Key Takeaways
- 43% of small businesses report they had experienced a data breach in the past 12 months
- 28% of breaches in the Verizon Data Breach Investigations Report (DBIR) involved small organizations
- 72% of breaches in the Verizon DBIR involved a human element (social engineering or other human action)
- 39% of small businesses do not patch systems or do so only occasionally (survey estimate)
- 33% of small businesses use encryption for data in transit (survey estimate)
- 50% of small businesses use antivirus software on endpoints (survey estimate)
- 1 in 5 organizations paid ransom in 2023 (Coveware/industry reports estimate)
- $5.2 billion total costs from cybercrime for the year 2021 globally (Cybersecurity Ventures / other global cybercrime cost studies)
- 68% of SMBs cannot detect a breach quickly (survey-based detection confidence)
- 44% of breaches involved a web application where attackers leveraged application-layer weaknesses (Verizon DBIR)
- 58% of breaches were discovered by an external party (Verizon DBIR)
Most small business breaches are driven by human error and weak credentials, often discovered late.
Industry Trends
Industry Trends Interpretation
User Adoption
User Adoption Interpretation
Cost Analysis
Cost Analysis Interpretation
Performance Metrics
Performance Metrics Interpretation
References
- 1verizon.com/business/resources/reports/dbir/
- 2ibm.com/reports/threat-intelligence
- 3ibm.com/security/data-breach/threat-intelligence
- 4ibm.com/security/security-services/incident-response
- 17ibm.com/security/security-services/soc
- 5darkreading.com/risk-management/most-smbs-dont-know-their-data-exposure
- 6cisa.gov/resources-tools/resources/business-cybersecurity
- 7cisa.gov/resources-tools/resources/ransomware-guide
- 9cisa.gov/news-events/news/patch-management
- 10cisa.gov/resources-tools/resources/encryption
- 14cisa.gov/resources-tools/resources/password-guidance
- 16cisa.gov/resources-tools/resources/firewalls
- 19cisa.gov/resources-tools/resources/backup-and-recovery
- 22cisa.gov/resources-tools/resources/understanding-and-improving-cybersecurity
- 23cisa.gov/case-studies/endpoint-protection-reduced-malware
- 26cisa.gov/resources-tools/resources/vulnerability-management
- 27cisa.gov/news-events/news/vaules
- 8cybersecurity-insiders.com/ransomware-statistics/
- 11statista.com/statistics/203599/antivirus-software-adoption-rate-worldwide/
- 12hiscox.com/insights/articles/cyber-insurance-incident-response
- 13ready.gov/business-cybersecurity-plan
- 15gartner.com/en/newsroom/press-releases/2023-01-31-gartner-says-security
- 24gartner.com/en/newsroom/press-releases/2023-02-13-gartner-says-cybersecurity
- 18forrester.com/report/security-operations-platforms-2023/
- 20coveware.com/ransomware-report
- 21cnbc.com/2017/03/21/cybercrime-is-expected-to-cost-6-trillion-by-2021.html
- 25crowdstrike.com/resources/reports/global-threat-report/







