Desk live·
ForensicPost
Breaches/Regulation/File 25-0616b

Neither DORA nor the UK Bill Reaches the Small Firms Taking 43% of Attacks

DORA covers EU financial entities. The UK Bill covers essential and digital services and designated critical suppliers. Neither reaches the organisations that 43% of attacks are aimed at.

Constructed geometry · not a chart of case data
JurisdictionUnited Kingdomthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSmall organisations
ActorRegulator
S. Rosler12 min readConfidence: medium2 sources reviewed

This file tests the 2025 regulatory reforms recorded at 25-0117, 25-1113, 25-1119 and 25-1124 against the small-organisation population described in this section.

Every Instrument Is Scoped Upward

DORA applies to EU financial entities, with extension to critical ICT providers. The UK Bill covers essential and digital services, managed service providers, data centres and designated critical suppliers.

Scoping upward is deliberate and defensible: regulation targets systemic risk, and a ten-person firm is not systemically important. The corpus filed at 25-1124 that criticality is emergent and hard to designate in advance, and that difficulty argues for focusing where the dependency concentration is.

And The Reasoning Has A Hole In It

Small firms are suppliers. Marquis at 25-0814, Chain IQ at 25-0613 and the health IT vendor at 25-0515 were not household names, and criticality was visible only after the incident.

A designation regime that reaches organisations already recognised as critical will not reach the next Marquis, which is the specific criticism this desk made at 25-1124.

What Would Help Is Not Regulation

The corpus has been consistent that duties without capacity produce non-compliance rather than security, at 25-1223, and 25-0612b establishes that a third of small firms could not absorb a $10,000 loss.

What that population needs is not an obligation. It is secure defaults in the products they already buy — the administrative consent default at 25-0311, the enrolment controls at 25-0813, the automatic deletion at 25-0903 — decided by platform vendors on behalf of customers who cannot make the decision themselves.

That is the argument at 25-0923, where a platform with no fault held the only lever operating at the scale of the problem. For small organisations it is the only lever at all.

Graded medium: this is a reading of published instruments against a survey-based population estimate, not a legal analysis.

This is an analysis file

It reads the 2025 regulatory files in this database against the small-organisation files. It is not legal advice and does not assess any instrument’s precise scope. Corrections: corrections@forensicpost.com.

Sources
  1. Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience BillGlobal Policy Watch
  2. Small business cybersecurity statistics and trendsStationX
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary