In a June 2010 survey of 2,500 executives with responsibility for IT security – half from companies of less than 100 employees – cyber-attacks were ranked as their top business risk. And, of those polled, 74 percent said they were “somewhat or extremely concerned” about losing sensitive electronic data. Addressing this challenge, small-to-medium sized businesses (SMBs) were in 2010 spending an average of $51,000 a year, or about two-thirds of IT staff time, working on “information protection, including computer security, backup, recovery, and archiving, as well as disaster preparedness.” This seemed like a sound investment back in 2010 given that the average cost of a breach to these SMBs was $188,242. Indeed, 95 percent of security and compliance professionals polled by nCircle in 2010 believed that data breaches would continue to increase after 2010. They were right.

Fast forward to today and this trend continues as evidenced by a report listing 35 Alarming Small Business Cybersecurity Statistics for 2024. Just a few of the highlights of this report include:

  • 46% of all cyber breaches impact businesses with fewer than 1,000 employees.
  • 95% of cybersecurity incidents at SMBs cost between $826 and $653,587.
  • 75% of SMBs could not continue operating if they were hit with ransomware.
  • 47% of businesses with fewer than 50 employees have no cybersecurity budget.
  • 29% of businesses that suffered a breach responded by hiring a cybersecurity firm or dedicated IT staff.

Rather than pay any vendor from a money bucket that does not exist, SMBs should at least review some of the readily available free resources on the subject. For example, the U.S. Small Business Administration (SBA) has online resources dedicated to informing SMBs on how to bolster their cybersecurity. Well beyond the SBA there are other free tools. To that end, NIST provides SMBs, who admittedly likely have modest or no cybersecurity plans in place, with material to “kick-start their cybersecurity risk management strategy” by using the NIST Cybersecurity Framework (CSF) 2.0. After reviewing these free resources, business owners can better determine which direction to turn when it comes to preparing for the worst.