Small Business Cybersecurity in 2026: Five Numbers Owners Should Actually Use

,
Small Business Cybersecurity 2026: Five Numbers Every Owner Should Actually Use infographic

Most small business owners do not need a 60-page threat report on cybersecurity. They need a short list of numbers that changes what they do Monday morning.

The numbers below come from direct source reports: Verizon’s 2025 Data Breach Investigations Report, the FBI IC3 2025 Annual Report, CISA ransomware guidance, IRS Publication 4557, FTC Safeguards Rule guidance, and NCSL’s breach-notification law survey.

Small Business Cybersecurity 2026: Five Numbers Every Owner Should Actually Use square infographic

The five numbers

1. Verizon analyzed 22,052 security incidents and 12,195 confirmed data breaches. The 2025 DBIR is not a survey of opinions. It is a data set of real-world incidents and breaches contributed by Verizon’s partners and dataset participants. That makes it more useful than generic “how worried are you” statistics.

2. Small businesses were not a side note. Verizon’s SMB snapshot identified 3,049 incidents and 2,842 confirmed data breaches involving small businesses with fewer than 1,000 employees. The practical point is simple: small business is part of the target set, not outside it.

3. Three patterns made up 96% of SMB breaches. Verizon grouped the leading SMB breach patterns as System Intrusion, Social Engineering, and Basic Web Application Attacks. In plain English: attackers get in through systems, people, or exposed web accounts. That maps directly to patching, multi-factor authentication, email controls, vendor access, and employee payment discipline.

4. Ransomware showed up in 88% of SMB breaches. Verizon’s SMB snapshot puts ransomware-related breaches at 88% for SMBs, compared with 39% for large organizations. Verizon also reported a $115,000 median ransom payment. That number is more useful to an owner than a huge average pulled upward by enterprise incidents.

5. FBI IC3 recorded $20.877 billion in reported 2025 losses. The FBI’s 2025 IC3 report recorded 1,008,597 complaints. Business Email Compromise alone accounted for $3.046 billion in reported losses. Phishing/spoofing produced 191,561 complaints. Ransomware produced more than 3,600 complaints, and the FBI cautions that ransomware loss totals often exclude lost business, time, wages, files, equipment, and third-party remediation costs. IC3 also recorded 22,364 AI-related complaints and $893.346 million in AI-related losses.

What those numbers mean for an owner

The actionable lesson is not “buy more software.” It is to answer five operational questions before an incident happens.

1. Where are the backups, and when did you last restore from them? The FBI recommends off-site or offline backups, encrypted and immutable where possible, with regular backup and restoration testing. A backup that has never been restored is a hope, not a plan.

2. Which accounts can move money or expose customer data? Email, banking, payroll, vendor portals, cloud drives, remote access, and admin accounts need multi-factor authentication. The FBI specifically calls out MFA for webmail, VPNs, and accounts that touch critical systems.

3. Who can change payment instructions? Business Email Compromise is a payment-control problem as much as an IT problem. If one email can change vendor banking information, approve a wire, or redirect payroll, the control is too weak. Use callback procedures and dual approval for banking changes.

4. What personal data do you actually hold? Every state, D.C., Guam, Puerto Rico, and the U.S. Virgin Islands has a breach-notification law. The details vary by jurisdiction, but the owner-level issue is consistent: if you store customer, employee, taxpayer, payment, or health-related data, an incident may trigger notice obligations.

5. Who owns the first 24 hours? A small business needs a short incident-response sheet that names the decision maker, IT contact, insurance contact, legal contact, bank contact, and law-enforcement reporting path. The morning of a ransomware note is not the time to decide who is allowed to talk to the attacker or freeze a bank account.

Why this belongs on a compliance site

Cybersecurity is not only an IT topic. It becomes a compliance issue when the business holds regulated data, misses a notice deadline, loses tax records, accepts fraudulent payment instructions, or cannot show basic security discipline to a bank, insurer, customer, or regulator.

For tax-record handling, IRS Publication 4557 and IRS data-security guidance point tax professionals to written data-security planning, employee training, access controls, breach response, and FTC Safeguards Rule obligations where applicable. The FTC Safeguards Rule requires covered financial institutions to develop, implement, and maintain a written information security program appropriate to the size and complexity of the business and the sensitivity of the information.

For customer and employee data, state breach-notification rules are the floor. For payment cards, health information, financial services, and government contracting, other rules can attach. The details depend on what data the business holds and what contracts it has signed.

The five-part BCA conversation

BCA is not an IT vendor. We do not sell endpoint software, manage firewalls, or negotiate with attackers. Our role is the business and compliance layer:

  1. Map what data the business holds and which legal or contractual duties attach.
  2. Review whether the business has a written security plan where IRS, FTC, customer, or insurer expectations require one.
  3. Help owners convert “cybersecurity” into operating controls: bank-change rules, vendor access, backup testing, record retention, and incident contacts.
  4. Coordinate the planning conversation among the owner, IT provider, insurance broker, bank, and legal counsel.
  5. Build the documentation trail the business will need if an incident turns into a notice, claim, audit, or customer dispute.

When to bring BCA in

Bring BCA in before the incident if any of these are true:

  • You handle customer records, taxpayer records, payroll records, payment information, medical-adjacent information, or sensitive employee files.
  • You do not have a written incident-response sheet with named contacts.
  • Your business has never tested a backup restoration.
  • Vendor bank changes happen by email without a callback rule.
  • You have cyber insurance but have not checked the notice, vendor, MFA, backup, or cooperation conditions.

The technical work stays with IT and security partners. The owner decision, compliance mapping, and documentation discipline should not be left until after a breach.

Key Takeaways

  • Verizon’s 2025 DBIR analyzed 22,052 incidents and 12,195 confirmed breaches, including 3,049 incidents and 2,842 confirmed breaches involving small businesses.
  • In Verizon’s SMB snapshot, three patterns represented 96% of SMB breaches: System Intrusion, Social Engineering, and Basic Web Application Attacks.
  • Ransomware appeared in 88% of SMB breaches, compared with 39% for large organizations. Verizon reported a $115,000 median ransom payment.
  • FBI IC3 recorded 1,008,597 complaints and $20.877 billion in reported 2025 losses. BEC alone accounted for $3.046 billion.
  • FBI IC3 recorded 22,364 AI-related complaints and $893.346 million in AI-related losses.
  • Cybersecurity becomes compliance when the business holds personal data, taxpayer data, financial data, payment information, or regulated records.
  • BCA’s role is advisory: data mapping, written plan review, incident-response coordination, breach-notification preparation, and owner-level control design.

Sources

  1. Verizon, “2025 Data Breach Investigations Report.” https://www.verizon.com/business/resources/T44a/reports/2025-dbir-data-breach-investigations-report.pdf
  2. Verizon, “Verizon’s 2025 Data Breach Investigations Report: Alarming surge in cyberattacks through third-parties.” https://www.verizon.com/about/news/2025-data-breach-investigations-report
  3. FBI Internet Crime Complaint Center, “2025 IC3 Annual Report.” https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
  4. CISA, “#StopRansomware Guide.” https://www.cisa.gov/stopransomware/ransomware-guide
  5. National Conference of State Legislatures, “Security Breach Notification Laws.” https://www.ncsl.org/technology-and-communication/security-breach-notification-laws
  6. IRS Publication 4557, “Safeguarding Taxpayer Data.” https://www.irs.gov/pub/irs-pdf/p4557.pdf
  7. IRS, “Here’s what tax preparers need to know about a data security plan.” https://www.irs.gov/newsroom/heres-what-tax-preparers-need-to-know-about-a-data-security-plan
  8. FTC, “FTC Safeguards Rule: What Your Business Needs to Know.” https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know

This information is provided for general educational purposes and reflects opinions based on experience. Individual circumstances may vary. Cybersecurity data sets use different collection methods and do not capture every incident. Breach-notification, tax-record, payment-card, health-data, financial-services, and government-contracting obligations depend on the specific facts. BCA advisors bring business and compliance experience to help you map cybersecurity considerations against your business obligations and coordinate with your IT, insurance, legal, and banking partners.

Leave a Reply