{"id":11044,"date":"2021-11-11T16:15:00","date_gmt":"2021-11-11T21:15:00","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=11044"},"modified":"2023-03-27T14:31:00","modified_gmt":"2023-03-27T18:31:00","slug":"15-small-business-cyber-security-statistics-that-you-need-to-know","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/15-small-business-cyber-security-statistics-that-you-need-to-know\/","title":{"rendered":"15 Small Business Cyber Security Statistics That You Need to Know"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-small-business-cyber-attacks-aren-t-cheap-ibm-reports-that-breaches-associated-with-business-email-compromise-cost-an-average-of-5-01-million-in-2020-here-s-our-list-of-the-top-smb-cybersecurity-statistics-you-need-to-know-in-2021\">Small business cyber attacks aren\u2019t cheap \u2014 IBM reports that breaches associated with business email compromise cost an average of $5.01 million in 2020. Here\u2019s our list of the top SMB cybersecurity statistics you need to know in 2021<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><em><strong>Note: This small business cyber security statistics article is one that we periodically update with new data. <strong><em>This is the most recent update and is the last one we&#8217;ll likely make before we head into 2022.<\/em><\/strong><\/strong><\/em> <em><strong>Be sure to check back periodically for updates and fresh SMB cybersecurity statistics!<\/strong><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You may have heard the oft-quoted small business cyber\nsecurity statistic that\u2019s something akin to \u201c60% of small companies that suffer\na cyber attack are out of business within six months.\u201d Heck, like many major\nmedia outlets, we\u2019ve even quoted this stat ourselves in the past. However, it\nturns out that the organization that\u2019s often attributed for this small business\ncyber security statistic, the National Cyber Security Alliance (NCSA), actually\nrecommends <em>not<\/em> citing this statistic for the <a href=\"https:\/\/staysafeonline.org\/press-release\/national-cyber-security-alliance-statement-regarding-incorrect-small-business-statistic\/\">following\nreason<\/a>:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cThis statistic was not generated from NCSA research, and we cannot verify its original source. NCSA has not actively referenced this statistic for several years, but we discovered that it was included in an outdated infographic on our website. We have removed all of these references and do not recommend its ongoing usage. Members of the media, policy makers, small businesses and others are encouraged to rely upon more current and clearly sourced data.\u201d<\/em> <\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Well, that\u2019s a bummer, right? <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While we here at Hashed Out may not be the internet\u2019s top resource for cyber security related information \u2013 though we strive to be and have more than two million readers \u2013 we still want to do the best job we can at providing you with the best and most useful information possible. This includes topics such as small business <a href=\"https:\/\/www.thesslstore.com\/blog\/cyber-security-statistics\/\">cyber security statistics<\/a>. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With this in mind, we\u2019ve updated our list of some of the small business cyber security statistics you SHOULD know in one convenient resource. We\u2019ll also discuss why SMBs make such attractive targets and what you can do to protect your business. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-top-small-business-cyber-security-statistics-to-know-in-2021\">The Top Small Business Cyber Security Statistics to Know in 2021<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The ongoing COVID-19 global pandemic is changing things for small businesses and organizations around the world. An <a href=\"https:\/\/www.interpol.int\/en\/News-and-Events\/News\/2020\/INTERPOL-report-shows-alarming-rate-of-cyberattacks-during-COVID-19\">August 2020 report from INTERPOL<\/a> indicates that small businesses may not (currently) be the top target of cybercriminals:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>&#8220;To maximise damage and financial gain, cybercriminals are shifting their targets from individuals and small businesses to major corporations, governments and critical infrastructure, which play a crucial role in responding to the outbreak. Concurrently, due to the sudden, and necessary, global shift to teleworking, organizations have had to rapidly deploy remote systems, networks and applications. As a result, criminals are taking advantage of the increased security vulnerabilities arising from remote working to steal data, generate profits and cause disruption.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">But just because larger organizations are their primary targets doesn\u2019t mean that SMBs should let their guards down, either. Many types of cyber attacks and other dangers still pose a risk to small and mid-size businesses, too.<\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-what-qualifies-as-an-smb\">What Qualifies as an SMB?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Well, that answer depends. One of the things that makes reporting small business cyber security statistics a bit challenging is that different reports identify small businesses differently. For example, according to some of the reports we cite in this article:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Verizon categorizes small businesses as those that have fewer than 1,000 employees.<\/li>\n\n\n\n<li>IBM identifies small businesses as those with fewer than 500 employees.<\/li>\n\n\n\n<li>Flexera categorizes SMBs as those that have fewer than 1,000 employees.<\/li>\n\n\n\n<li>The cyber security company VIPRE categorizes small businesses as those that have 1-500 employees.<\/li>\n\n\n\n<li>Alliant Cybersecurity\u2019s data includes companies that have 500 or fewer employees as well.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">With this in mind, let\u2019s kick off our list of small business cyber security statistics.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. $2.98 Million: The Average Cost of a Data Breach for SMBs With &lt;500 Employees<\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/small-business-cyber-security-statistics-data-breach.png\" alt=\"Small business cyber security statistics graphic: a $2.98 million price tag, which is the average cost of a data breach for SMBs\" class=\"wp-image-15151\" width=\"248\" height=\"248\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The costs associated with data breaches vary greatly depending on the size of the organization and scope of the attack. Research from&nbsp;<a href=\"https:\/\/www.ibm.com\/security\/data-breach\">IBM and the Ponemon Institute\u2019s 2021 Cost of a Data Breach Report<\/a>&nbsp;shows that small organizations (those with fewer than 500 employees) spend an average of nearly $3 million per incident. Compare this to the $2.63 million price tag for organizations with 500-1000 employees and the $5.25 million average per-incident cost for organizations with 10,001-25,000 employees.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. 43% of SMBs Lack Any Type of Cybersecurity Defense Plans<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What if we were to tell you that more than two in five companies that have 50 or fewer employees in the U.S. and United Kingdom don\u2019t have any type of cybersecurity defense plan in place? Yes, that\u2019s right. A <a href=\"https:\/\/www.prweb.com\/releases\/new_study_reveals_one_in_three_smbs_use_free_consumer_cybersecurity_and_one_in_five_use_no_endpoint_security_at_all\/prweb16921507.htm\">January 2020 research study<\/a> by BullGuard showcases a disturbing number of businesses are choosing to be reckless. They\u2019re essentially rolling the dice in terms of securing their data (and that of their customers) from small business cyber attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. One in Five SMBs Don\u2019t Use Any Endpoint Security Protections<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">BullGuard\u2019s survey of 3,083 SMBs also shows that 23% of small businesses in both the U.K. and U.S. neglect to use endpoint security mechanisms. Additionally, 32% of those surveyed who do use endpoint security protections say they rely solely on free, consumer-grade cybersecurity solutions. Yeah, take a moment to wrap your head around that one!<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"155\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Negligence-300x155.png\" alt=\"A graphic that illustrates the number of days it's been since a small business had a data breach\" class=\"wp-image-11049\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Negligence-300x155.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Negligence.png 738w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>4. Only 47% of SMBs Find Breaches Within Days<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Speed is of the essence when it comes to discovering data breaches. <a href=\"https:\/\/www.verizon.com\/about\/news\/verizon-2021-data-breach-investigations-report\">Verizon\u2019s 2021 Data Breach Investigations Report (DBIR)<\/a> shows that while small organizations were doing better than their large organization counterparts last year, those big boys are finding breaches \u201cwithin days or faster\u201d in 55% of the cases. Compare this to the 47% of small ones.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5. AWS Has 72% of Market Share for SMBs That Use Public Cloud<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Amazon Web Services (AWS) is the leading public cloud service provider for small businesses, according to <a href=\"https:\/\/info.flexera.com\/CM-REPORT-State-of-the-Cloud\">Flexera\u2019s 2021 State of the Cloud Report<\/a>. Azure comes in second with 48% and Google follows with 39%.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As cloud becomes more widely adopted, it\u2019s essential that businesses take the necessary steps to ensure they\u2019re as secure as possible. For more information relating to <a href=\"https:\/\/www.thesslstore.com\/blog\/19-cloud-computing-statistics-that-will-keep-you-awake-at-night\/\">cloud security statistics<\/a>, be sure to check out our article on that topic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>6. 78% of SMBs View Security as Their Top Cloud Security Challenge<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nearly four in five of the SMB technical professional who responded to Flexera\u2019s survey indicate that security is their biggest cloud hurdle. This is followed by concerns relating to better managing cloud spend (76%) and lacking the necessary resources and expertise (72%). &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check out the table below to see how these cloud challenges stack up against Enterprises (as well as a breakdown of other cloud challenges):<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"815\" height=\"479\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/SMB-top-cloud-challenges.png\" alt=\"Small business cyber security statistics graphic: This bar chart highlights the top cloud challenges for small businesses and enterprises.\" class=\"wp-image-15153\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/SMB-top-cloud-challenges.png 815w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/SMB-top-cloud-challenges-300x176.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/SMB-top-cloud-challenges-768x451.png 768w\" sizes=\"auto, (max-width: 815px) 100vw, 815px\" \/><figcaption class=\"wp-element-caption\">Data source: Flexera&#8217;s 2021 State of the Cloud Report.<\/figcaption><\/figure>\n<\/div>\n\n\n\n\n<p class=\"wp-block-paragraph\"><strong>7. 93% of Small Business Data Breaches Are Financially Motivated<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When it comes to money, to paraphrase a line from a popular country song, cybercriminals \u201clike it, love it, and want some more of it.\u201d Verizon\u2019s 2021 DBIR report shows that the data breaches they analyzed were overwhelmingly caused by threat actors who had financial motivations. Compare this to 3% of cases that involved espionage and the remaining 4% that include \u201cfun\u201d and \u201cconvenience\u201d as motives.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This differs from larger organizations (1,000 or more employees) that had 87% of breaches that were financially motivated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>8. 84% of MSPs Say SMBs Should Be &#8220;Very Concerned&#8221; About Ransomware<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In their&nbsp;2020 <a href=\"https:\/\/www.datto.com\/resources\/dattos-global-state-of-the-channel-ransomware-report\">Global State of the Channel Ransomware Report<\/a>, Datto reported that four in five managed service providers (MSPs) identified ransomware (68%) as the biggest malware threat to SMBs. But there appears to be a significant difference in opinion regarding the threat of ransomware attacks:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u201c84% of MSPs say that SMBs should be \u201cvery concerned\u201d about the threats that ransomware poses to organizations, and<\/li>\n\n\n\n<li>30% report their SMB clients are \u201cvery concerned\u201d and 32% are \u201cmoderately concerned\u201d about ransomware.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Be sure to check out our other article that specifically focuses on <a href=\"https:\/\/www.thesslstore.com\/blog\/ransomware-statistics\/\">ransomware statistics<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>9. 63% of SMBs Report Experiencing a Data Breach in the Previous 12 Months<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Data from a&nbsp;<a href=\"https:\/\/start.keeper.io\/2019-ponemon-report\">2019 study by Keeper Security and the Ponemon Institute<\/a>&nbsp;shows that the number of small and medium-sized businesses that experienced data breaches increased to 63% in FY 2019. In the two prior fiscal years, participants report 58% in FY 2018 and 54% in FY 2017, respectively.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>10. Small Organizations&#8217; Privacy Budgets Reach an Average of $1.6 Million<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cisco reports in its <a href=\"https:\/\/www.cisco.com\/c\/dam\/en_us\/about\/doing_business\/trust-center\/docs\/cisco-privacy-benchmark-study-2021.pdf\">2021 Data Privacy Benchmark Study<\/a> that the average privacy budget for smaller organizations (250-499 employees) doubles from $0.8 million to $1.6 million. Although they didn\u2019t have data available from last year, this year\u2019s average privacy budget for small businesses with 50-249 employees is $1.1 million.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>11. 46% of SMBs With &lt;1K Employees Had 5-16 Hours of Breach-Related Downtime<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cisco\u2019s 2020 CISO Benchmark Study data indicates that downtime from data breaches is an issue for all organizations with up to 10,000 employees. According to their data (as it was cited in Cisco\u2019s <a href=\"https:\/\/www.cisco.com\/c\/en\/us\/products\/security\/ciso-benchmark-report-2020.html\">\u201cSecuring What\u2019s Now and What\u2019s Next\u201d report<\/a>), small and mid-size organizations with 250-449 employees reported the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>43% experienced 0-4 hours of downtime<\/li>\n\n\n\n<li>45% experienced experiencing 5-16 hours of downtime, and<\/li>\n\n\n\n<li>12% experienced 17-48 hours of downtime.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For businesses with more employees \u2014 500-999 or 1,000-9,999 employees \u2014 their numbers showed greater variance:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"906\" height=\"630\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/cisco-small-business-cyber-security-statistics.png\" alt=\"A graph of SMB data breach downtime from Cisco\" class=\"wp-image-12740\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/cisco-small-business-cyber-security-statistics.png 906w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/cisco-small-business-cyber-security-statistics-300x209.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/cisco-small-business-cyber-security-statistics-768x534.png 768w\" sizes=\"auto, (max-width: 906px) 100vw, 906px\" \/><figcaption class=\"wp-element-caption\">Image source: Cisco\u2019s <a href=\"https:\/\/www.cisco.com\/c\/en\/us\/products\/security\/ciso-benchmark-report-2020.html\" target=\"_blank\" rel=\"noreferrer noopener\">\u201cSecuring What\u2019s Now and What\u2019s Next\u201d report<\/a>.<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>12. 47% of SMBs Report Keeping Data Secure as Biggest Challenge<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.vipre.com\/wp-content\/uploads\/2020\/07\/VIPRE_2020_IG_-SMB-SECURITY-TRENDS-_0715_US-1.pdf\">VIPRE\u2019s SMB Security Trends<\/a> survey results indicate that nearly half of the CISOs and IT pros surveyed find data security to be their biggest IT security challenge. The next biggest hurdles they identified include preventing data loss (42%) and increasing employee security awareness (41%).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>13. Credentials (44%) Represent the Most Compromised Type of Data in 2019<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Credential compromise continues to be an issue for SMBs and other businesses as well. Verizon\u2019s 2020 DBIR reports that more than half (52%) of small businesses reported issues of credential compromised in 2019. Their 2021 DBIR shows that while the number has decreased to 44%, it remains the most common type of compromised data followed by:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Personal (39%),<\/li>\n\n\n\n<li>Other (34%), and<\/li>\n\n\n\n<li>Medical (17%).<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">But just who does Verizon say is responsible for these attacks on small businesses?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>14. 57% of SMB Data Breaches Involve External Threat Actors<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By far, the overwhelming majority (57%) of the data breaches that targeted small businesses were perpetrated by external threat actors, according to Verizon\u2019s 2021 DBIR. However, it\u2019s worth mentioning that this is a noticeable decrease from the 74% they reported in their 2020 DBIR.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But how does this compare to insider threats? Verizon says that internal threat actors were responsible for 44% of the breaches they analyzed in their 2021 report. This is an increase from the 26% they reported the previous year\u2019s report.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>15. 22% of SMBs Switched to Remote Work Without a Cybersecurity Threat Prevention Plan<\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"300\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Recovery-Plan-2-300x300.png\" alt=\"\" class=\"wp-image-11046\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Recovery-Plan-2-300x300.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Recovery-Plan-2-768x768.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/Recovery-Plan-2.png 788w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The COVID-19 global pandemic forced the hands of businesses worldwide to allow their employees to work from home at unprecedented rates starting in 2020. But what does this mean for small business cybersecurity preparations? Research from <a href=\"https:\/\/www.alliantcybersecurity.com\/the-flight-to-remote-working-cybersecurity\/\">Alliant Cybersecurity<\/a> shows that one-in-five small businesses jumped head-first into remote working without having a clear cybersecurity mitigation or prevention policy in place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, consider that more than half (52%) of these SMBs indicate that they didn\u2019t regularly allow their employees to work remotely prior to the start of the pandemic. With this in mind, it\u2019s easy to imagine what kind of Pandora\u2019s box this opens in terms of cybersecurity vulnerabilities and risks. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, what makes matters worse is findings from the Keeper Security\/Ponemon Institute survey we mentioned earlier. Their data shows that 39% of their SMB survey respondents report that their organizations lack any incident response plans. So, this means that when (not if) crap hits the proverbial cooling system, they won\u2019t have a plan in place that helps them to respond to cyber-related events.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-smbs-are-thought-to-be-more-vulnerable-to-cyber-attacks-data-breaches\">Why SMBs Are Thought to Be More Vulnerable to Cyber Attacks &amp; Data Breaches<\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"300\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/SMBs-300x300.png\" alt=\"\" class=\"wp-image-11045\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/SMBs-300x300.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/SMBs-768x768.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/SMBs.png 852w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Small businesses are the drivers of the U.S. economy. The most recent data from the <a href=\"https:\/\/cdn.advocacy.sba.gov\/wp-content\/uploads\/2021\/08\/30144808\/2021-Small-Business-Profiles-For-The-States.pdf\">U.S. Small Business Administration (SBA)&nbsp;reports<\/a>&nbsp;that there are 32.5 million small businesses in the U.S. Furthermore, a significant part of the country\u2019s workforce includes 61.2 million small business employees. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Historically, there\u2019s been this common notion that small businesses are at greater risk to cybercrimes because they lack the resources \u2014 funds, personnel, time, etc. \u2014 to properly monitor and mitigate cyber threats. However, Verizon\u2019s 2021 DBIR findings indicate that the gap between the number of breaches that SMBs and larger organizations experience is narrowing, and the top breach patterns targeting both groups were largely identical:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>80%<\/strong> \u2014 This small business cyber security statistic represents the percentage of breaches that involved system intrusion, miscellaneous errors, and basic web app attacks.<\/li>\n\n\n\n<li><strong>74%<\/strong> \u2014 Much like SMBs, large organizations also share these three top patterns for nearly three in four data breaches.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">However, where they still differ is in their detection capabilities. Large organizations are doing better in terms of detecting breaches faster than their smaller counterparts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately for consumers, some business owners and executives still convince themselves that their businesses are too small to be of interest to hackers. Some businesses take a head-in-the-sand approach to cyber security even though they say they experienced cyber attacks and data breaches in the past! This means that they may not put the time, money, training, and other resources in place to protect their businesses (and their customers as a result).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-you-can-protect-your-small-business-from-smb-cyber-security-attacks\">How You Can Protect Your Small Business from SMB Cyber Security Attacks<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">At the SSL Store, we\u2019re a small company with about 80 employees. We specialize in secure sockets layer\/transport layer security (SSL\/TLS) to create encrypted connections. As such, we\u2019re happy to help you configure your servers for maximum protection and to get that lauded \u201cHTTPS\u201d in your web address. However, that\u2019s only one piece of the puzzle \u2014 SSL only secures certain attack vectors. As such, you\u2019ll need to invest in additional security measures to increase the digital security of your small or medium-sized business. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some such methods that should be used to create\nmulti-layered protection include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Firewalls, antivirus, and endpoint security solutions<\/li>\n\n\n\n<li>Network penetration testing and vulnerability assessments<\/li>\n\n\n\n<li>Cyber security audits<\/li>\n\n\n\n<li>Computer use, device, and password policies<\/li>\n\n\n\n<li>Strong <a href=\"https:\/\/www.thesslstore.com\/blog\/pki-management-private-key-certificate-lifecycle-management-best-practices\/\">PKI management<\/a> practices<\/li>\n\n\n\n<li>Access management and <a href=\"https:\/\/www.thesslstore.com\/blog\/the-role-of-access-control-in-information-security\/\">access control<\/a> policies and procedures<\/li>\n\n\n\n<li>Email security solutions (such as anti-phishing solutions, spam filters, email signing certificates [S\/MIME certificates])<\/li>\n\n\n\n<li>Employee cyber security awareness training and phishing simulations<\/li>\n\n\n\n<li>Incident response and disaster recovery plans<\/li>\n\n\n\n<li>Current data backups<\/li>\n\n\n\n<li>Updates and patching<\/li>\n<\/ul>\n\n\n<span style=\"--tl-form-height-m:966.781px;--tl-form-height-t:989px;--tl-form-height-d:989px;\" class=\"tl-placeholder-f-type-shortcode_12768 tl-preload-form\"><span><\/span><\/span>\n\n\n<p class=\"wp-block-paragraph\">But what are some of the most common methods of defense that SMBs implement? According to 2020 <a href=\"https:\/\/themanifest.com\/mobile-apps\/data-safety-small-businesses-2020-cybersecurity-statistics\">survey data from The Manifest<\/a>:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8220;<em>The most popular small business cybersecurity measures include limiting employee access to user data (46%), data encryption (44%), requiring strong user passwords (34%), and training employees on data safety and best practices (34%).\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-tl-dr-a-quick-summary-of-these-smb-cybersecurity-statistics-findings\">TL;DR? A Quick Summary of These SMB Cybersecurity Statistics Findings<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We know you\u2019ve already got a lot on your plate and probably\ndon\u2019t have time to read a long article. Here\u2019s what we covered in today\u2019s\ndiscussion on small business cyber security statistics: <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We know you\u2019ve already got a lot on your plate and probably don\u2019t have time to read a long article. Here\u2019s what we covered in today\u2019s discussion on small business cyber security statistics:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>$2.98 million is the average cost of a data breach for small businesses, according to IBM and the Ponemon Institute.<\/li>\n\n\n\n<li>Small and medium-sized businesses need to get their butts in gear and put cybersecurity threat mitigation and incident response plans in place.<\/li>\n\n\n\n<li>Consumer-grade cybersecurity products simply aren\u2019t going to cut it for securing small businesses.<\/li>\n\n\n\n<li>Phishing still leads the way in terms of being the leading threat action that attackers use against SMBs.<\/li>\n\n\n\n<li>The largest percentages of surveyed SMBs experienced between 5 and 16 hours of downtime during a breach.<\/li>\n\n\n\n<li>You need security beyond just SSL \u2013 this should include the use of firewalls, email security protections, secure CDNs, two-factor authentication (2FA), and endpoint security.<\/li>\n\n\n\n<li>Ensure all software, hardware, servers, and other devices are up to date.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><em><strong>Editor&#8217;s Note:<\/strong> This article was originally published in June 2019. It was updated with new SMB cyber security statistics and research on Dec. 9, 2020 and again on Nov. 11, 2021. It will be updated again in 2022 to include new small business cyber security statistics.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Small business cyber attacks aren\u2019t cheap \u2014 IBM reports that breaches associated with business email compromise cost an average of $5.01 million in 2020. Here\u2019s our list of the top&#8230;<\/p>\n","protected":false},"author":17,"featured_media":12743,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16,10200],"tags":[4458,10083],"class_list":["post-11044","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","category-monthly-digest","tag-smbs","tag-statistics","post-with-tags"],"views":120075,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/06\/small-business-cyber-security-statistics.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/11044","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=11044"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/11044\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/12743"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=11044"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=11044"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=11044"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}