---
title: "Why Small Businesses Are Still the #1 Cybercrime Target in…"
description: "By 2026, 73% of cyberattacks hit SMBs, costing $3.8M per breach. Learn why your business is a target, how threats have evolved, and what controls actually…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Person",
      "@id": "https://christianespinosa.com/#person",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "image": "https://christianespinosa.com/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg",
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ],
      "jobTitle": "Bestselling Author, Keynote Speaker, Entrepreneur",
      "worksFor": {
        "@type": "Organization",
        "name": "Blue Goat Cyber",
        "url": "https://bluegoatcyber.com/"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://christianespinosa.com/#website",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "publisher": {
        "@id": "https://christianespinosa.com/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://christianespinosa.com/#organization",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://christianespinosa.com/logo.svg"
      },
      "founder": {
        "@id": "https://christianespinosa.com/#person"
      },
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Why Small Businesses Are Still the #1 Cybercrime Target in 2026 - Christian Espinosa",
      "description": "By 2026, 73% of cyberattacks hit SMBs, costing $3.8M per breach. Learn why your business is a target, how threats have evolved, and what controls actually…",
      "image": "https://christianespinosa.com/__l5e/assets-v1/5fd05b58-3baa-46cd-bbeb-6a5e8891e773/70-of-cyber-attacks-will-be-against-small-businesses-in-2020-card.png",
      "datePublished": "2020-01-24T05:58:00+00:00",
      "dateModified": "2026-06-26T05:31:41.873Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://christianespinosa.com/blog/70-of-cyber-attacks-will-be-against-small-businesses-in-2020"
      },
      "author": {
        "@type": "Person",
        "name": "Christian Espinosa",
        "url": "https://christianespinosa.com/about"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Christian Espinosa",
        "logo": {
          "@type": "ImageObject",
          "url": "https://christianespinosa.com/logo.svg"
        }
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is the core idea behind \"Why Small Businesses Are Still the #1 Cybercrime Target in 2026 - Christian Espinosa\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Small and mid-sized businesses absorb the majority of cyberattacks. Here's why attackers target them, what's changed since 2020, and the practical defenses that actually work."
          }
        },
        {
          "@type": "Question",
          "name": "Who is this post for?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Honestly, security leaders, medical device teams, and technical operators who want the honest version, not the vendor version. If you want a listicle, this is not that. If you want the honest version of what I have actually lived and worked through, keep reading."
          }
        },
        {
          "@type": "Question",
          "name": "How do I actually apply this, not just nod along?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Pick the single line in the post that made you flinch or look away, and change one thing in your week because of it. One choice this week beats a whole framework you never touch."
          }
        }
      ]
    }
  ]
---

[Skip to content](#main)

[](/)

[About](/about)[Speaking](/speaking)[Cybersecurity](/cybersecurity)[Programs](/programs)[Books](/books)[Media](/media)

Writing

Search Ctrl K[Connect](/connect)

[Cybersecurity](/blog/category/cybersecurity)

# Why Small Businesses Are Still the #1 Cybercrime Target in 2026

January 24, 2020 6 min read 1,223 words 

Back in 2020, I wrote a post warning that 70% of cyber attacks were aimed directly at small and mid-sized businesses. I told leaders then that the "we're too small to be a target" excuse was a dangerous delusion.

![](/__l5e/assets-v1/13cc7366-511f-4407-9a1d-49568b872401/332629a66660.jpg)

The takeaways

1.  01 
    
    The landscape hasn’t just validated that warning; it has accelerated.
    
    What to do next Ask your security lead this week for the one-page view of landscape in your environment, and read it end to end.
    
2.  02 
    
    The Verizon Data Breach Investigations Report (DBIR) 2025 says 73% of all breaches now involve SMBs.
    
    What to do next Open your current breach plan today and identify the one gap you would not want an auditor to find.
    
3.  03 
    
    The IBM Cost of a Data Breach 2025 report reveals that the average cost of an SMB breach has surged to $3.8 million.
    
    What to do next Open your current breach plan today and identify the one gap you would not want an auditor to find.
    
4.  04 
    
    For most companies under $50M in revenue, a breach is no longer an IT headache, it is an extinction-level event.
    
    What to do next Open your current revenue plan today and identify the one gap you would not want an auditor to find.
    

## You’re Still the Target: Why 73% of Cyber Attacks Hit SMBs in 2026 (And What to Do About It)

Back in 2020, I wrote a post warning that 70% of cyber attacks were aimed directly at small and mid-sized businesses. I told leaders then that the "we're too small to be a target" excuse was a dangerous delusion.

It's 2026 now. The landscape hasn’t just validated that warning; it has accelerated. The _Verizon Data Breach Investigations Report (DBIR) 2025_ says 73% of all breaches now involve SMBs. The stakes, however, have skyrocketed. The _IBM Cost of a Data Breach 2025_ report reveals that the average cost of an SMB breach has surged to $3.8 million. For most companies under $50M in revenue, a breach is no longer an IT headache, it is an extinction-level event.

If you are a business leader, this is your reality. You cannot ignore it, and you cannot completely outsource the risk. It’s time to look past the fluff and understand why you are in the crosshairs, what has mutated since 2020, and how to execute on the controls that actually move the needle.

## Why SMBs Remain the Ultimate Target

Cybercriminals are business operators. They look for high return on investment (ROI) with minimal friction. SMBs sit at the perfect, vulnerable intersection of this calculus.

First, you have enough cash to pay a ransom, but you likely lack the 24/7 Security Operations Center (SOC) to stop an attack. You are the path of least resistance.

Second, you are the stepping stone. As Fortune 500 companies have poured billions into hardening their perimeters, threat actors realized it's much easier to breach the enterprise by hacking their vendors. You are the HVAC contractor, the law firm, or the specialized manufacturer digitally hooked into your enterprise client’s network. You are targeted for the access you provide.

## What’s Changed Since 2020

The fundamental vulnerability of SMBs remains, but the tactics deployed against you have scaled aggressively. Here is what has shifted:

### 1\. The Industrialization of Ransomware (RaaS)

Ransomware is no longer executed by lone wolves; it is an organized, franchised enterprise. Ransomware-as-a-Service (RaaS) allows affiliates with zero technical skills to rent elite malware. The _Sophos State of Ransomware 2025_ report dropped a bombshell: 68% of SMBs were hit by ransomware last year. It is a high-volume volume game, and your IP addresses are being scanned blindly every second by automation.

### 2\. Supply Chain and MSP Exploitation

Attackers have realized they can hack one entity to compromise hundreds. _ENISA_ reports that supply chain and Managed Service Provider (MSP) attacks have tripled over the last three years. If your MSP gets breached, _you_ get breached. Trusting a third party to handle your IT blindly without auditing their security maturity is a critical leadership failure.

### 3\. AI-Enabled Phishing at Scale

Forget Nigerian prince emails with terrible grammar. In 2026, generative AI has armed attackers with the ability to create hyper-personalized, flawless phishing campaigns at scale. They synthesize your CEO’s tone, reference current vendor invoices, and create deepfake audio for business email compromise (BEC). Human intuition is no longer enough to spot a fake.

### 4\. The Cyber Insurance Squeeze

In 2020, you could buy a cyber insurance policy with a pulse and a premium. Today, insurers are bleeding from ransomware payouts. The _Coalition 2025 Cyber Claims Report_ illustrates a brutal new reality: premiums have stabilized, but coverage is ruthlessly denied if you cannot prove you maintained basic security hygiene. Insurance is no longer a substitute for adequate cybersecurity; it is a reward for it.

## The 6 Controls That Actually Move the Needle

Stop getting distracted by shiny new security tools promising military-grade AI protection. Cybersecurity success is about brilliant at the basics. Stop doing security theater and implement these six foundational controls:

### 1\. Phishing-Resistant MFA

Multifactor Authentication (MFA) via SMS texts or simple push notifications is effectively dead, attackers bypass them daily with adversary-in-the-middle (AiTM) attacks and MFA fatigue. You need phishing-resistant MFA across all critical systems. Move to FIDO2 hardware keys or passkeys. Make it impossible for a stolen password to equal a compromised network.

### 2\. Endpoint Detection and Response (EDR / MDR)

Legacy antivirus is useless against modern, fileless attacks. You need EDR deployed on every endpoint to monitor for malicious activity and isolate infected machines instantly. Because EDR requires human context, most SMBs need Managed Detection and Response (MDR), put a 24/7 team of experts behind the tool so alerts aren't ignored at 2 A.M. On a Sunday.

### 3\. Immutable, Air-Gapped Backups

When ransomware hits, attackers actively seek out your backups to destroy them, forcing you to pay. Your backups must be immutable (unchangeable, even by an admin) and segregated from your primary network. If a threat actor gets domain admin privileges, they still shouldn't be able to delete your backups.

### 4\. Aggressive Patching SLAs

Vulnerability management cannot be an "when we get to it" effort. _CISA_ (Cybersecurity and Infrastructure Security Agency) maintains a Known Exploited Vulnerabilities (KEV) catalog. When a vulnerability hits that list, you do not have weeks; you have hours. Establish a formal Service Level Agreement (SLA) with your IT team or MSP to patch critical, internet-facing assets within 48 hours.

### 5\. Advanced Cloud Email Security

Because AI has supercharged phishing, native Microsoft 365 or Google Workspace filters are not enough. You need an API-based cloud email security solution that uses behavioral analysis to detect business email compromise, vendor impersonation, and zero-day malicious links before they reach the inbox.

### 6\. A Tested Incident Response (IR) Plan

Having a Word document labeled "IR Plan" on a server that gets encrypted during an attack is useless. You must have a physical, printed plan, and you must run a tabletop exercise at least annually. Execution matters more than theory. When a breach happens, your team needs muscle memory, not a brainstorming session.

## A Note on Leadership and Culture

Cybersecurity is not an IT problem. It is a business risk and a leadership issue. When a breach occurs, the market doesn't blame your systems administrator; they blame the executive team.

Also, you cannot simply hire your way out of this. The _ISC2 Cybersecurity Workforce Study 2025_ highlights a global shortage of over 4.8 million cybersecurity professionals. The talent pool is incredibly tight, and egos often run high in tech. As leaders, you must foster a culture where security is everyone's responsibility.

Kill the "genius IT guy" silo where one person holds the keys to the kingdom. Demand transparency, metrics, and accountability from your technical teams. If they cannot explain a risk to you in plain business English, they either don't understand it themselves, or they are hiding behind jargon to protect their ego.

## Bottom Line

The 2026 threat landscape for small and mid-sized businesses is highly automated, ruthlessly efficient, and incredibly expensive. The attackers don't care how small you are; they care how vulnerable you are. Stop relying on hope. Implement the six controls, hold your IT providers accountable, and lead your organization toward genuine cyber resilience. Action prevents extinction.

Frequently asked

### What is the core idea behind "Why Small Businesses Are Still the #1 Cybercrime Target in 2026 - Christian Espinosa"?

### Who is this post for?

### How do I actually apply this, not just nod along?

### Work with me

I help founders and cybersecurity leaders build teams that ship, not teams that stall. If that's the problem you're trying to solve, let's talk.

[Start a conversation](/contact)

Share this essay

[X ](https://twitter.com/intent/tweet?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2F70-of-cyber-attacks-will-be-against-small-businesses-in-2020&text=Why%20Small%20Businesses%20Are%20Still%20the%20%231%20Cybercrime%20Target%20in%202026) [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2F70-of-cyber-attacks-will-be-against-small-businesses-in-2020) [Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fchristianespinosa.com%2Fblog%2F70-of-cyber-attacks-will-be-against-small-businesses-in-2020) [Email](mailto:?subject=Why%20Small%20Businesses%20Are%20Still%20the%20%231%20Cybercrime%20Target%20in%202026&body=https%3A%2F%2Fchristianespinosa.com%2Fblog%2F70-of-cyber-attacks-will-be-against-small-businesses-in-2020)Copy link 

![Christian Espinosa, headshot](/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg)

About the author

[Christian Espinosa](/about) · Founder & CEO, Blue Goat Cyber

Christian is the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm. He's an Air Force Academy graduate, 24x Ironman, climber of two of the Seven Summits, and the author of The Smartest Person in the Room and The In-Between: Life in the Micro.

Keep reading

-   [
    
    ### Remote Work Is Here to Stay: The Impact on Cybersecurity - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/remote-work-is-here-to-stay-the-impact-on-cybersecurity)
-   [
    
    ### What a 'Good' SBOM Actually Looks Like, And What Reviewers Reject | Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/what-a-good-sbom-actually-looks-like)
-   [
    
    ### Cyber Risk and Digital Transformation: The Gap Is Growing - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/cyber-risk-and-digital-transformation-the-gap-is-growing)

[← Previous essay 

Medical Device Hacking and the Vulnerability of Connected Medical Devices - Christian Espinosa

](/blog/medical-device-hacking-and-the-vulnerability-of-connected-medical-devices)[Next essay → 

Aviation Cybersecurity – Hacking Aircraft - Christian Espinosa

](/blog/aviation-cybersecurity-hacking-aircraft)

Related, Cybersecurity

### Need medical-device or offensive security expertise?

Blue Goat Cyber, Christian's firm, runs FDA-aligned premarket submissions, penetration testing, and SBOM/SOUP analysis for medtech and high-stakes industries.

[Explore Blue Goat Cyber](/cybersecurity)

Christian Espinosa

Bestselling author, keynote speaker, and Founding CEO of [Blue Goat Cyber](https://bluegoatcyber.com/). Helping technical leaders develop the soft skills that turn brilliance into impact.

[](https://www.linkedin.com/in/christianespinosa/)[](https://x.com/Ironracer)[](https://www.instagram.com/christian.espinosa.official/)[](https://www.youtube.com/@ChristianEspinosaOfficial)[](https://www.facebook.com/christian.espinosa.official)

Explore

-   [About](/about)
-   [Timeline](/timeline)
-   [Speaking](/speaking)
-   [Cybersecurity](/cybersecurity)
-   [Programs](/programs)

Read

-   [Books](/books)
-   [Guides](/guides)
-   [Blog](/blog)
-   [Media](/media)
-   [Podcast Interviews](/podcasts)
-   [Success Stories](/success-stories)

Connect

-   [Contact Christian](/connect)
-   [LinkedIn ↗](https://www.linkedin.com/in/christianespinosa/)
-   [Blue Goat Cyber ↗](https://bluegoatcyber.com/)
-   [Resources](/resources)

© 2026 Christian Espinosa. All rights reserved.

[Privacy](/privacy-policy)[Terms](/terms-of-use)