Small businesses are not attacked less than large ones. They are attacked more, pay a bigger share of their revenue when it goes wrong, and get far less coverage in the annual reports that budget decisions are built on. This page pulls the small business numbers out of those reports: Verizon, IBM, the FBI, Sophos, the insurers who pay the claims, and the Identity Theft Resource Center’s survey of business owners. Every figure carries its source. We update the page as each report is published.
How to cite: link to this page or to the primary source listed beside each figure. Where a figure is from a survey, the sample size is stated so you can judge it.
1. How often small businesses are attacked
- 81% of small businesses (500 or fewer employees) reported a security breach, a data breach, or both in the past year, in the Identity Theft Resource Center’s survey of 662 owners and executives. (ITRC 2025 Business Impact Report)
- 59% of small and medium-sized enterprises across the US, UK, France, Germany, Spain, Ireland and Portugal experienced a cyber attack in the last twelve months, in a survey of 5,750 businesses. 27% were hit by ransomware. (Hiscox Cyber Readiness Report 2025)
- 96% of ransomware victims whose size was known were small and medium-sized businesses, in Verizon’s analysis of more than 22,000 confirmed breaches. (Verizon 2026 Data Breach Investigations Report)
- A year earlier the same report found ransomware present in 88% of breaches at small businesses against 39% at large organizations. Ransomware is the small business breach. (Verizon 2025 DBIR)
- 98% of cyber insurance claims in a study of 10,402 claims came from small and medium-sized enterprises. Large companies were 2% of claims but more than half of the total incident cost. (NetDiligence Cyber Claims Study 2025)
- Over 40% of the incidents small businesses reported to the ITRC named an AI-powered attack as a root cause; 57% of Hiscox respondents said they had been hit through at least one AI-related vulnerability. (ITRC; Hiscox)
What this means for testing: attackers choose small businesses because the same tools work against many of them at once. The tests that matter are the ones that remove the common entry points: exposed services, weak credentials, and unpatched software. See external network penetration testing for the scope that covers all three.
2. What an incident costs a small business
- $264,000: the average total incident cost for a small or medium-sized enterprise in the NetDiligence claims data, up about 30% year over year. Crisis services alone (forensics, legal, notification) averaged $152,000. (NetDiligence 2025)
- 62.5% of breached small businesses put their total financial impact above $250,000, and 36.7% above $500,000, up from 2024. (ITRC 2025 Business Impact Report)
- 38.3% of breached small business leaders said they raised prices to absorb the cost of an incident. The ITRC calls this the hidden cyber tax. (ITRC)
- 33% of attacked SMEs were hit with a substantial fine afterwards. 44% lost money to payment diversion fraud. 29% found it harder to win new business. (Hiscox 2025)
- For context, the average cost of a data breach across all organization sizes reached $4.99 million globally and $11.5 million in the United States in 2026. A small business does not pay that, but the per-record costs of notification, legal work and downtime are the same. (IBM Cost of a Data Breach Report 2026)
- Ransomware recovery cost an average of $1.7 million excluding any ransom, across 2,158 organizations hit in the past year. (Sophos State of Ransomware 2026)
Against those numbers, a fixed-price penetration test is the cheapest line in the budget. Our pricing page publishes the figures.
3. Ransomware and the small business
- Ransomware incidents at SMEs accounted for 81% of insurance claims with a business interruption component. (NetDiligence 2025)
- 80% of SMEs hit by ransomware paid the ransom, and only 60% of them recovered all or part of their data. 31% of payers received further demands. (Hiscox 2025)
- Across all sizes the picture is different: only 31% of ransomware victims in Verizon’s data paid, and Coalition reports 86% of its policyholders refused. Small businesses without a response plan pay more often than businesses with one. (Verizon 2026 DBIR; Coalition 2026 Cyber Claims Report)
- 34% of organizations with 100 to 250 employees stopped the ransomware attack before data was encrypted. The rest did not. (Sophos 2026)
- The median ransom payment fell below $140,000 in Verizon’s data. Ransomware operators have moved down-market, and the demands scale to what a smaller victim can pay. (Verizon 2026 DBIR)
- Ransomware was the most expensive claim type at $269,000 on average, and initial ransom demands rose 47% in 2025. (Coalition 2026)
4. How attackers get in
- 31% of breaches now start with the exploitation of a software vulnerability, the first time in nineteen years of the DBIR that it beat stolen credentials as the top entry point. Credential abuse as the initial vector fell to 13%. (Verizon 2026 DBIR)
- 48% of breaches involved a third party, a 60% increase in one year. For a small business that means the vendor, the SaaS tool, or the outsourced IT provider. (Verizon 2026 DBIR)
- Among ransomware victims the root causes were malicious email 26%, phishing 24%, compromised credentials 23%, and exploited vulnerabilities 18%. 79% of attacks began with an identity-based approach. (Sophos 2026)
- 62% of breaches involved the human element, and social engineering on mobile devices succeeded 40% more often than email phishing. (Verizon 2026 DBIR)
- Only 26% of known exploited vulnerabilities were fully remediated in 2025, down from 38%, while the median time to remediate rose from 32 to 43 days. (Verizon 2026 DBIR)
- Only 27.2% of small businesses said they had put critical controls such as multi-factor authentication in place in 2025, down from 33.6% the year before, while the share that felt very prepared fell from 56.5% to 38.4%. (ITRC 2025 Business Impact Report)
The pattern is the same one we see on engagements: an internet-facing system that nobody patched, a shared password, and a vendor connection nobody reviewed. External network and web application tests find the first two; phishing testing measures the third.
5. Business email compromise, the quiet one
- Business email compromise cost US victims $3.046 billion in reported losses in 2025, up from $2.77 billion, the largest loss category aimed at businesses. 86% of BEC losses moved by wire transfer or ACH. (FBI IC3 2025 Internet Crime Report)
- BEC was 31% of cyber insurance claims and funds transfer fraud another 27%. Together they were 58% of incidents. The average BEC loss was $27,000; the average funds transfer fraud loss was $141,000, and 52% of those frauds started with a compromised mailbox. (Coalition 2026)
- The average wire transfer requested in a BEC attack was $50,297 in the fourth quarter of 2025, and 69% of BEC attacks were sent from free webmail domains. (APWG Phishing Activity Trends Report, Q4 2025)
- 44.2% of vendor email compromise messages that were read were engaged with by employees. (Verizon 2026 DBIR)
6. The scale of the problem in the United States
- The FBI received 1,008,597 internet crime complaints in 2025, about 3,000 a day, with reported losses of $20.877 billion, up 26% in a year. (FBI IC3 2025)
- The ITRC tracked a record 3,322 publicly reported data compromises in 2025, up 79% over five years. Financial services (739), healthcare (534), and professional services (478) led the count, all sectors with long tails of small firms. (ITRC 2025 Annual Data Breach Report)
- 70% of breach notices in 2025 gave no information about how the attack happened, up from 65%. Small businesses that were breached mostly cannot say how. (ITRC)
- Supply chain attacks affected 1,251 entities in 2025 against 660 in 2024. One compromised vendor becomes hundreds of small business breaches. (ITRC via HIPAA Journal)
7. What the numbers say to do
The reports agree on the order of operations for a business with no security team:
- Close the exposed surface. Vulnerability exploitation is the top entry point (31%), and exposed applications and systems were the entry point in 38% of ransomware attacks. An external penetration test or a vulnerability assessment shows what the internet sees.
- Fix identity. 79% of ransomware attacks started with an identity attack, and 97% of identity attacks are password attacks. Phishing-resistant MFA blocks more than 99% of them. (Microsoft Digital Defense Report 2025)
- Test the people. 62% of breaches involve a human. A phishing test shows the real click rate before an attacker measures it for you.
- Get the paperwork right. 33% of attacked SMEs were fined. A test report that maps to SOC 2, PCI DSS or HIPAA is the evidence that keeps a breach from becoming a penalty.
Our small business penetration testing page describes how we scope a first engagement for a company without an internal security team, at a fixed price with a free retest.
Sources
- Verizon, 2026 Data Breach Investigations Report (31,000+ incidents, 22,000 breaches, 2025 data)
- Identity Theft Resource Center, 2025 Business Impact Report and 2025 Annual Data Breach Report
- Hiscox, Cyber Readiness Report 2025 (5,750 businesses)
- NetDiligence, Cyber Claims Study 2025 (10,402 claims)
- Coalition, 2026 Cyber Claims Report
- Sophos, The State of Ransomware 2026 (2,158 organizations)
- IBM, Cost of a Data Breach Report 2026 (602 organizations)
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report
- APWG, Phishing Activity Trends Report, Q4 2025
- Microsoft, Digital Defense Report 2025
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →