Small Business Cybersecurity Statistics 2026: Verified Data

Small Business Cybersecurity Statistics (2026) Verified Data
ObaidaAlsulaiman

Information Security Manager · CISSP · CEH · OSCP

Table of Contents

Small business cybersecurity statistics are quoted constantly and sourced carelessly, which is how a viral claim like “60% of small businesses close within six months of an attack” outlived the organization that disowned it. This page collects the numbers that survive a source check, separates confirmed incident data from surveys, and names the ones to retire. The verified picture is serious enough without exaggeration: small and mid sized businesses (SMBs) stop fewer ransomware attacks before damage is done, absorb a heavy recovery burden, and face the same automated and identity driven threats as larger firms with fewer resources to counter them.

Short answerIn Sophos State of Ransomware 2026, only 34% of small organizations with 100 to 250 employees stopped a ransomware attack before encryption or extortion, against 46% at organizations of 3,001 to 5,000 employees. In Verizon’s 2026 DBIR small business dataset, vulnerability exploitation was the leading breach entry vector at 26%. The claim that 60% of small businesses close within six months is not supported by any primary source.

Last updated: August 2026. This page is a source audit, reviewed quarterly. You are welcome to cite it with a link back to ScanTitan.

Key small business cybersecurity statistics at a glance

Each row states the figure, what it actually measures, the year of the underlying data, and the source, so an editor can quote it without misreading it. Where a figure is an all sizes average rather than SMB specific, the row says so.

Metric Figure What it measures Data year Source
Small orgs stopping ransomware before encryption or extortion 34% Organizations with 100 to 250 employees that stopped the attack 2026 Sophos State of Ransomware 2026
Larger orgs stopping ransomware before encryption or extortion 46% Organizations with 3,001 to 5,000 employees, for contrast 2026 Sophos State of Ransomware 2026
SMB breach initial access: vulnerability exploitation 26% Leading initial-access vector in the SMB dataset Nov 2024 to Oct 2025 Verizon 2026 DBIR
SMB breach initial access: credential abuse 13% Second initial-access vector, SMB dataset Nov 2024 to Oct 2025 Verizon 2026 DBIR
Third-party involvement in SMB breaches 55% Share of SMB breaches involving a third party Nov 2024 to Oct 2025 Verizon 2026 DBIR
Ransomware attacks starting with an identity approach 79% All sizes, not SMB-only 2026 Sophos State of Ransomware 2026
Encrypted victims that paid the ransom 48% All sizes; of organizations whose data was encrypted 2026 Sophos State of Ransomware 2026
Average ransomware recovery cost per incident $1.7M All sizes, not SMB-only; up 11% year over year 2026 Sophos State of Ransomware 2026
SMB breaches involving ransomware (historical) 88% Share of SMB breaches with a ransomware component 2025 Verizon 2025 DBIR
Average breach cost, org under 500 employees $3.31M Organization-level breach cost for smaller firms 2024 IBM

What these numbers actually measure

Small business statistics get misused when different measurements are treated as the same thing. Four distinctions carry most of the risk on this topic.

  • Attack rates vs breach rates. Read a survey figure such as a share of firms reporting an attack as attempts reported by respondents, not as confirmed breaches. An attempted attack is not a compromise.
  • Survey self-report vs incident data. Treat Hiscox and similar figures as self reported surveys, and Verizon DBIR and Sophos incident data as analysis of investigated attacks. The two answer different questions and should not be blended into one total.
  • Ransomware involved vs ransomware caused. Note that a figure like “ransomware present in a share of breaches” means ransomware was involved, not that it was always the initial entry point. Entry vectors are measured separately.
  • All sizes vs SMB specific. Do not benchmark a small firm against an all sizes average. Several current ransomware figures, including the 48% payment rate and the 1.7 million dollar recovery cost, are all sizes numbers, and this page labels them as such.

How often are small businesses attacked?

Small businesses face the same automated and identity driven threat environment as larger firms, usually with fewer defensive resources. Survey research consistently shows a large share reporting incidents: the Hiscox Cyber Readiness Report 2025 recorded that 59% of small and mid sized enterprises reported at least one cyberattack in the prior 12 months, and the Identity Theft Resource Center (ITRC) 2025 Business Impact Report found that 81% of small business owners and executives said they had experienced a security breach, a data breach, or both in the past year. These are self reported survey numbers, higher than confirmed incident counts, and are labeled here as surveys rather than presented as breach rates.

The pattern beneath the numbers is a capability gap, not a belief problem alone. Attackers apply automation broadly, and smaller firms are the softer target, so they carry a disproportionate share of the damage even when they are not singled out by name. A lean team running the same public software as everyone else sits under the same automated pressure as a large enterprise without the same ability to absorb it.

Why small businesses bear a heavy share

Why small businesses bear a heavy share

The clearest current evidence of the size gap comes from ransomware outcomes. Sophos State of Ransomware 2026, a vendor agnostic survey of 2,158 information technology and security leaders across 17 countries whose organizations were hit by ransomware in the prior year, found that only 34% of small organizations with 100 to 250 employees stopped an attack before encryption or extortion, well behind the 46% success rate at organizations of 3,001 to 5,000 employees. Larger enterprises generally benefit from more security staffing, wider monitoring, and stronger incident response, which buys measurably better outcomes.

The data shows that SMBs are not merely incidental victims; they represent a substantial share of organizations affected by ransomware and other common breach patterns, and they are less able to stop an attack before it does damage. That is a statement the evidence supports, without claiming that attackers deliberately single out every small firm.

Ransomware and small business

Ransomware and small business

Ransomware is the defining SMB threat, and 2026 data sharpens the picture while shifting some of the older framing.

  • Encryption is climbing even as payments fall. Sophos State of Ransomware 2026 reported that 56% of attacks succeeded in encrypting data, up from 50% the year before, while 48% of organizations whose data was encrypted paid the ransom, the second lowest rate on record. Both figures are all sizes numbers, not SMB specific.
  • Recovery costs remain heavy. Sophos put the average recovery cost per incident at 1.7 million dollars across all organization sizes, up 11% year over year. As a 2025 historical reference for the small business band specifically, Sophos State of Ransomware 2025 reported an average recovery cost of 638,536 dollars for organizations with 100 to 250 employees, excluding any ransom paid.
  • Identity is now the leading way in. Sophos found that 79% of ransomware attacks started with an identity based approach, with compromised identities overtaking exploited vulnerabilities as the top root cause for the first time in four years. For historical context, Verizon’s 2025 DBIR found ransomware present in 88% of SMB breaches against 39% at large organizations; that is a 2025 figure and is cited here as a dated comparison, not as the current 2026 headline.

The shift to identity and email

The shift to identity and email

The 2026 data marks a real change in how ransomware attacks begin, and it reshapes where a small firm should spend first. Sophos State of Ransomware 2026 found that, for the first time in four years, exploited software vulnerabilities were no longer the top root cause across all organization sizes. The ranking instead placed malicious email at 26% and phishing at 24%, which together account for half of all incidents, followed by compromised credentials at 23% and exploited vulnerabilities at 18%, down 14 percentage points year over year, with brute force attacks at 6%. These are all sizes figures, not SMB specific, but the direction applies broadly: identity and email have become the dominant entry points. For a small team, that argues for advanced email protection, authentication standards such as DMARC, DKIM, and SPF, and user awareness training alongside patching, rather than treating patching as the whole program.

The cost of a small business breach

Cost is where careless benchmarking does the most damage. IBM’s Cost of a Data Breach research reported an average of about 3.31 million dollars for organizations with fewer than 500 employees, well below the all sizes global average. Both are averages across wide ranges, and neither is the cost of a single hacked website. The Sophos recovery figures above tell the same story from the ransomware angle: the headline recovery cost is an all sizes number, while the small business band, where it is reported separately, sits lower in absolute terms but far higher relative to a small firm’s revenue.

The financial shock is compounded by non financial damage. Search visibility drops when a search engine flags malware or spam, blocklisting cuts off email and browser access, and reputation damage lingers after systems are clean. For a small firm running on thin margins with no rehearsed recovery plan, any of these can turn a contained incident into an extended crisis.

How small businesses get breached

The entry points are measurable, and they argue for a layered defense rather than any single control. In Verizon’s 2026 DBIR small business dataset, which the report describes as covering 7,256 incidents and 7,152 confirmed breaches, exploitation of vulnerabilities was the leading initial access vector at 26%, followed by credential abuse at 13% and phishing at 9%. Third party involvement appeared in 55% of these breaches, and the human element in 45%. For the deeper treatment of which vulnerabilities matter and how quickly they are exploited, see our vulnerability statistics page.

More than half of SMB breaches involve a third party

Two implications follow. First, vulnerability exploitation leading the list means unpatched, internet facing software is a productive door for attackers, which a scheduled website vulnerability scanner is built to close. Second, credential abuse and phishing together remain a large share, and Sophos 2026 adds an important nuance: multi factor authentication (MFA) was deployed in some capacity in 97% of incidents where compromised credentials were the root cause, which shows that partial or bypassable MFA still leaves exposure. The lesson is coverage and layering, not a single switch. For the many small firms running WordPress, platform specific coverage such as a WordPress vulnerability scanner narrows a common exposure, and our website hacking statistics page covers website and content management system risk in depth.

Vulnerability exploitation leads SMB breach entry — 26% 13% 9%

The small business readiness gap

The data repeatedly shows that defensive outcomes improve with capability, and small firms tend to have the least of it. Sophos 2026 framed the takeaway directly: outcomes improve when identity, email, endpoint, and network defenses operate as one system rather than in isolation, and the largest gains come from closing coverage gaps rather than buying a single tool. Cyber insurance coverage among United States small businesses remains comparatively low, leaving many firms to fund recovery from operating cash. The organizations most at risk are often those that self assess as competent but have never tested a response plan or run a basic scan.

Budget is the stated blocker, but the economics favor prevention. The controls that reduce the most SMB risk are the least expensive: keep software current, enforce MFA across privileged, remote, and high risk access, reduce the plugin and software count, train staff against phishing, and scan on a schedule so exposure surfaces from your own tooling first. If a compromise has already happened, professional website malware removal is more reliable than a surface cleanup that misses server side backdoors.

Small business vs large organization: the size gap

The starkest way to read the data is side by side. The same reports that measure large enterprise outcomes show small firms stopping fewer attacks before damage and carrying a heavier relative burden.

Measure Small and mid sized business Large organization Source
Stopped ransomware before encryption or extortion 34% (100 to 250 staff) 46% (3,001 to 5,000 staff) Sophos 2026
Breaches involving ransomware (historical) 88% 39% Verizon 2025 DBIR

The gap is not explained by attackers preferring small targets in principle. It is explained by capability: large firms typically have more security staffing, segmentation, monitoring, and rehearsed recovery, while small firms often have less of each. Closing even one of those gaps measurably improves both the odds of stopping an attack and the cost of recovering from one.

Statistics to stop citing

Honest small business statistics means refusing to repeat numbers that do not hold up. Each of the following is widely circulated and should be retired.

  1. “60% of small businesses close within six months of a cyberattack.” The National Cybersecurity Alliance stated in 2022 that this figure did not come from its research, that it could not verify the original source, and that it removed references and does not recommend continued use. Its own correction is the primary record. Use current Verizon DBIR SMB data and labeled survey findings instead.
  2. “43% of cyberattacks target small businesses.” This round figure is widely repeated, but current articles often cite it without a transparent primary source methodology or with outdated sourcing. It should not be presented as a current share of all cyberattacks. Where a defensible framing is needed, describe the measured size gap in ransomware outcomes and breach patterns rather than a fixed percentage of all attacks.
  3. “A cyberattack every 11 seconds” (or every 7, or every 39). These cadence figures are usually derived by dividing an annual estimate into seconds, or are historical rather than current, and do not equal measured successful SMB breaches. The often cited “every 39 seconds” traces to a University of Maryland study from 2007 that recorded automated attack attempts against four Linux test systems, not a modern SMB or website breach rate. Use current exploitation and ransomware telemetry instead.
  4. “95% of breaches are caused by human error.” This figure is repeated without a clean, traceable primary source. Verizon’s current data uses the term “human element,” which is not the same as saying 95% of breaches are caused by human error; in the 2026 SMB dataset the human element appears in 45% of breaches. Cite the current measured figure rather than the viral one.

Source-lineage verification table

Popular claim Verdict What the source actually supports Use instead
60% of SMBs close within 6 months Do not cite The National Cybersecurity Alliance disavowed it (2022) Verizon DBIR SMB data + labeled surveys
43% of cyberattacks target SMBs Not verifiable as current Often cited without a transparent primary methodology Measured size gap in ransomware and breach data
An attack every 7 to 39 seconds Derived or historical Division of estimates, or a 2007 lab test of four Linux systems Current exploitation and ransomware telemetry
95% of breaches are human error Untraceable lineage Verizon uses “human element,” at 45% in the SMB dataset Verizon human-element figure

How small businesses reduce risk

The data points to a short, high impact checklist rather than a long program.

  1. Patch on a schedule, not on discovery. Vulnerability exploitation is the leading way SMBs get breached, so unpatched internet facing software is the first thing to close.
  2. Enforce MFA where it matters, and cover the gaps. Credential abuse is a top entry vector, and Sophos 2026 shows that incomplete MFA coverage still leaves exposure, so extend it across privileged, remote, and high risk access and pair it with email security and credential hygiene.
  3. Cut and inventory your software. Fewer plugins, apps, and exposed services mean a smaller attack surface and fewer advisories to track.
  4. Scan continuously and fix exploited findings first. Prioritize vulnerabilities with confirmed exploitation over raw severity, and let scheduled scanning turn the constant background of automated attacks into a list a small team can work through.

Methodology and sources

This page is a source audit of small business cybersecurity statistics, built on a few principles: it prioritizes primary reports and links them where possible; it labels survey self report separately from investigated incident data; it marks all sizes averages so they are not mistaken for SMB specific figures; it distinguishes ransomware involvement from initial access; it treats 2025 figures as dated comparisons rather than current 2026 numbers; and it refuses to repeat a claim it cannot attribute to a named primary source, flagging disproven numbers instead. Primary and named sources include the Sophos State of Ransomware 2026, the Verizon 2025 and 2026 Data Breach Investigations Report, the IBM Cost of a Data Breach Report, the Hiscox Cyber Readiness Report 2025, the ITRC 2025 Business Impact Report, and the National Cybersecurity Alliance correction on the closure statistic. This page is reviewed quarterly. You are welcome to cite it with a link back to ScanTitan.

Frequently asked questions

What percentage of cyberattacks target small businesses?

There is no reliable current figure for the exact share of all attacks aimed at small businesses, and the widely repeated “43%” is usually cited without a transparent primary source methodology. The defensible, measured statement is that small businesses stop fewer ransomware attacks before damage than larger firms, with only 34% of organizations of 100 to 250 employees stopping an attack before encryption or extortion in Sophos State of Ransomware 2026, against 46% at much larger firms.

How much does a data breach cost a small business?

IBM’s Cost of a Data Breach research reported an average of about 3.31 million dollars for organizations with fewer than 500 employees, below the all sizes global average. From the ransomware angle, Sophos put the average recovery cost at 1.7 million dollars per incident across all sizes in 2026, and reported a 2025 average of 638,536 dollars for the 100 to 250 employee band specifically. All are averages across wide ranges, not the cost of a single hacked website.

Do 60% of small businesses close within six months of a cyberattack?

No credible source supports this. The National Cybersecurity Alliance, often credited as the origin, stated in 2022 that the statistic did not come from its research, that it could not verify it, and that it removed references and does not recommend using it. Real impact is better described with current incident data and clearly labeled survey findings.

How common is ransomware for small businesses?

It is the defining SMB threat. Sophos State of Ransomware 2026 found that only 34% of small organizations of 100 to 250 employees stopped an attack before encryption or extortion, and that 79% of ransomware attacks across all sizes began with an identity based approach. For historical context, Verizon’s 2025 DBIR found ransomware present in 88% of SMB breaches against 39% at large organizations.

How do most small businesses get breached?

In Verizon’s 2026 DBIR small business dataset, exploitation of vulnerabilities was the leading initial access vector at 26%, followed by credential abuse at 13% and phishing at 9%, with third party involvement in 55% of breaches. Phishing can also contribute indirectly to credential compromise, although those categories are measured separately in the DBIR. The practical response is patching internet facing software, enforcing MFA across high risk access, and scanning on a schedule.

Reviewed by Obaida Al-Sulaiman, Information Security Manager (CISSP, GWAPT, GXPN, GCIH, CEH), on August 19, 2026.

Want vulnerability scanning that prioritizes for you?

ScanTitan continuously matches your site against the CVE/NVD database, then ranks findings by real-world exploitability — so you patch what matters first.

o

Information Security Manager · Dubai, UAE · 12+ years InfoSec experience

Obaida specialises in web application security, vulnerability management, and external attack surface reduction for SMB and mid-market organisations. All ScanTitan content is reviewed against live scan findings before publication.

Share :

Facebook
LinkedIn

Continue reading

Your security score

?
/10
Unknown
Most sites we scan for the first time carry 3–7 OWASP findings they weren’t aware of.
Table of Contents

Weekly security digest

New CVEs, scan methodology updates, practical guides. One email per week — no sales pitch.

GDPR compliant · Unsubscribe any time