What SMBs Get Wrong About Cybersecurity
What the Verizon DBIR and IBM breach data really say about SMB cybersecurity — and the five fundamentals to fix before buying another tool.
Most SMB cybersecurity conversations start in the wrong place. They start with a product — a firewall, an email filter, an antivirus renewal — instead of with the question of how attackers actually get in, and what happens on the day something works.
That gap matters, because the most common assumption small business owners hold — that they’re too small to be worth attacking — misreads what the published breach data shows. Whether you’re worth attacking has less to do with it than whether you’re easy to attack.
Here is what the Verizon DBIR and IBM’s Cost of a Data Breach reporting actually say, what they don’t say, and the short list of fundamentals worth getting right before spending on anything else.
Are small businesses really targets for cyberattacks?
Yes — but not for the reason most owners assume. Verizon’s 2025 Data Breach Investigations Report found ransomware present in 88% of breaches involving SMB-sized organizations, compared with 39% at larger organizations.
Two caveats on that number, because both matter. First, it is 2025-edition data; we haven’t seen an equivalent SMB-specific ransomware split published in the 2026 edition, so don’t treat it as a current-year figure. Second, Verizon’s researchers attributed the gap to lower IT and cybersecurity maturity, not to attackers preferring small brands. The figure describes the state of small-business defenses, not a target list.
Why do small businesses get hit harder than large ones?
Because of that maturity gap, and it’s a meaningful distinction. The burden isn’t about who you are. It’s about whether someone is patching, watching, and testing recovery.
Most attacks against small organizations are opportunistic. They find the door that was left open, not the company whose name they recognize.
Ransomware also got more common overall in that reporting period, not less. Verizon’s 2025 DBIR reports it featured in 44% of all confirmed breaches, up from 32% in the prior edition.
What is the most common way attackers get in now?
Unpatched systems. Published summaries of Verizon’s 2026 DBIR — including write-ups from Tenable and Modern Distribution Management — report that exploitation of vulnerabilities became the top initial access vector at 31% of breaches, overtaking stolen credentials, while median time-to-patch rose from 32 days to 43 days.
The dataset behind it is large. Mimecast’s summary of the 2026 report describes more than 22,000 confirmed breaches, the largest breach dataset in the report’s history.
Those 2026 figures come from secondary coverage rather than the report itself, so treat the exact percentages as directional until you’ve read the primary source. The direction is what should concern a small business: attackers are moving faster on new vulnerabilities while defenders are getting slower at closing them.
For an organization with no dedicated IT staff, this is the single most actionable finding available. A patch program is not glamorous work. It is also the thing standing between you and the most common entry point in the current data.
A workable cadence for a small business looks like this:
- A current inventory of every device, server, and application — you cannot patch what you don’t know about.
- Automated OS and browser patching on a defined schedule, with reporting that shows what actually applied.
- A defined exception process for the one legacy system that can’t be patched, with compensating controls around it.
- Regular vulnerability scanning, and a named owner for remediation.
- Firmware and network gear included, not forgotten. Firewalls and access points age out too.
Do most ransomware victims pay the ransom?
No, and that’s a recoverability story rather than a bravery story. Verizon’s 2025 DBIR reports that 64% of victim organizations did not pay ransoms, up from 50% two years earlier.
Organizations that can say no are usually the ones that can restore. That means backups that are tested, immutable, and stored offsite — plus a recovery time objective you’ve actually agreed on and rehearsed, so “how long until we’re operating again?” has a real answer before you need it.
palmiq builds backup and business continuity on Veeam and Acronis, and we’re an Acronis Platinum partner in the top 1% globally. But the product matters less than the discipline around it. An untested backup is a hypothesis.
Is your small business somebody else’s third-party risk?
Almost certainly, and this is the reframe most SMBs miss. Verizon’s 2025 DBIR reports that incidents involving third parties doubled year over year, from 15% to 30%.
If you subcontract to a larger firm, support a K-12 district, sit in a health system’s vendor list, or serve as a supplier inside a government contractor’s supply chain, you are the third party in someone else’s risk register. That changes what security is for. It stops being purely a loss-prevention expense and starts being a condition of contract eligibility — the security questionnaire, the attestation, the evidence request.
If you’re in a regulated supply chain, the specific framework requirements (CMMC, NIST 800-171, HIPAA, FERPA) deserve their own conversation. No single control or service makes an organization compliant, and anyone who tells you otherwise is selling.
Is shadow AI a real risk for a small team?
It is already here. IBM’s 2025 Cost of a Data Breach Report found that 97% of breached organizations that experienced an AI-related security incident reported lacking proper AI access controls.
Shadow AI is the new shadow IT: staff pasting customer records, contracts, or patient information into consumer chatbots because it saves them twenty minutes. Nobody is being malicious. There’s just no rule.
The first step is cheap:
- A short written list of approved AI tools, and a clear statement that consumer accounts are not on it.
- Identity and single sign-on enforced through Microsoft 365 or Google Workspace, so tool access follows employment status.
- Simple data-classification rules: what categories of information never leave sanctioned systems.
- One named person who approves new tools.
What five controls should an SMB get right first?
Before any new purchase: multifactor authentication everywhere, a real patching cadence, tested backups, monitored endpoints, and ongoing phishing awareness for staff.
The word doing the work in that list is “monitored.” Unmonitored antivirus generates alerts nobody reads. Detection speed is the main variable you can still influence once an attacker is inside — alongside how well your network limits where they can go — which is why round-the-clock monitoring is often worth more to a small team than another tool in the stack.
That’s the argument for managed detection and response. When you evaluate an MDR arrangement, the useful questions are operational, not technical:
- Who triages alerts, and are they people or automation?
- What’s the escalation path, and who gets called at 2 a.m.?
- Does the provider have authority to isolate a compromised endpoint without waiting for your approval — and do you want them to?
- What reporting do you receive, how often, and can you hand it to a client or auditor?
For reference, palmiq runs a 24/7 SOC with a 15-minute response SLA on critical issues. Whoever you talk to, get their answers to those four questions in writing.
Which cybersecurity statistics should you ignore?
The ones you can’t trace. A lot of “small business cybersecurity statistics” content online is aggregator listicles recycling figures with no primary report behind them — the “43% of attacks target small businesses” and “96% of ransomware victims are small businesses” genre. We looked; the sources lead to other listicles.
Be equally careful with headline breach-cost averages. The published averages in IBM’s reporting are all-organization figures, heavily influenced by large enterprises. They are not what a breach costs a small business, and using them as a budgeting anchor will either scare you into the wrong purchase or get your proposal dismissed by a CFO who checks.
Ask for the edition, the sample, and the population. Any provider worth hiring will tell you when a number doesn’t apply to you.
Where to start
If you’re not sure whether your patching, backups, and endpoint monitoring would hold up, that’s a diagnosable question, not a philosophical one. Across palmiq’s MDR and EDR services we maintain a 99.9% threat neutralization rate and neutralize 1,200+ threats monthly — but the first step is seeing what’s actually running in your environment today.
Book a discovery call and we’ll walk through where you stand.