Small Business Cybersecurity Statistics 2026: Verified Data

ObaidaAlsulaiman

Obaida Al-Sulaiman, Information Security Manager at ScanTitan,

Small Business Cybersecurity Statistics (2026) Verified Data
Table of Contents
Small business cybersecurity statistics are easy to inflate because surveys, investigated breaches, blocked attacks, ransomware incidents, and financial-loss estimates all measure different things. The clearest 2026 picture is more useful than the viral numbers: smaller organizations stop fewer ransomware attacks before damage, vulnerability exploitation leads breach entry in Verizon’s SMB dataset, third parties appear in more than half of SMB breaches, and several surveys show a large gap between how worried small businesses are and how much time or budget they devote to security. This report separates those measurements and traces each major figure to a named source.

Short answer: In Sophos State of Ransomware 2026, only 34% of organizations with 100 to 250 employees stopped a ransomware attack before encryption or extortion, compared with 46% of organizations with 3,001 to 5,000 employees. In Verizon’s 2026 DBIR SMB dataset, vulnerability exploitation was the leading initial-access vector at 26%. Coalition’s 2025 small-business survey found that 79% had experienced at least one cyberattack in five years, yet 64% still did not consider themselves attractive targets.

Updated September 2026. Figures are labeled as SMB-specific, all-size, survey-based, or incident-based so they are not blended into one false “small business attack rate.”

Key small business cybersecurity statistics at a glance

The table below is designed to be quotable without stripping away the denominator. Where a statistic applies to all organization sizes rather than SMBs specifically, that limitation is stated directly.

Statistic Figure What it measures Data period Source
Small organizations stopping ransomware before encryption or extortion 34% Organizations with 100 to 250 employees 2026 survey Sophos State of Ransomware 2026
Larger organizations stopping ransomware before encryption or extortion 46% Organizations with 3,001 to 5,000 employees 2026 survey Sophos
SMB breach initial access from vulnerability exploitation 26% Leading initial-access vector in Verizon SMB dataset Nov 2024 to Oct 2025 Verizon 2026 DBIR
SMB breach initial access from credential abuse 13% Second initial-access vector in SMB dataset Nov 2024 to Oct 2025 Verizon 2026 DBIR
SMB breach initial access from phishing 9% Phishing as initial-access vector Nov 2024 to Oct 2025 Verizon 2026 DBIR
Third-party involvement in SMB breaches 55% Share of SMB breaches involving a third party Nov 2024 to Oct 2025 Verizon 2026 DBIR
Human element in SMB breaches 45% Verizon “human element,” not “human error” Nov 2024 to Oct 2025 Verizon 2026 DBIR
SMEs reporting a cyberattack in previous 12 months 59% Self-reported survey of almost 6,000 small businesses 2025 Hiscox Cyber Readiness Report
Small businesses reporting a security or data breach 81% Survey of 662 owners/executives at firms with 500 or fewer employees 2025 ITRC Business Impact Report
Small businesses experiencing at least one attack in five years 79% Survey of 1,000 small businesses 2025 Coalition Small Business Cybersecurity Study
Small businesses that do not think they are attractive targets 64% Perception of target attractiveness 2025 Coalition
Small businesses concerned about cyber threats in next 12 months 87% Very or somewhat concerned 2025 Coalition
Small businesses saying risk increased over prior year 83% Perception of rising risk 2025 Coalition
Small businesses spending under 10 hours a week on cybersecurity 59% Time devoted to cybersecurity activity 2025 Coalition
Small businesses allocating under 10% of total business budget to cybersecurity 74% Surveyed budget allocation 2025 Coalition
Ransomware attacks starting with an identity-based approach 79% All organization sizes, not SMB-only 2026 Sophos
Ransomware attacks that encrypted data 56% All organization sizes 2026 Sophos
Encrypted ransomware victims that paid 48% All sizes; denominator is encrypted victims 2026 Sophos
Average ransomware recovery cost $1.7M All organization sizes; excludes ransom 2026 Sophos
Small businesses with breach impact above $250,000 62.5% Among breached small businesses surveyed 2025 ITRC
Small businesses with breach impact above $500,000 36.7% Among victims in ITRC survey 2025 ITRC
Small businesses raising prices to absorb cyber incident costs 38.3% Business response to recovery cost 2025 ITRC

What these small business cybersecurity statistics actually measure

Most ranking pages mix attack attempts, confirmed breaches, surveys, insurance claims, and ransomware outcomes as though they were interchangeable. They are not. A survey saying 59% of SMEs experienced a cyberattack does not mean 59% suffered a verified data breach, and a breach dataset does not measure every attack that failed. This distinction is one of the biggest reasons small business cyber statistics disagree across publishers.

  • Survey self-report: Hiscox, Coalition, and ITRC ask business owners or security decision-makers what they experienced or believe.
  • Incident and breach analysis: Verizon DBIR analyzes reported incidents and confirmed breaches.
  • Ransomware victim surveys: Sophos surveys organizations that were hit by ransomware.
  • All-size figures: A statistic such as the $1.7 million average ransomware recovery cost should not be relabeled as “the average small-business cyberattack cost.”

How often are small businesses attacked?

No single current percentage measures the share of every small business worldwide that is successfully attacked. Hiscox’s 2025 Cyber Readiness Report surveyed almost 6,000 small businesses across seven countries and found that 59% reported a cyberattack in the previous 12 months. The ITRC surveyed 662 U.S. small-business owners or executives at organizations with 500 or fewer employees and reported that 81% had suffered a security breach, a data breach, or both during the prior year.

Coalition’s 2025 study adds a longer time horizon. Among 1,000 small businesses surveyed globally, 79% said they had experienced at least one cyberattack in the previous five years. These results do not merge into a universal “attack rate” because the questionnaires, locations, definitions, and periods differ.

Primary sources: Hiscox Cyber Readiness Report 2025, ITRC 2025 Business Impact Report, and Coalition Small Business Cybersecurity Study.

The small business cyber risk perception gap

Coalition found that 87% of surveyed small businesses were very or somewhat concerned about cyber threats over the coming year, and 83% believed their risk had increased during the prior year. Yet 64% still did not believe they were attractive targets to threat actors. The same study reported that 59% spent fewer than 10 hours per week on cybersecurity activities and 74% allocated less than 10% of their total business budget to cybersecurity.

The numbers describe a readiness problem more precisely than the old claim that small businesses simply “do not care” about security. Many leaders understand that cyber risk is rising but still underestimate their own exposure or have difficulty turning concern into controls.

Why small businesses bear a heavy share of cybersecurity risk
Small businesses face the same internet-scale attack pressure with fewer defensive resources.

How small businesses get breached

Verizon’s 2026 DBIR gives the clearest current breakdown of initial access in its small-business dataset. Vulnerability exploitation led at 26%, credential abuse followed at 13%, and phishing accounted for 9%. Third-party involvement appeared in 55% of SMB breaches, while the “human element” appeared in 45%. The human-element figure should not be rewritten as “45% were caused by human error”; Verizon’s category is broader than that.

Why the 26% figure matters: vulnerability exploitation is not just a general enterprise problem. In the SMB dataset it is the largest measured initial-access route, which means patch latency, exposed software, unsupported systems, and internet-facing applications deserve first-order attention.
Vulnerability exploitation leads SMB breach entry at 26 percent, followed by credential abuse at 13 percent and phishing at 9 percent

For the wider disclosure and exploitation picture, including CVE growth, CISA KEV, EPSS, and exploitation timing, see our Vulnerability Statistics research. When a team has more findings than it can fix, our guide on How to Prioritize Vulnerability Remediation explains how to move from raw severity to exploitability and exposure.

Third-party risk is now a small business security problem

Third-party involvement in 55% of the Verizon SMB breaches is one of the most important statistics on this page because it changes what “small business cybersecurity” means. A company can patch its laptops and still inherit exposure through a managed service provider, website plugin, SaaS integration, payment provider, cloud service, outsourced IT account, or compromised vendor credential.

More than half of SMB breaches involve a third party

The practical response is not to eliminate vendors. It is to inventory them, remove unused access, require strong authentication, review privileged integrations, and know which third parties can reach customer data or production systems.

Ransomware statistics for small businesses

Ransomware and small business cybersecurity statistics

Ransomware remains the clearest place where organization size changes outcomes. Sophos State of Ransomware 2026 surveyed 2,158 IT and security leaders from organizations that had experienced ransomware in the prior 12 months. Only 34% of organizations with 100 to 250 employees stopped the attack before encryption or extortion, compared with 46% among organizations with 3,001 to 5,000 employees.

Across all organization sizes, 56% of ransomware attacks succeeded in encrypting data, up from 50% the previous year. Among organizations whose data was encrypted, 48% paid a ransom. The average recovery cost reached $1.7 million, excluding ransom payments. These are not SMB-only averages and should not be presented that way.

For the broader attack, payment, encryption, recovery-cost, and group activity data, see our Ransomware Statistics report.

The shift to identity, email, and incomplete MFA coverage

The shift to identity and email in ransomware attacks

Sophos reported a major change in ransomware root cause for 2026. Malicious email accounted for 26% of incidents and phishing for 24%, while compromised credentials represented 23% and exploited vulnerabilities 18%. Across the report, 79% of ransomware attacks began with an identity-based approach. These figures apply across organization sizes rather than SMBs alone.

Sophos also reported that MFA was deployed in some capacity in 97% of incidents where compromised credentials were the ransomware root cause. That does not mean MFA is ineffective. It means partial deployment, bypassable factors, uncovered accounts, session theft, and other identity gaps can still leave a path through.

AI and small business cybersecurity statistics

AI-related statistics deserve more caution than most categories because many current figures are survey perceptions rather than directly observed attribution. Hiscox reported that 57% of SMEs surveyed said they had experienced a cyberattack due to AI vulnerabilities. ITRC’s 2025 Business Impact Report said AI-powered attacks were identified as a root cause in more than 40% of cyber events reported by respondents. Those figures should be quoted as survey findings, not as proof that an independent forensic investigation attributed that share of all attacks to artificial intelligence.

The strongest takeaway is operational rather than sensational: generative AI can lower the cost of producing convincing phishing, accelerate reconnaissance, and expand the number of automated attempts a small team must filter.

The cost of cyberattacks on small businesses

Cost is where statistics pages most often compare unlike populations. ITRC provides one of the more directly SMB-specific 2025 views: among small businesses that suffered a breach, 62.5% reported total financial impact above $250,000, and 36.7% reported costs above $500,000. The report also found that 38.3% of small-business leaders raised prices to absorb the financial effects of an incident.

IBM’s earlier Cost of a Data Breach research reported an average of roughly $3.31 million for organizations with fewer than 500 employees. Sophos adds a different measure: average ransomware recovery cost reached $1.7 million across all organization sizes in 2026, excluding ransom payments.

Do not combine these numbers. A breach-cost average, a ransomware-recovery average, and an SMB survey of financial impact answer different questions.

Website, WordPress, WooCommerce, and API exposure for SMBs

Small businesses increasingly run on public software stacks rather than on isolated internal networks. A brochure site can still expose a CMS, plugins, contact forms, hosting panels, third-party scripts, and login endpoints. An online store adds payment workflows and extensions. A SaaS company adds public APIs and cloud integrations.

For the broader web attack surface, our Website Hacking Statistics page separates bot traffic, attack attempts, compromises, and vulnerability disclosures. WordPress-heavy businesses should also review WordPress Plugin Vulnerability Statistics, which focuses on the plugin ecosystem rather than incorrectly treating every WordPress flaw as a core vulnerability.

Small online stores have a second layer of plugin and extension exposure around checkout, payments, subscriptions, and ecommerce administration. Our WooCommerce Vulnerability Statistics report separates WooCommerce core records from third-party extensions and the wider WordPress ecosystem.

For SaaS products, mobile backends, ecommerce integrations, and public services, the API layer creates its own authorization and inventory problems. Our API Security Statistics report covers API incidents, attack volume, exploited vulnerabilities, and visibility gaps without mixing those metrics into generic website attack counts.

Small business vs large organization: the cybersecurity size gap

The most defensible “small businesses are more vulnerable” claim is not that a fixed percentage of every cyberattack targets them. It is that current datasets show measurable differences in defensive outcomes and resources.

Measure Small organization Larger organization / context Source
Stopped ransomware before encryption or extortion 34% at 100 to 250 employees 46% at 3,001 to 5,000 employees Sophos 2026
Cybersecurity time commitment 59% spend under 10 hours/week Small-business survey measure Coalition 2025
Cybersecurity budget allocation 74% allocate under 10% of total business budget Small-business survey measure Coalition 2025

Small business cybersecurity statistics to stop citing

A strong statistics page should remove bad numbers as aggressively as it adds new ones. These claims are still common in competing articles, but they should not be presented as current verified facts.

“60% of small businesses close within six months of a cyberattack”

The National Cybersecurity Alliance stated that this statistic did not come from its research, could not be verified, and should not continue to be cited.

“43% of all cyberattacks target small businesses”

This figure is repeated widely, but current articles often point to secondary references rather than a transparent current dataset measuring the denominator “all cyberattacks.” It is safer to use direct measurements such as Verizon’s SMB breach vectors or Sophos’s size-based ransomware outcomes.

“A small business is attacked every 7, 11, or 39 seconds”

These cadence claims usually come from dividing an annual estimate by the number of seconds in a year or from old laboratory observations of automated attempts.

“95% of breaches are caused by human error”

Verizon uses a “human element” category, which is broader and should not be rewritten as a causal human-error percentage. In the 2026 SMB dataset, the human element appeared in 45% of breaches.

How small businesses should reduce cyber risk

The data points to a short control set rather than a giant enterprise checklist. Smaller teams get more value from covering the biggest entry paths consistently than from buying many tools and leaving gaps between them.

  1. Patch internet-facing software on a schedule. Vulnerability exploitation leads the Verizon SMB initial-access table, so exposed software should not wait for a quarterly review. A website vulnerability scanner is most useful when it runs repeatedly and feeds a remediation queue rather than producing a one-time report.
  2. Protect identity and email together. Enforce MFA broadly, remove stale accounts, protect privileged access, and verify sensitive payment or credential-reset requests through a second channel.
  3. Inventory third-party access. Know which MSPs, SaaS tools, plugins, ecommerce extensions, contractors, and integrations can reach production systems or customer data.
  4. Reduce unnecessary attack surface. Delete unused plugins, old accounts, abandoned subdomains, stale API endpoints, and software that no longer has an owner.
  5. Prioritize exploited and reachable vulnerabilities first. A high CVSS score on an isolated system is not automatically more urgent than a lower-scored flaw on a public asset with active exploitation.
  6. Back up for recovery, not compliance. Keep offline or isolated copies, test restores, and document who can trigger recovery during an incident.
  7. Measure whether the controls actually work. Track patch time, MFA coverage, exposed assets, third-party accounts, recovery tests, and repeat findings rather than counting purchased tools.

For the operational cadence behind repeated testing, see Continuous Vulnerability Scanning.

Phishing and social engineering statistics for small businesses

Phishing deserves its own section because different reports measure it at different stages of an incident. In Verizon’s 2026 SMB dataset, phishing represented 9% of measured initial access. That figure is not contradicted by Sophos reporting phishing at 24% of ransomware root causes across all organization sizes, because the reports use different populations and taxonomies. Sophos separately placed malicious email at 26%, meaning those two email-driven categories together accounted for half of ransomware incidents in its 2026 survey.

For a small business, the semantic distinction matters operationally. Phishing can lead directly to credential theft, session compromise, fraudulent payments, malware delivery, or a later ransomware event. A percentage measured as “initial access” should not be added to a percentage measured as “root cause” to create a new total. Instead, the repeated appearance of email and credentials across multiple datasets supports controls such as phishing-resistant MFA for privileged users, domain authentication, attachment and URL filtering, and secondary verification for payment or account-change requests.

Hiscox adds a consequence-based measure: 33% of SMEs in its 2025 survey said they faced a substantial fine following an attack. That is not a phishing-specific penalty, but it illustrates why social engineering can create downstream regulatory and financial consequences when it leads to data exposure.

Cybersecurity spending and preparedness statistics

The best current preparedness data is not a single maturity score. Coalition’s 2025 study of 1,000 small businesses found a pattern of concern without equivalent investment: 87% were very or somewhat concerned about cyber exposure over the next 12 months, 83% believed their risk had grown over the previous year, and 79% had experienced at least one attack in five years. Even so, 64% did not think their businesses were attractive targets.

The resource figures sharpen that gap. 59% of respondents spent fewer than 10 hours per week on cybersecurity activities, and 74% allocated less than 10% of their total business budget to cybersecurity. Coalition also found that 59% believed their cybersecurity spending was the right amount. This does not prove a universal “underinvestment percentage,” but it does show why perceived adequacy and actual coverage should be measured separately.

Coalition 2025 readiness measure Figure Meaning
Concerned about cyber threats in next 12 months 87% Awareness is already high
Believe cyber risk increased in prior year 83% Most respondents see worsening risk
Experienced at least one cyberattack in five years 79% Long-horizon exposure is common
Do not think they are attractive targets 64% Target perception remains low despite experience
Spend under 10 hours/week on cybersecurity 59% Limited operational time
Allocate under 10% of total business budget to cybersecurity 74% Budget allocation remains constrained
Believe current cybersecurity spending is the right amount 59% Perceived adequacy does not necessarily equal coverage

Coalition also asked what respondents thought a cyberattack would cost: 30% expected less than $500,000, 39% expected between $500,000 and $2 million, and 31% expected more than $2 million. The wide distribution is useful because it shows that small businesses do not share a consistent view of incident economics. It is more defensible than publishing one universal “average cyberattack cost” that mixes ransomware, fraud, downtime, legal costs, and breach response.

MFA adoption and the identity-security gap

Identity control data shows why adoption percentages alone can be misleading. ITRC reported that implementation of critical security measures such as MFA declined from 33.6% in 2024 to 27.2% in 2025 among its surveyed small-business population. Sophos, meanwhile, reported that MFA was present in some capacity in 97% of ransomware incidents where compromised credentials were the root cause. These two figures refer to different populations, but together they show the two problems a small business has to solve: getting MFA deployed broadly and making sure the deployment actually covers the accounts and attack paths that matter.

Coverage should include administrators, remote access, email, finance systems, cloud consoles, domain registrars, hosting panels, and third-party support accounts. Stronger factors such as passkeys or hardware-backed authentication are preferable for privileged access because they reduce the phishing and session-abuse paths that weaker implementations can leave open. The goal is not an MFA checkbox; it is eliminating password-only paths to high-impact systems.

Cyber insurance statistics need careful interpretation

Competing small-business statistics pages often publish a single cyber-insurance adoption percentage, but those figures vary sharply by country, company size, survey population, and whether partial coverage counts as insured. That makes a universal “only X% of small businesses have cyber insurance” claim unreliable unless the article names the geography and source. For this page, insurance is treated as a resilience control rather than a headline prevalence statistic.

The more useful evidence comes from actual incident-cost research. ITRC found that 38.3% of small-business leaders in its 2025 survey raised prices to absorb recovery costs, while more than one-third of breached respondents reported impacts above $500,000. Insurance can transfer part of that financial exposure, but it does not replace patching, identity controls, backups, or vendor management. Policy conditions may also require those controls before a claim is covered.

What changed from small business cybersecurity statistics in 2024 and 2025?

Searches for “small business cybersecurity statistics 2024” and “must know small business cybersecurity statistics for 2025” still surface because many widely quoted figures originated in older reports. The correct approach is not to erase historical numbers but to label them. The 2026 evidence changes several narratives that were common in older lists.

  • Vulnerability exploitation moved to the front of breach entry. Verizon’s 2026 DBIR reports vulnerability exploitation as the leading entry point overall, and its SMB dataset places it at 26%.
  • Ransomware outcomes show a size gap. Sophos 2026 provides a direct 34% versus 46% comparison for stopping attacks before encryption or extortion.
  • Email and identity became more prominent ransomware root causes. Sophos reported malicious email at 26%, phishing at 24%, compromised credentials at 23%, and exploited vulnerabilities at 18% across its ransomware-victim population.
  • AI-related claims became more common but remain methodology-sensitive. Hiscox and ITRC both report AI-linked survey findings, which should be labeled as respondent-reported attribution rather than universal forensic telemetry.
  • Source auditing matters more. The “60% close within six months” and “43% of attacks target small businesses” claims continue to rank despite weak or disputed lineage, so newer pages should prefer directly measurable SMB outcomes.

This is why a 2026 statistics page should not simply update the year in a 2024 article. The underlying measures, attack paths, and source quality have changed.

What the statistics mean for an SMB security roadmap

The data supports a practical order of operations. First, close internet-facing vulnerabilities because exploitation leads the Verizon SMB initial-access table. Second, improve identity and email controls because Sophos shows how heavily ransomware now depends on those paths. Third, review third-party access because vendor involvement appears in more than half of SMB breaches in Verizon’s dataset. Fourth, reduce unnecessary software, plugins, integrations, and public endpoints so a small team has less to monitor. Finally, test recovery so an incident does not become an existential outage.

The sequence matters because small businesses rarely have the budget to pursue every security program at once. Risk reduction comes from shrinking the number of reachable weaknesses and shortening the time they remain exposed. A recurring scan, a disciplined patch queue, full MFA coverage, tested backups, and a current third-party inventory create more measurable protection than a long list of products with no operating cadence.

Methodology and sources

This page treats “small business cybersecurity statistics” as a source-audit problem rather than a number-collection exercise. The methodology follows six rules: use primary or first-party research where possible; state the population and denominator; separate survey self-report from investigated incident data; separate SMB-specific figures from all-size figures; distinguish attack attempts from confirmed breaches; and reject popular numbers when their source lineage cannot be reproduced.

Primary sources used in this update include Sophos State of Ransomware 2026, Verizon Data Breach Investigations Report, Hiscox Cyber Readiness Report 2025, ITRC 2025 Business Impact Report, Coalition Small Business Cybersecurity Study, IBM Cost of a Data Breach research, and the National Cybersecurity Alliance correction to the “60% close within six months” claim.

Figures from 2025 are retained when they are the latest source-specific SMB measurement or when they provide clearly labeled historical context. They are not relabeled as 2026 data.

Frequently asked questions

What percentage of cyberattacks target small businesses?

There is no reliable current percentage for the share of every cyberattack worldwide that targets small businesses. Better measurements include Verizon’s SMB breach data, where vulnerability exploitation led initial access at 26%, and Sophos’s size comparison, where only 34% of organizations with 100 to 250 employees stopped ransomware before encryption or extortion.

How common are cyberattacks against small businesses?

Hiscox reported that 59% of SMEs surveyed experienced a cyberattack in the previous 12 months. ITRC reported that 81% of surveyed small businesses had suffered a security breach, a data breach, or both in the prior year. Coalition found that 79% of its surveyed small businesses had experienced at least one cyberattack in five years.

How much does a cyberattack cost a small business?

There is no single universal average. In ITRC’s 2025 small-business survey, 62.5% of breached respondents reported total financial impact above $250,000 and 36.7% reported more than $500,000. These measures should not be combined with all-size ransomware recovery averages.

Do 60% of small businesses close within six months of a cyberattack?

No verified primary source supports that claim. The National Cybersecurity Alliance publicly stated that the figure did not come from its research, that it could not verify the original source, and that it does not recommend continuing to use it.

What is the biggest cyber threat to small businesses?

No single threat explains every small-business breach. In Verizon’s 2026 SMB dataset, vulnerability exploitation was the leading initial-access vector at 26%, followed by credential abuse at 13% and phishing at 9%.

How important is third-party risk for small businesses?

Very important. Third-party involvement appeared in 55% of SMB breaches in Verizon’s 2026 DBIR dataset.

Are AI-powered attacks increasing small business risk?

Survey data indicates growing AI-related concern and reported impact, but attribution should be worded carefully. Hiscox reported that 57% of SMEs surveyed said they had experienced a cyberattack due to AI vulnerabilities, while ITRC reported AI-powered attacks as a root cause in more than 40% of cyber events reported by respondents.

What cybersecurity controls should a small business prioritize first?

Prioritize patching of internet-facing software, broad MFA and identity coverage, email security, third-party access review, backups with tested restoration, attack-surface reduction, and recurring vulnerability scanning.

Want vulnerability scanning that prioritizes for you?

ScanTitan continuously matches your site against the CVE/NVD database, then ranks findings by real-world exploitability — so you patch what matters first.

o

Information Security Manager · Dubai, UAE · 12+ years InfoSec experience

Obaida specialises in web application security, vulnerability management, and external attack surface reduction for SMB and mid-market organisations. All ScanTitan content is reviewed against live scan findings before publication.

Share :

Facebook
LinkedIn

Continue reading