Verified Primary Sources · Updated September 2026

Cybersecurity Statistics for Small Business 2026

The numbers every team needs before deciding what to secure: breach frequency, cost, ransomware, phishing, and the human factor. Pulled from FBI IC3, Verizon DBIR, IBM, and primary government sources. Built to be cited.

83 verified statisticsPrimary sources onlyNo fabricated figures

Key Takeaways

✓

Cyber breach/attack prevalence by size: 42% of micro businesses and 46% of small businesses, rising to 65% of medium and 69% of large businesses. Source: UK Government (DSIT), Cyber Security Breaches Survey 2025/2026, 2026.

✓

19% of UK businesses (approximately 267,000) were victims of at least one cyber crime in the past year (17% micro, 24% small, 41% medium, 48% large). Source: UK Government (DSIT), Cyber Security Breaches Survey 2025/2026, 2026.

✓

Verizon's 2026 DBIR recorded 7,256 incidents and 7,152 confirmed data breaches at small- and medium-sized businesses, up sharply from 3,049 SMB incidents in the 2025 edition. Source: Verizon, 2026 Data Breach Investigations Report (DBIR), SMB table, 2026.

✓

Global average cost of a data breach reached a record USD 4.99 million, a 12% increase over the prior year. Source: IBM, Cost of a Data Breach Report 2026, 2026.

✓

Ransomware appeared in 48% of all breaches in the 2026 DBIR, up from 44% the previous year. Source: Verizon, 2026 DBIR Executive Summary, 2026.

✓

69% of ransomware victims did not pay the ransom; the median ransom paid fell to $139,875 from $150,000 the previous year. Source: Verizon, 2026 DBIR Executive Summary, 2026.

✓

Ransomware was present in 88% of SMB breaches, versus 39% of breaches at larger organizations, showing ransomware disproportionately hits small businesses. Source: Verizon, 2025 DBIR Small- and Medium-Sized Business Snapshot, 2025.

✓

56% of ransomware attacks succeeded in encrypting data, and only 1 in 3 smaller organizations stopped an attack before encryption. Source: Sophos, The State of Ransomware 2026, 2026.

✓

Business Email Compromise (BEC) generated $3.05 billion in IC3-reported losses in 2025 across 24,768 complaints, the second-largest loss category. Source: FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report, 2025.

✓

Phishing attacks were experienced by 38% of UK businesses, and 69% of breached organizations named phishing as their most disruptive breach type. Source: UK Government (DSIT), Cyber Security Breaches Survey 2025/2026, 2026.

✓

The average data breach lifecycle (time to identify plus contain) rose to 247 days. Source: IBM, Cost of a Data Breach Report 2026, 2026.

✓

Internal security teams identified 38% of breaches and organizations' own security tools found 31%; third parties such as partners and law enforcement identified 14%. Source: IBM, Cost of a Data Breach Report 2026, 2026.

Statistics are attributed to their original producing organizations, FBI Internet Crime Complaint Center (IC3), Verizon Data Breach Investigations Report (DBIR) and Breach Impact Study, IBM Cost of a Data Breach Report, UK Government (DSIT) Cyber Security Breaches Survey, FTC, Sophos, and linked for verification. Prospyr 305 has no affiliation with these sources; they are cited for reference. A small share of figures (labeled "UK" / "GBP") come from the UK Government's Breaches Survey, which publishes the most current primary SMB-level cyber prevalence and cyber-insurance data.

What percentage of small businesses experience a cyber attack?

Verified primary sources. Linked at each statistic.

43% of UK businesses reported experiencing a cyber security breach or attack in the previous 12 months, equivalent to approximately 612,000 UK businesses.

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025/2026, 2026. Source

Cyber breach/attack prevalence by size: 42% of micro businesses and 46% of small businesses, rising to 65% of medium and 69% of large businesses.

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025/2026, 2026. Source

19% of UK businesses (approximately 267,000) were victims of at least one cyber crime in the past year (17% micro, 24% small, 41% medium, 48% large).

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025/2026, 2026. Source

3% of all UK businesses (about 43,000) were victims of cyber-facilitated fraud in the last 12 months.

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025/2026, 2026. Source

Verizon's 2026 DBIR recorded 7,256 incidents and 7,152 confirmed data breaches at small- and medium-sized businesses, up sharply from 3,049 SMB incidents in the 2025 edition.

Source: Verizon, 2026 Data Breach Investigations Report (DBIR), SMB table, 2026. Source

System Intrusion, Basic Web Application Attacks and Social Engineering accounted for 100% of small- and medium-sized business breaches in the 2026 DBIR dataset.

Source: Verizon, 2026 Data Breach Investigations Report (DBIR), SMB table, 2026. Source

The 2025 DBIR analyzed 3,049 incidents and 2,842 confirmed data disclosures at small businesses (fewer than 1,000 employees).

Source: Verizon, 2025 DBIR Small- and Medium-Sized Business Snapshot, 2025. Source

What is the average cost of a data breach for a small business vs. an enterprise?

Verified primary sources. Linked at each statistic.

Median financial impact of a cyber-insurance claim for an SMB (under $25M revenue) was about $38,000, versus about $96,000 for mid-market and about $283,000 for large enterprises.

Source: Verizon, 2026 Breach Impact Study (BIS), 2026. Source

In the SMB segment, breach impact reached 3% of revenue in the top 10% of cases and more than 7% of revenue in the top 2.5%; for mid-market and large enterprises it did not exceed 2% even in the top 2.5% of cases.

Source: Verizon, 2026 Breach Impact Study (BIS), 2026. Source

The top 2.5% of large-enterprise claims exceeded $22 million per claim, about 22 times larger than the same extreme tail of SMB claims.

Source: Verizon, 2026 Breach Impact Study (BIS), 2026. Source

Half of all paid cyber-insurance claims reviewed had a financial impact greater than $83,000; the top 10% exceeded $920,000 and the top 2.5% exceeded $5 million.

Source: Verizon, 2026 Breach Impact Study (BIS), 2026. Source

The median cyber-insurance claim impact almost doubled from 2019 to 2024, an 80% increase from roughly $60,000 to roughly $110,000.

Source: Verizon, 2026 Breach Impact Study (BIS), 2026. Source

Global average cost of a data breach reached a record USD 4.99 million, a 12% increase over the prior year.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

Average cost of a data breach in the United States hit a record USD 11.5 million, more than double the global average.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

Breaches with a lifecycle longer than 200 days cost an average of USD 5.65 million, versus USD 4.32 million for breaches contained in under 200 days.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

Healthcare recorded the highest average breach cost for the 13th consecutive year at USD 6.64 million; the financial services sector averaged USD 6.29 million and energy USD 5.2 million.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

The average self-reported cost of the most disruptive breach for a UK business was GBP 1,600 (GBP 3,550 when excluding businesses that reported zero cost).

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025, 2025. Source

Median perceived cost of the most disruptive breach for UK micro/small businesses was GBP 0, with the top 5% of cases (95th percentile) reaching GBP 15,000 (GBP 20,000 across all businesses).

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025/2026, 2026. Source

How common is ransomware at small businesses, and how much does it cost?

Verified primary sources. Linked at each statistic.

Ransomware appeared in 48% of all breaches in the 2026 DBIR, up from 44% the previous year.

Source: Verizon, 2026 DBIR Executive Summary, 2026. Source

69% of ransomware victims did not pay the ransom; the median ransom paid fell to $139,875 from $150,000 the previous year.

Source: Verizon, 2026 DBIR Executive Summary, 2026. Source

In the 2025 DBIR, ransomware was present in 44% of all breaches (up from 32%), the median amount paid fell to $115,000, and 64% of victims did not pay.

Source: Verizon, 2025 DBIR Small- and Medium-Sized Business Snapshot, 2025. Source

Ransomware was present in 88% of SMB breaches, versus 39% of breaches at larger organizations, showing ransomware disproportionately hits small businesses.

Source: Verizon, 2025 DBIR Small- and Medium-Sized Business Snapshot, 2025. Source

The FBI's IC3 received 3,611 ransomware complaints in 2025, with reported losses exceeding $32 million (a figure that excludes lost business, wages and third-party remediation).

Source: FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report, 2025. Source

IC3 identified 63 new ransomware variants in 2025; the top 10 reported variants accounted for 56.8% of ransomware incidents and 49.8% of reported ransomware losses.

Source: FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report, 2025. Source

IC3 received more than 1,400 ransomware complaints from businesses outside critical infrastructure in 2025, led by legal services (18%), contracting services (17%), engineering/architectural services (10%) and consulting services (7%).

Source: FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report, 2025. Source

IC3 ransomware complaints rose 9% in 2024 versus 2023, with 3,156 complaints and $12.47 million in reported losses.

Source: FBI Internet Crime Complaint Center (IC3), 2024 Internet Crime Report, 2024. Source

Ransomware affected 1% of UK businesses in 2025, about 19,000 businesses, up from less than 0.5% in 2024.

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025, 2025. Source

56% of ransomware attacks succeeded in encrypting data, and only 1 in 3 smaller organizations stopped an attack before encryption.

Source: Sophos, The State of Ransomware 2026, 2026. Source

The median ransom payment reported by Sophos was $769,000 and the average recovery cost from a ransomware attack was $1.7 million.

Source: Sophos, The State of Ransomware 2026, 2026. Source

Ransomware was the most common incident type in SMB cyber-insurance claims (39%), followed by Business Email Compromise (19%).

Source: Verizon, 2026 Breach Impact Study (BIS), 2026. Source

How common are phishing and social engineering attacks on small businesses?

Verified primary sources. Linked at each statistic.

Phishing/spoofing was the most-reported crime type to IC3 in 2025: 191,561 complaints and $215.8 million in reported losses.

Source: FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report, 2025. Source

Phishing/spoofing was the most-reported crime type to IC3 in 2024 with 193,407 complaints.

Source: FBI Internet Crime Complaint Center (IC3), 2024 Internet Crime Report, 2024. Source

Business Email Compromise (BEC) generated $3.05 billion in IC3-reported losses in 2025 across 24,768 complaints, the second-largest loss category.

Source: FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report, 2025. Source

BEC losses as reported to IC3 totaled $2.77 billion in 2024.

Source: FBI Internet Crime Complaint Center (IC3), 2024 Internet Crime Report, 2024. Source

BEC losses reached $6.3 billion in 2024, with the median amount extracted from victims settling around $50,000.

Source: Verizon, 2025 DBIR (citing FBI IC3 data), 2025. Source

Phishing remained the initial access vector in 16% of breaches and pretexting reached 6%; Social Engineering was the third most common breach pattern at 16%.

Source: Verizon, 2026 DBIR Executive Summary, 2026. Source

Phishing attacks with mobile-based entry points (voice and text) had a 40% higher median click rate than email-based phishing in simulations.

Source: Verizon, 2026 DBIR, SMB findings, 2026. Source

Prompt bombing (MFA login request spam) appeared in 14% of social engineering incidents, while other MFA-bypass techniques such as adversary-in-the-middle appeared in only 4% of breaches.

Source: Verizon, 2025 DBIR Small- and Medium-Sized Business Snapshot, 2025. Source

Phishing was the most prevalent and most disruptive breach type for UK businesses, experienced by 85% of those that identified a breach or attack.

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025, 2025. Source

Phishing attacks were experienced by 38% of UK businesses, and 69% of breached organizations named phishing as their most disruptive breach type.

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025/2026, 2026. Source

The FTC received 845,806 imposter-scam reports in 2024, with $2.952 billion in reported losses and a median loss of $800; business imposter reports alone numbered 399,753.

Source: Federal Trade Commission, Consumer Sentinel Network Data Book 2024, 2024. Source

Consumers reported losing more than $12.5 billion to fraud in 2024 (up over $2 billion from 2023), with a median loss of $497 across all fraud reports.

Source: Federal Trade Commission, Consumer Sentinel Network Data Book 2024, 2024. Source

Voice and SMS phishing was the costliest initial attack vector, used in 17% of attacks and leading to average breach costs of USD 5.29 million; social engineering (helpdesk impersonation/MFA fatigue) cost USD 5.23 million.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

How long does it take to detect and contain a breach?

Verified primary sources. Linked at each statistic.

The average data breach lifecycle (time to identify plus contain) rose to 247 days.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

Breaches involving replication to removable media or supply chain compromise took the longest to resolve, at 258 days on average.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

Only 42% of breached organizations fully recovered from their breach, up from 35% the previous year.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

Internal security teams identified 38% of breaches and organizations' own security tools found 31%; third parties such as partners and law enforcement identified 14%.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

The median time for organizations to fully resolve a critical vulnerability rose to 43 days (up from 32), and only 26% of CISA Known Exploited Vulnerabilities were fully remediated, down from 38% the previous year.

Source: Verizon, 2026 DBIR Executive Summary, 2026. Source

Only 23% of third-party cloud accounts with missing or misconfigured MFA were fully remediated; weak passwords and permission misconfigurations took almost eight months to resolve in half of cases.

Source: Verizon, 2026 DBIR Executive Summary, 2026. Source

In the 2025 DBIR, only about 54% of edge-device and VPN vulnerabilities were fully remediated, taking a median of 32 days.

Source: Verizon, 2025 DBIR Small- and Medium-Sized Business Snapshot, 2025. Source

61% of UK businesses took some action to prevent future incidents after a breach, but only 25% had a formal incident response plan in place.

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025/2026, 2026. Source

What percentage of small businesses have cyber insurance?

Verified primary sources. Linked at each statistic.

47% of UK businesses reported being insured against cyber security risks; small businesses (55%) and medium businesses (61%) were more likely than average to hold some form of cyber insurance.

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025/2026, 2026. Source

45% of UK businesses held cyber insurance in 2025; 62% of small businesses were insured, up from 49% in 2024.

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025, 2025. Source

The 2026 Breach Impact Study analyzed 69,683 cyber-insurance claims in the United States, of which 38,181 had recorded losses paid to policyholders.

Source: Verizon, 2026 Breach Impact Study (BIS), 2026. Source

SMB cyber-insurance claims numbered 15,431 (11,996 with recorded losses); 88.9% were primary policies, 9.7% endorsements and 1.5% excess-layer policies.

Source: Verizon, 2026 Breach Impact Study (BIS), 2026. Source

A majority of ransomware victims chose not to pay (69%), a trend consistent with cyber insurance and broker guidance against payment.

Source: Verizon, 2026 DBIR Executive Summary, 2026. Source

How much do human error and insider threats contribute to breaches?

Verified primary sources. Linked at each statistic.

The human element was present in 62% of breaches, a slight increase from 60% the previous year.

Source: Verizon, 2026 DBIR Executive Summary, 2026. Source

The human element was involved in roughly 60% of breaches, and third-party involvement doubled from 15% to 30% year over year.

Source: Verizon, 2025 DBIR Small- and Medium-Sized Business Snapshot, 2025. Source

Miscellaneous human errors accounted for 18% of breaches at large organizations but only 1% of SMB breaches.

Source: Verizon, 2025 DBIR Small- and Medium-Sized Business Snapshot, 2025. Source

Root causes of breaches: malicious or criminal attacks 55%, human error 23%, and IT failure 22%.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

Shadow AI is now the third most common non-malicious insider action detected in DLP data, a fourfold increase, with 67% of users accessing AI services via non-corporate accounts and 45% of employees now regular AI users on corporate devices (up from 15%).

Source: Verizon, 2026 DBIR Executive Summary, 2026. Source

15% of employees routinely accessed generative AI systems on corporate devices, and 72% of those accounts used non-corporate email identifiers.

Source: Verizon, 2025 DBIR Small- and Medium-Sized Business Snapshot, 2025. Source

The human element was a factor in 45% of SMB breaches and 55% involved a third party.

Source: Verizon, 2026 DBIR, SMB table, 2026. Source

What are the most common cyber attack vectors targeting small businesses?

Verified primary sources. Linked at each statistic.

Exploitation of software vulnerabilities became the most common initial access vector at 31% of breaches, overtaking credential abuse, which fell to 13%.

Source: Verizon, 2026 DBIR Executive Summary, 2026. Source

For SMBs specifically, initial access vectors were exploitation of vulnerabilities (26%), credential abuse (13%) and phishing (9%).

Source: Verizon, 2026 DBIR, SMB table, 2026. Source

In the 2025 DBIR, exploitation of vulnerabilities as an initial access vector reached 20% (up 34%), with edge devices and VPNs representing 22% of exploitation activity, an almost eightfold increase.

Source: Verizon, 2025 DBIR Small- and Medium-Sized Business Snapshot, 2025. Source

In Basic Web Application Attacks, 88% of breaches involved the use of stolen credentials.

Source: Verizon, 2025 DBIR Small- and Medium-Sized Business Snapshot, 2025. Source

Breaches with third-party involvement increased 60% year over year and now account for 48% of all breaches.

Source: Verizon, 2026 DBIR Executive Summary, 2026. Source

The 2026 DBIR analyzed more than 22,000 confirmed data breaches, the largest dataset in the report's history.

Source: Verizon, 2026 DBIR Executive Summary, 2026. Source

53% of breached organizations had not encrypted their sensitive data, leaving it exposed in the event of an attack.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

Among UK businesses that experienced cyber crime, phishing was the most common type by a wide margin (93% of those affected).

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025, 2025. Source

Just 15% of UK businesses reviewed the risks posed by their immediate suppliers and only 6% reviewed their wider supply chain.

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025/2026, 2026. Source

What does a breach cost per record, and how does it compare to SMB security budgets?

Verified primary sources. Linked at each statistic.

Customer personally identifiable information was the most commonly compromised data type (52% of breaches) and cost an average of USD 192 per record.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

Employee PII was compromised in 35% of breaches and cost on average USD 188 per record, while intellectual property was the costliest data type at USD 196 per record.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

AI-enabled attack economics: AI model inversion attacks averaged nearly USD 6 million and prompt-injection attacks averaged USD 6.07 million and USD 5.89 million across categories.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

AI-driven attacks increased 56% year over year and added an average of USD 1 million per breach.

Source: IBM, Cost of a Data Breach Report 2026, 2026. Source

Software supply chain claims had a median impact of $252,666, more than double the overall median, with the top 2.5% of losses exceeding $100 million.

Source: Verizon, 2026 Breach Impact Study (BIS), 2026. Source

Business interruption losses had the highest median among loss types at around $90,000, with the top 2.5% reaching almost $5 million.

Source: Verizon, 2026 Breach Impact Study (BIS), 2026. Source

The mean cost of cyber crime for a UK business (excluding phishing) was GBP 990, rising to GBP 1,970 when excluding businesses reporting zero cost.

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025, 2025. Source

Cyber-facilitated fraud cost UK businesses a mean of GBP 5,900 each (GBP 10,000 when excluding zero-cost responses), higher than other cyber crime.

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025, 2025. Source

Only 47% of UK businesses required two-factor authentication and just 30% had conducted a cyber security risk assessment, indicating SMB budget and control gaps.

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025/2026, 2026. Source

14% of UK businesses said they held personal data not protected by anonymisation or encryption.

Source: UK Government (DSIT), Cyber Security Breaches Survey 2025/2026, 2026. Source

The FBI's IC3 Recovery Asset Team recovered about 58% of the $1.16 billion in attempted fraudulent transfers it handled in 2025, freezing $679 million.

Source: FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report, 2025. Source

Know the numbers. Close the gaps.

We run adversarial security testing and cloud audits that turn these statistics into your action list, same-day, with verified proof of every finding.