Key Takeaways
- 43% of all cyber attacks target small businesses despite them representing only 20% of the market
- In 2023, 74% of small and medium-sized businesses (SMBs) reported experiencing at least one cyber incident
- Small businesses account for 31% of all data breaches reported in 2023
- Average cost of a data breach for small businesses was $25,000 in 2023
- SMBs lost $4.45 million on average per ransomware attack in 2023
- 60% of small businesses that suffer a breach close within 6 months, costing $1.2M in lost revenue
- Phishing is the most common threat, accounting for 36% of SMB breaches in 2023
- Ransomware affected 66% of SMBs that paid attackers in 2023 surveys
- Malware infections represent 22% of small business cyber incidents annually
- Only 26% of SMBs use multi-factor authentication (MFA), exposing to account takeovers
- 51% of small businesses lack employee cybersecurity training programs
- Just 14% of SMBs have incident response plans in place
- Businesses with backups recover 60% faster from ransomware
- SMBs with incident response plans reduce breach costs by 35%
- MFA adoption cuts account compromise recovery time by 50%
Small businesses face devastating cyber attacks and must urgently increase their security.
Common Threats
Common Threats Interpretation
Financial Impact
Financial Impact Interpretation
Prevalence and Incidence
Prevalence and Incidence Interpretation
Recovery and Response
Recovery and Response Interpretation
Security Practices
Security Practices Interpretation
Sources & References
- Reference 1VERIZONverizon.comVisit source
- Reference 2HISCOXGROUPhiscoxgroup.comVisit source
- Reference 3IBMibm.comVisit source
- Reference 4KEEPERSECURITYkeepersecurity.comVisit source
- Reference 5HISCOXhiscox.co.ukVisit source
- Reference 6NATIONWIDEnationwide.comVisit source
- Reference 7FORBESforbes.comVisit source
- Reference 8CISCOcisco.comVisit source
- Reference 9PONEMONponemon.orgVisit source
- Reference 10SOPHOSsophos.comVisit source
- Reference 11NATIONALCYBERSECURITYALLIANCEnationalcybersecurityalliance.orgVisit source
- Reference 12ENISAenisa.europa.euVisit source
- Reference 13STATISTAstatista.comVisit source
- Reference 14APWGapwg.orgVisit source
- Reference 15CHECKPOINTcheckpoint.comVisit source
- Reference 16HHShhs.govVisit source
- Reference 17CLOUDFLAREcloudflare.comVisit source
- Reference 18PWCpwc.comVisit source
- Reference 19NAMnam.orgVisit source
- Reference 20ACSCacsc.gov.auVisit source
- Reference 21CISAcisa.govVisit source
- Reference 22IC3ic3.govVisit source
- Reference 23PTSECURITYptsecurity.comVisit source
- Reference 24AGCagc.orgVisit source
- Reference 25ZDNETzdnet.comVisit source
- Reference 26COUNCILOFNONPROFITScouncilofnonprofits.orgVisit source
- Reference 27SHOPIFYshopify.comVisit source
- Reference 28AMERICANBARamericanbar.orgVisit source
- Reference 29TTNEWSttnews.comVisit source
- Reference 30AICPAaicpa.orgVisit source
- Reference 31CROWDSTRIKEcrowdstrike.comVisit source
- Reference 32MARSHmarsh.comVisit source
- Reference 33MALWAREBYTESmalwarebytes.comVisit source
- Reference 34OAGoag.ca.govVisit source
- Reference 35UPTIMEINSTITUTEuptimeinstitute.comVisit source
- Reference 36AKAMAIakamai.comVisit source
- Reference 37PROOFPOINTproofpoint.comVisit source
- Reference 38EXPERIANexperian.comVisit source






