Business Tips Plus
Business Tips

Cybersecurity for Small Business: What Actually Protects You

A
Asim·Published August 18, 2026
Cybersecurity for Small Business: What Actually Protects You

Quick Answer

Four things cover most of your risk: multi-factor authentication on every account, a tested backup, a password manager, and a quick phishing talk with your team. Verizon's 2025 DBIR found ransomware-style extortion in 88% of small-business breaches, and Microsoft says MFA alone can block over 99% of automated account-takeover attempts. Start with MFA on your email.

TL;DR

  • Small businesses see roughly four times the breach volume of large companies (Verizon 2025 DBIR)
  • MFA can block over 99% of automated account-takeover attempts, and it costs nothing (Microsoft)
  • Business email compromise cost US businesses $3.05 billion in 2025, the #2 cybercrime by losses (FBI IC3)
  • A five-person shop can cover the basics for a few hundred dollars a year, not thousands
  • US cyber insurance uptake jumped from 53% to 71% of small businesses in two years, and most insurers now require MFA before they'll write a policy (Hiscox 2025)
On this page +

Most small business owners assume they are too small to be worth a hacker’s time. That assumption is the single biggest reason small businesses get hit as often as they do. Almost none of it is personal, and almost none of it requires a sophisticated attacker. This guide covers the handful of things that actually move the needle, what a breach really costs at small-business scale, and the one habit that would have saved our own Instagram account.

How often do small businesses actually get attacked?

Small and mid-sized businesses saw roughly four times the breach volume of large organizations in Verizon’s 2025 Data Breach Investigations Report. Ransomware-style extortion showed up in 88% of small-business breaches, against 39% at large companies. Small businesses also catch malicious email at the highest rate of any size group, roughly 1 in every 323 messages.

Here is the part owners miss: almost none of this is personal. Most attacks are automated. A bot scans the internet for a weak spot, a reused password, an open port, software three updates behind, and it does not check your headcount first. It lands on a Fortune 500 company and a five-person landscaping crew the same way. The businesses that get burned worst are usually the ones that figured they were too small to bother with.

What does a cyberattack actually cost?

Depends who you ask, and the spread is huge. IBM’s 2023 Cost of a Data Breach Report found $3.31 million on average for organizations with fewer than 500 employees, but that figure is pulled way up by mid-sized firms with far more to lose. Hiscox, which surveys businesses specifically under 50 employees, found a much smaller median direct cost in its own 2023 report: $8,300.

So which is it? Honestly, both, because a five-person shop and a 400-person company are both “small” and their exposure is nothing alike. If you are closer to five people, use the smaller number. The million-dollar averages are describing somebody else’s business.

What’s the single most effective thing you can do?

Turn on multi-factor authentication. It is the highest-value move on this whole page, and it is free almost everywhere you already log in: email, bank, social, cloud storage. Microsoft’s own research says MFA can block more than 99% of automated account-takeover attempts. And yet a 2024 global survey from the Cyber Readiness Institute found nearly two-thirds of small and medium businesses still don’t use MFA at all.

I know the cost of skipping it, because we skipped it. Our Craftan Instagram got hacked, and since we had never turned on 2FA, we could not prove the account was ours once it was gone. Instagram sends the recovery code to the email or phone tied to the account. The attacker had already swapped both. We emailed support back and forth for weeks and got nowhere. In the end we started the account over from zero, no followers, no post history, no reviews, all of it gone. Every account I touch now, work or personal, has MFA on and set to the strongest option the platform gives me. It took about ten minutes each. It would have saved us a month.

How much should a small business budget for cybersecurity?

This is the number with the widest spread in the whole guide, because “cybersecurity” can mean a $20-a-month password manager or a full managed contract with a monitoring team. At the low end, 2025 MSP pricing puts the bare basics, antivirus, firewall, MFA, at $1,000 to $3,000 a year. A managed setup with monitoring and training for a 25 to 50 person team runs more like $12,000 to $30,000. One 2025 industry estimate pushes comprehensive coverage for a sub-50-employee business all the way to $50,000 to $150,000, though that is aimed at firms in regulated fields like healthcare or finance.

Ignore most of that if you are small. Those figures assume employees, servers, and compliance rules you probably do not have. For a five-person shop, MFA plus a password manager plus a tested backup runs a few hundred dollars a year, and it covers the bulk of your real risk. Spend up from there only when you actually have something specific to protect.

What is business email compromise, and why does it matter?

Business email compromise (BEC) is a scam where someone pretends to be a vendor, your boss, or your bank and talks a person into sending money or handing over data. There is usually no hacking involved at all. It is a convincing email and a fake deadline.

The money is real. The FBI’s Internet Crime Complaint Center logged $3.05 billion in BEC losses in 2025 across just under 25,000 complaints, second only to investment fraud among all cybercrime categories. About 86% of that moved by wire or ACH, which means it is usually gone within hours, well before anyone spots it. The defense is a habit, not a tool: if an email asks you to change payment details or send money, call and confirm first, using a number you already have, never the one in the email. Do not wire money off an email alone, however clean it looks. That one rule stops most of these cold.

Do I need cyber insurance?

Adoption is climbing fast. Hiscox’s 2025 Cyber Readiness Report found 71% of US small businesses now carry a standalone cyber insurance policy or cyber coverage bundled into another policy, up from 53% just two years earlier. That still leaves a real gap, and the businesses without coverage are often the ones who assumed a general liability or business owner’s policy already handled a breach. It usually doesn’t.

Insurers have also tightened up on what they will cover. Most now want MFA and tested backups in place before they will write a policy at all, and some will deny a ransomware claim outright if you cannot show basic protections were running when the attack hit.

The deciding question is what data you hold. If you keep customer card numbers, health records, or anything that legally forces you to notify people when it leaks, get a quote even if you end up passing on it. If you do not touch that kind of data, the basics in this guide already cover most of what would actually go wrong.

What’s a realistic starter checklist?

You do not have to do all of this at once. Work down the list in order, because it runs from “stops the most common attacks” to “nice once the rest is done”:

  • Turn on MFA everywhere it is offered, starting with email, then banking, then any social account tied to the business
  • Use a password manager instead of reusing passwords or keeping them in your head
  • Back up your data automatically to two places, with at least one copy stored off your main system (a cloud backup counts)
  • Sit your team down for 15 minutes once a quarter and show them what a phishing email looks like; almost every breach traces back to a person, not clever code
  • Keep software and devices updated, and switch on automatic updates wherever you can
  • Track who has access to what, and pull that access the day someone leaves
  • Write down now who you call first if it goes wrong: your IT contact, your bank’s fraud line, your insurer

Most of this costs nothing but an afternoon.

FAQ

Frequently Asked Questions

Is free antivirus enough for a small business?+
No, though it is worth having. Free antivirus catches known malware, but it will not stop a phishing email, it will not stop business email compromise, and it will not stop an employee reusing one password across ten accounts, which is how most small-business breaches actually start. Treat it as one layer. MFA and a password manager close far more of the real risk, and both are free or close to it.
What's the difference between 2FA and MFA?+
Two-factor authentication (2FA) means proving who you are with exactly two things: your password plus one more, usually a code from a text or an app. Multi-factor authentication (MFA) is the wider term and can use more than two, including a fingerprint or face scan. Most small business tools use the words interchangeably. Either one beats a password on its own by a mile.
Can I recover a hacked business social media account without 2FA?+
Sometimes, but it is slow and far from guaranteed. Instagram and Facebook send recovery codes to the email or phone on the account, so if an attacker already changed those, you are stuck submitting ID and waiting in a support queue. In 2023, a US senator and a state attorney general publicly pressed Meta after small businesses reported waiting weeks to months to get hacked accounts back, and a 40-state coalition of attorneys general raised the same complaint again in 2024. Turning on 2FA before you need it is the only reliable fix.
How do I know if my business has already been breached?+
Watch for logins from places you have never been, password reset emails you did not ask for, customers mentioning messages you never sent, and account or payment settings that changed on their own. See any of those, and change your passwords right away from a device you trust, turn on MFA if it is off, and check your bank and payment processor for charges you do not recognize.
Should I hire an IT or security company, or handle this myself?+
For the basics here, MFA, backups, a password manager, a quick training talk, most owners can set all of it up themselves in an afternoon. Bring in a managed IT provider or a part-time security consultant once you are handling regulated data, running more than a handful of people, or cleaning up after an incident you already had.
What's the fastest way to start if I haven't done anything yet?+
Put MFA on your email first. Your email is the master key to nearly everything else, your bank, your social accounts, every 'reset my password' link, so it is the single best place to spend ten minutes. Do banking and business social accounts next. The rest of this list can wait a week. Your email cannot.

Sources

A

Asim

Founder, Business Tips Plus · Co-founder, Devsort

Asim is a technology entrepreneur and co-founder of Devsort, an AI/ML services company. He writes about starting and running small businesses because he's done it: the tools, mistakes, and decisions that actually move the needle.

Connect on LinkedIn →