Updated September 2026. Figures are labeled as SMB-specific, all-size, survey-based, or incident-based so they are not blended into one false “small business attack rate.”
Key small business cybersecurity statistics at a glance
The table below is designed to be quotable without stripping away the denominator. Where a statistic applies to all organization sizes rather than SMBs specifically, that limitation is stated directly.
| Statistic | Figure | What it measures | Data period | Source |
|---|---|---|---|---|
| Small organizations stopping ransomware before encryption or extortion | 34% | Organizations with 100 to 250 employees | 2026 survey | Sophos State of Ransomware 2026 |
| Larger organizations stopping ransomware before encryption or extortion | 46% | Organizations with 3,001 to 5,000 employees | 2026 survey | Sophos |
| SMB breach initial access from vulnerability exploitation | 26% | Leading initial-access vector in Verizon SMB dataset | Nov 2024 to Oct 2025 | Verizon 2026 DBIR |
| SMB breach initial access from credential abuse | 13% | Second initial-access vector in SMB dataset | Nov 2024 to Oct 2025 | Verizon 2026 DBIR |
| SMB breach initial access from phishing | 9% | Phishing as initial-access vector | Nov 2024 to Oct 2025 | Verizon 2026 DBIR |
| Third-party involvement in SMB breaches | 55% | Share of SMB breaches involving a third party | Nov 2024 to Oct 2025 | Verizon 2026 DBIR |
| Human element in SMB breaches | 45% | Verizon “human element,” not “human error” | Nov 2024 to Oct 2025 | Verizon 2026 DBIR |
| SMEs reporting a cyberattack in previous 12 months | 59% | Self-reported survey of almost 6,000 small businesses | 2025 | Hiscox Cyber Readiness Report |
| Small businesses reporting a security or data breach | 81% | Survey of 662 owners/executives at firms with 500 or fewer employees | 2025 | ITRC Business Impact Report |
| Small businesses experiencing at least one attack in five years | 79% | Survey of 1,000 small businesses | 2025 | Coalition Small Business Cybersecurity Study |
| Small businesses that do not think they are attractive targets | 64% | Perception of target attractiveness | 2025 | Coalition |
| Small businesses concerned about cyber threats in next 12 months | 87% | Very or somewhat concerned | 2025 | Coalition |
| Small businesses saying risk increased over prior year | 83% | Perception of rising risk | 2025 | Coalition |
| Small businesses spending under 10 hours a week on cybersecurity | 59% | Time devoted to cybersecurity activity | 2025 | Coalition |
| Small businesses allocating under 10% of total business budget to cybersecurity | 74% | Surveyed budget allocation | 2025 | Coalition |
| Ransomware attacks starting with an identity-based approach | 79% | All organization sizes, not SMB-only | 2026 | Sophos |
| Ransomware attacks that encrypted data | 56% | All organization sizes | 2026 | Sophos |
| Encrypted ransomware victims that paid | 48% | All sizes; denominator is encrypted victims | 2026 | Sophos |
| Average ransomware recovery cost | $1.7M | All organization sizes; excludes ransom | 2026 | Sophos |
| Small businesses with breach impact above $250,000 | 62.5% | Among breached small businesses surveyed | 2025 | ITRC |
| Small businesses with breach impact above $500,000 | 36.7% | Among victims in ITRC survey | 2025 | ITRC |
| Small businesses raising prices to absorb cyber incident costs | 38.3% | Business response to recovery cost | 2025 | ITRC |
What these small business cybersecurity statistics actually measure
Most ranking pages mix attack attempts, confirmed breaches, surveys, insurance claims, and ransomware outcomes as though they were interchangeable. They are not. A survey saying 59% of SMEs experienced a cyberattack does not mean 59% suffered a verified data breach, and a breach dataset does not measure every attack that failed. This distinction is one of the biggest reasons small business cyber statistics disagree across publishers.
- Survey self-report: Hiscox, Coalition, and ITRC ask business owners or security decision-makers what they experienced or believe.
- Incident and breach analysis: Verizon DBIR analyzes reported incidents and confirmed breaches.
- Ransomware victim surveys: Sophos surveys organizations that were hit by ransomware.
- All-size figures: A statistic such as the $1.7 million average ransomware recovery cost should not be relabeled as “the average small-business cyberattack cost.”
How often are small businesses attacked?
No single current percentage measures the share of every small business worldwide that is successfully attacked. Hiscox’s 2025 Cyber Readiness Report surveyed almost 6,000 small businesses across seven countries and found that 59% reported a cyberattack in the previous 12 months. The ITRC surveyed 662 U.S. small-business owners or executives at organizations with 500 or fewer employees and reported that 81% had suffered a security breach, a data breach, or both during the prior year.
Coalition’s 2025 study adds a longer time horizon. Among 1,000 small businesses surveyed globally, 79% said they had experienced at least one cyberattack in the previous five years. These results do not merge into a universal “attack rate” because the questionnaires, locations, definitions, and periods differ.
Primary sources: Hiscox Cyber Readiness Report 2025, ITRC 2025 Business Impact Report, and Coalition Small Business Cybersecurity Study.
The small business cyber risk perception gap
Coalition found that 87% of surveyed small businesses were very or somewhat concerned about cyber threats over the coming year, and 83% believed their risk had increased during the prior year. Yet 64% still did not believe they were attractive targets to threat actors. The same study reported that 59% spent fewer than 10 hours per week on cybersecurity activities and 74% allocated less than 10% of their total business budget to cybersecurity.
The numbers describe a readiness problem more precisely than the old claim that small businesses simply “do not care” about security. Many leaders understand that cyber risk is rising but still underestimate their own exposure or have difficulty turning concern into controls.

How small businesses get breached
Verizon’s 2026 DBIR gives the clearest current breakdown of initial access in its small-business dataset. Vulnerability exploitation led at 26%, credential abuse followed at 13%, and phishing accounted for 9%. Third-party involvement appeared in 55% of SMB breaches, while the “human element” appeared in 45%. The human-element figure should not be rewritten as “45% were caused by human error”; Verizon’s category is broader than that.

For the wider disclosure and exploitation picture, including CVE growth, CISA KEV, EPSS, and exploitation timing, see our Vulnerability Statistics research. When a team has more findings than it can fix, our guide on How to Prioritize Vulnerability Remediation explains how to move from raw severity to exploitability and exposure.
Third-party risk is now a small business security problem
Third-party involvement in 55% of the Verizon SMB breaches is one of the most important statistics on this page because it changes what “small business cybersecurity” means. A company can patch its laptops and still inherit exposure through a managed service provider, website plugin, SaaS integration, payment provider, cloud service, outsourced IT account, or compromised vendor credential.

The practical response is not to eliminate vendors. It is to inventory them, remove unused access, require strong authentication, review privileged integrations, and know which third parties can reach customer data or production systems.
Ransomware statistics for small businesses

Ransomware remains the clearest place where organization size changes outcomes. Sophos State of Ransomware 2026 surveyed 2,158 IT and security leaders from organizations that had experienced ransomware in the prior 12 months. Only 34% of organizations with 100 to 250 employees stopped the attack before encryption or extortion, compared with 46% among organizations with 3,001 to 5,000 employees.
Across all organization sizes, 56% of ransomware attacks succeeded in encrypting data, up from 50% the previous year. Among organizations whose data was encrypted, 48% paid a ransom. The average recovery cost reached $1.7 million, excluding ransom payments. These are not SMB-only averages and should not be presented that way.
For the broader attack, payment, encryption, recovery-cost, and group activity data, see our Ransomware Statistics report.
The shift to identity, email, and incomplete MFA coverage

Sophos reported a major change in ransomware root cause for 2026. Malicious email accounted for 26% of incidents and phishing for 24%, while compromised credentials represented 23% and exploited vulnerabilities 18%. Across the report, 79% of ransomware attacks began with an identity-based approach. These figures apply across organization sizes rather than SMBs alone.
Sophos also reported that MFA was deployed in some capacity in 97% of incidents where compromised credentials were the ransomware root cause. That does not mean MFA is ineffective. It means partial deployment, bypassable factors, uncovered accounts, session theft, and other identity gaps can still leave a path through.
AI and small business cybersecurity statistics
AI-related statistics deserve more caution than most categories because many current figures are survey perceptions rather than directly observed attribution. Hiscox reported that 57% of SMEs surveyed said they had experienced a cyberattack due to AI vulnerabilities. ITRC’s 2025 Business Impact Report said AI-powered attacks were identified as a root cause in more than 40% of cyber events reported by respondents. Those figures should be quoted as survey findings, not as proof that an independent forensic investigation attributed that share of all attacks to artificial intelligence.
The strongest takeaway is operational rather than sensational: generative AI can lower the cost of producing convincing phishing, accelerate reconnaissance, and expand the number of automated attempts a small team must filter.
The cost of cyberattacks on small businesses
Cost is where statistics pages most often compare unlike populations. ITRC provides one of the more directly SMB-specific 2025 views: among small businesses that suffered a breach, 62.5% reported total financial impact above $250,000, and 36.7% reported costs above $500,000. The report also found that 38.3% of small-business leaders raised prices to absorb the financial effects of an incident.
IBM’s earlier Cost of a Data Breach research reported an average of roughly $3.31 million for organizations with fewer than 500 employees. Sophos adds a different measure: average ransomware recovery cost reached $1.7 million across all organization sizes in 2026, excluding ransom payments.
Website, WordPress, WooCommerce, and API exposure for SMBs
Small businesses increasingly run on public software stacks rather than on isolated internal networks. A brochure site can still expose a CMS, plugins, contact forms, hosting panels, third-party scripts, and login endpoints. An online store adds payment workflows and extensions. A SaaS company adds public APIs and cloud integrations.
For the broader web attack surface, our Website Hacking Statistics page separates bot traffic, attack attempts, compromises, and vulnerability disclosures. WordPress-heavy businesses should also review WordPress Plugin Vulnerability Statistics, which focuses on the plugin ecosystem rather than incorrectly treating every WordPress flaw as a core vulnerability.
Small online stores have a second layer of plugin and extension exposure around checkout, payments, subscriptions, and ecommerce administration. Our WooCommerce Vulnerability Statistics report separates WooCommerce core records from third-party extensions and the wider WordPress ecosystem.
For SaaS products, mobile backends, ecommerce integrations, and public services, the API layer creates its own authorization and inventory problems. Our API Security Statistics report covers API incidents, attack volume, exploited vulnerabilities, and visibility gaps without mixing those metrics into generic website attack counts.
Small business vs large organization: the cybersecurity size gap
The most defensible “small businesses are more vulnerable” claim is not that a fixed percentage of every cyberattack targets them. It is that current datasets show measurable differences in defensive outcomes and resources.
| Measure | Small organization | Larger organization / context | Source |
|---|---|---|---|
| Stopped ransomware before encryption or extortion | 34% at 100 to 250 employees | 46% at 3,001 to 5,000 employees | Sophos 2026 |
| Cybersecurity time commitment | 59% spend under 10 hours/week | Small-business survey measure | Coalition 2025 |
| Cybersecurity budget allocation | 74% allocate under 10% of total business budget | Small-business survey measure | Coalition 2025 |
Small business cybersecurity statistics to stop citing
A strong statistics page should remove bad numbers as aggressively as it adds new ones. These claims are still common in competing articles, but they should not be presented as current verified facts.
“60% of small businesses close within six months of a cyberattack”
The National Cybersecurity Alliance stated that this statistic did not come from its research, could not be verified, and should not continue to be cited.
“43% of all cyberattacks target small businesses”
This figure is repeated widely, but current articles often point to secondary references rather than a transparent current dataset measuring the denominator “all cyberattacks.” It is safer to use direct measurements such as Verizon’s SMB breach vectors or Sophos’s size-based ransomware outcomes.
“A small business is attacked every 7, 11, or 39 seconds”
These cadence claims usually come from dividing an annual estimate by the number of seconds in a year or from old laboratory observations of automated attempts.
“95% of breaches are caused by human error”
Verizon uses a “human element” category, which is broader and should not be rewritten as a causal human-error percentage. In the 2026 SMB dataset, the human element appeared in 45% of breaches.
How small businesses should reduce cyber risk
The data points to a short control set rather than a giant enterprise checklist. Smaller teams get more value from covering the biggest entry paths consistently than from buying many tools and leaving gaps between them.
- Patch internet-facing software on a schedule. Vulnerability exploitation leads the Verizon SMB initial-access table, so exposed software should not wait for a quarterly review. A website vulnerability scanner is most useful when it runs repeatedly and feeds a remediation queue rather than producing a one-time report.
- Protect identity and email together. Enforce MFA broadly, remove stale accounts, protect privileged access, and verify sensitive payment or credential-reset requests through a second channel.
- Inventory third-party access. Know which MSPs, SaaS tools, plugins, ecommerce extensions, contractors, and integrations can reach production systems or customer data.
- Reduce unnecessary attack surface. Delete unused plugins, old accounts, abandoned subdomains, stale API endpoints, and software that no longer has an owner.
- Prioritize exploited and reachable vulnerabilities first. A high CVSS score on an isolated system is not automatically more urgent than a lower-scored flaw on a public asset with active exploitation.
- Back up for recovery, not compliance. Keep offline or isolated copies, test restores, and document who can trigger recovery during an incident.
- Measure whether the controls actually work. Track patch time, MFA coverage, exposed assets, third-party accounts, recovery tests, and repeat findings rather than counting purchased tools.
For the operational cadence behind repeated testing, see Continuous Vulnerability Scanning.
Phishing and social engineering statistics for small businesses
Phishing deserves its own section because different reports measure it at different stages of an incident. In Verizon’s 2026 SMB dataset, phishing represented 9% of measured initial access. That figure is not contradicted by Sophos reporting phishing at 24% of ransomware root causes across all organization sizes, because the reports use different populations and taxonomies. Sophos separately placed malicious email at 26%, meaning those two email-driven categories together accounted for half of ransomware incidents in its 2026 survey.
For a small business, the semantic distinction matters operationally. Phishing can lead directly to credential theft, session compromise, fraudulent payments, malware delivery, or a later ransomware event. A percentage measured as “initial access” should not be added to a percentage measured as “root cause” to create a new total. Instead, the repeated appearance of email and credentials across multiple datasets supports controls such as phishing-resistant MFA for privileged users, domain authentication, attachment and URL filtering, and secondary verification for payment or account-change requests.
Hiscox adds a consequence-based measure: 33% of SMEs in its 2025 survey said they faced a substantial fine following an attack. That is not a phishing-specific penalty, but it illustrates why social engineering can create downstream regulatory and financial consequences when it leads to data exposure.
Cybersecurity spending and preparedness statistics
The best current preparedness data is not a single maturity score. Coalition’s 2025 study of 1,000 small businesses found a pattern of concern without equivalent investment: 87% were very or somewhat concerned about cyber exposure over the next 12 months, 83% believed their risk had grown over the previous year, and 79% had experienced at least one attack in five years. Even so, 64% did not think their businesses were attractive targets.
The resource figures sharpen that gap. 59% of respondents spent fewer than 10 hours per week on cybersecurity activities, and 74% allocated less than 10% of their total business budget to cybersecurity. Coalition also found that 59% believed their cybersecurity spending was the right amount. This does not prove a universal “underinvestment percentage,” but it does show why perceived adequacy and actual coverage should be measured separately.
| Coalition 2025 readiness measure | Figure | Meaning |
|---|---|---|
| Concerned about cyber threats in next 12 months | 87% | Awareness is already high |
| Believe cyber risk increased in prior year | 83% | Most respondents see worsening risk |
| Experienced at least one cyberattack in five years | 79% | Long-horizon exposure is common |
| Do not think they are attractive targets | 64% | Target perception remains low despite experience |
| Spend under 10 hours/week on cybersecurity | 59% | Limited operational time |
| Allocate under 10% of total business budget to cybersecurity | 74% | Budget allocation remains constrained |
| Believe current cybersecurity spending is the right amount | 59% | Perceived adequacy does not necessarily equal coverage |
Coalition also asked what respondents thought a cyberattack would cost: 30% expected less than $500,000, 39% expected between $500,000 and $2 million, and 31% expected more than $2 million. The wide distribution is useful because it shows that small businesses do not share a consistent view of incident economics. It is more defensible than publishing one universal “average cyberattack cost” that mixes ransomware, fraud, downtime, legal costs, and breach response.
MFA adoption and the identity-security gap
Identity control data shows why adoption percentages alone can be misleading. ITRC reported that implementation of critical security measures such as MFA declined from 33.6% in 2024 to 27.2% in 2025 among its surveyed small-business population. Sophos, meanwhile, reported that MFA was present in some capacity in 97% of ransomware incidents where compromised credentials were the root cause. These two figures refer to different populations, but together they show the two problems a small business has to solve: getting MFA deployed broadly and making sure the deployment actually covers the accounts and attack paths that matter.
Coverage should include administrators, remote access, email, finance systems, cloud consoles, domain registrars, hosting panels, and third-party support accounts. Stronger factors such as passkeys or hardware-backed authentication are preferable for privileged access because they reduce the phishing and session-abuse paths that weaker implementations can leave open. The goal is not an MFA checkbox; it is eliminating password-only paths to high-impact systems.
Cyber insurance statistics need careful interpretation
Competing small-business statistics pages often publish a single cyber-insurance adoption percentage, but those figures vary sharply by country, company size, survey population, and whether partial coverage counts as insured. That makes a universal “only X% of small businesses have cyber insurance” claim unreliable unless the article names the geography and source. For this page, insurance is treated as a resilience control rather than a headline prevalence statistic.
The more useful evidence comes from actual incident-cost research. ITRC found that 38.3% of small-business leaders in its 2025 survey raised prices to absorb recovery costs, while more than one-third of breached respondents reported impacts above $500,000. Insurance can transfer part of that financial exposure, but it does not replace patching, identity controls, backups, or vendor management. Policy conditions may also require those controls before a claim is covered.
What changed from small business cybersecurity statistics in 2024 and 2025?
Searches for “small business cybersecurity statistics 2024” and “must know small business cybersecurity statistics for 2025” still surface because many widely quoted figures originated in older reports. The correct approach is not to erase historical numbers but to label them. The 2026 evidence changes several narratives that were common in older lists.
- Vulnerability exploitation moved to the front of breach entry. Verizon’s 2026 DBIR reports vulnerability exploitation as the leading entry point overall, and its SMB dataset places it at 26%.
- Ransomware outcomes show a size gap. Sophos 2026 provides a direct 34% versus 46% comparison for stopping attacks before encryption or extortion.
- Email and identity became more prominent ransomware root causes. Sophos reported malicious email at 26%, phishing at 24%, compromised credentials at 23%, and exploited vulnerabilities at 18% across its ransomware-victim population.
- AI-related claims became more common but remain methodology-sensitive. Hiscox and ITRC both report AI-linked survey findings, which should be labeled as respondent-reported attribution rather than universal forensic telemetry.
- Source auditing matters more. The “60% close within six months” and “43% of attacks target small businesses” claims continue to rank despite weak or disputed lineage, so newer pages should prefer directly measurable SMB outcomes.
This is why a 2026 statistics page should not simply update the year in a 2024 article. The underlying measures, attack paths, and source quality have changed.
What the statistics mean for an SMB security roadmap
The data supports a practical order of operations. First, close internet-facing vulnerabilities because exploitation leads the Verizon SMB initial-access table. Second, improve identity and email controls because Sophos shows how heavily ransomware now depends on those paths. Third, review third-party access because vendor involvement appears in more than half of SMB breaches in Verizon’s dataset. Fourth, reduce unnecessary software, plugins, integrations, and public endpoints so a small team has less to monitor. Finally, test recovery so an incident does not become an existential outage.
The sequence matters because small businesses rarely have the budget to pursue every security program at once. Risk reduction comes from shrinking the number of reachable weaknesses and shortening the time they remain exposed. A recurring scan, a disciplined patch queue, full MFA coverage, tested backups, and a current third-party inventory create more measurable protection than a long list of products with no operating cadence.
Methodology and sources
This page treats “small business cybersecurity statistics” as a source-audit problem rather than a number-collection exercise. The methodology follows six rules: use primary or first-party research where possible; state the population and denominator; separate survey self-report from investigated incident data; separate SMB-specific figures from all-size figures; distinguish attack attempts from confirmed breaches; and reject popular numbers when their source lineage cannot be reproduced.
Primary sources used in this update include Sophos State of Ransomware 2026, Verizon Data Breach Investigations Report, Hiscox Cyber Readiness Report 2025, ITRC 2025 Business Impact Report, Coalition Small Business Cybersecurity Study, IBM Cost of a Data Breach research, and the National Cybersecurity Alliance correction to the “60% close within six months” claim.
Figures from 2025 are retained when they are the latest source-specific SMB measurement or when they provide clearly labeled historical context. They are not relabeled as 2026 data.
Frequently asked questions
What percentage of cyberattacks target small businesses?
There is no reliable current percentage for the share of every cyberattack worldwide that targets small businesses. Better measurements include Verizon’s SMB breach data, where vulnerability exploitation led initial access at 26%, and Sophos’s size comparison, where only 34% of organizations with 100 to 250 employees stopped ransomware before encryption or extortion.
How common are cyberattacks against small businesses?
Hiscox reported that 59% of SMEs surveyed experienced a cyberattack in the previous 12 months. ITRC reported that 81% of surveyed small businesses had suffered a security breach, a data breach, or both in the prior year. Coalition found that 79% of its surveyed small businesses had experienced at least one cyberattack in five years.
How much does a cyberattack cost a small business?
There is no single universal average. In ITRC’s 2025 small-business survey, 62.5% of breached respondents reported total financial impact above $250,000 and 36.7% reported more than $500,000. These measures should not be combined with all-size ransomware recovery averages.
Do 60% of small businesses close within six months of a cyberattack?
No verified primary source supports that claim. The National Cybersecurity Alliance publicly stated that the figure did not come from its research, that it could not verify the original source, and that it does not recommend continuing to use it.
What is the biggest cyber threat to small businesses?
No single threat explains every small-business breach. In Verizon’s 2026 SMB dataset, vulnerability exploitation was the leading initial-access vector at 26%, followed by credential abuse at 13% and phishing at 9%.
How important is third-party risk for small businesses?
Very important. Third-party involvement appeared in 55% of SMB breaches in Verizon’s 2026 DBIR dataset.
Are AI-powered attacks increasing small business risk?
Survey data indicates growing AI-related concern and reported impact, but attribution should be worded carefully. Hiscox reported that 57% of SMEs surveyed said they had experienced a cyberattack due to AI vulnerabilities, while ITRC reported AI-powered attacks as a root cause in more than 40% of cyber events reported by respondents.
What cybersecurity controls should a small business prioritize first?
Prioritize patching of internet-facing software, broad MFA and identity coverage, email security, third-party access review, backups with tested restoration, attack-surface reduction, and recurring vulnerability scanning.


