security is about more than just peace of mind
Testing isn’t only about protecting your business. It’s also becoming something that more clients, insurers and regulators are expecting to see evidence of. Some cyber insurance providers require accredited penetration testing as a condition of cover. If you’re in a regulated sector, e.g. finance, healthcare, or legal, or handle card payments, accredited testing can support compliance with frameworks such as ISO 27001 and PCI DSS.
Even outside regulated industries, showing a client or partner that your systems are independently tested demonstrates you take security seriously. It could be what sets you apart from competitors.
Cyber security is never really finished
The theme running through this blog series is that cyber security isn’t a ‘one and done’ job. Training, monitoring and testing all feed into each other. Insights from a pen test can shape your training. Training can reduce the risk that testing later uncovers.
Keep checking if the protections you have in place can withstand a determined attacker and you’re giving yourself the information you need to better protect your business.
More Cyber Security Information from AJT Managed IT Services
We’re here to help local businesses in Brighton and Sussex protect themselves against cyber threats. Check out the links below to find out more about the cyber security services we offer, as well as some of our latest security guidance.
- Antivirus isn’t enough Part One: Why XDR & MDR are smart cyber security choices for Brighton businesses
- Antivirus isn’t enough Part Two: Protect your Brighton business with cyber security training and dark web monitoring
- Social engineering guide for Brighton businesses: How to detect & protect your business from phishing
- Cyber security services
Latest Managed IT Support Advice
Check out our latest IT support blog posts.
Antivirus Isn’t Enough Part Three – Do You Know How Far a Cyber Attacker Could Get in Your Business?
In the second of two articles looking at why antivirus software on its own is no longer enough to keep your business safe, find out about the importance of a multi-layered approach to cyber security, bookended by employee training and dark web monitoring.

Windows 10 End of Life: What your small business in Brighton needs to know
Understanding the implications of Windows 10 EOL – and how best to handle it – is critical for small businesses in Brighton and beyond. You need to ensure your systems remain secure, compliant, and don’t create unnecessary problems. Read our blog to understand the risks, remedies, and how we can help you transition smoothly away…

What to Learn from M&S & Co-op Cyber Attacks
2025 was a big year for cyber security headlines in the UK, with two of our biggest stores suffering high profile cyber attacks: Marks and Spencer and The Co-op. Around a year on, here’s a breakdown of what happened, how Co-op’s cyber security measures helped them come out on top and what local businesses can…