There's a statistic that circulates constantly in cybersecurity writing claiming that 60% of small businesses close within six months of a cyberattack. It's widely repeated, intuitively plausible, and — as the National Cyber Security Alliance confirmed in a 2022 public statement — unverifiable. They disavowed it. The original source doesn't exist.
We're not going to use it. The verified numbers are more alarming anyway.
75%
of small businesses say they could not continue operating if hit with ransomware
This isn't a historical figure about businesses that were attacked and failed. It's a forward-looking statement from business owners about their own survivability. Three in four SMB owners, when asked directly, say ransomware would end their business. That number is based on current conditions — their current cash reserves, their current recovery capabilities, their current absence of backups or incident response plans.
The distinction matters. "60% close within 6 months" describes a past event with an unknown methodology. "75% say they couldn't survive" describes a present reality — the self-assessed survivability of businesses operating right now, including businesses that have never been attacked and believe they won't be. The 75% figure is what makes the math in this post worth running.
$254K
average total cost of a cyberattack on an SMB in 2026 — across all incident types including downtime, recovery, and notification
Total Assure Research 2026
49%
of small businesses experienced a cyberattack in 2026 — nearly one in two. Attack frequency globally: roughly every 7 seconds.
Total Assure / VikingCloud 2026
47%
of businesses with fewer than 50 employees have zero cybersecurity budget — the most targeted businesses are the least protected
StrongDM 2025
The math your business needs to see
The financial impact of a cyberattack on a small business isn't a single number. It's a cascade — each layer compounding the one before it. Here's what the verified research documents as the actual cost components of a typical SMB ransomware incident:
The real cost breakdown — typical SMB ransomware incident (2026 averages)
Immediate downtime lossesRevenue lost during system outage. Average SMB downtime after ransomware: 21 days. Lost sales, missed orders, idle staff.
$28,000–$85,000
Professional incident responseForensic investigation, containment, system restoration. External IR firms typically charge $200–$500/hr. Minimum engagement: 3–5 days.
$15,000–$50,000
Data recovery and system rebuildRestoring encrypted files, rebuilding compromised systems, replacing hardware. Higher if backups don't exist or haven't been tested.
$10,000–$40,000
Legal, regulatory, and notification costsAttorney fees, breach notification to affected individuals, state AG filings. Required by law in 47 states if personal data is involved.
$8,000–$30,000
Ransom payment (if paid)31% of victims paid in 2025, down from 50% two years earlier. Median payment: below $140,000. Payment does not guarantee data recovery.
$0–$140,000
Reputational damage and customer churnLost clients, cancelled contracts, damaged relationships. Hardest to quantify but often exceeds the direct financial cost. Not covered by cyber insurance.
Variable
Total documented rangeExcludes ransom and reputational damage. VikingCloud 2025 average: $120,000 minimum. Total Assure 2026 average across all incident types: $254,000.
$61K–$345K+
The ransom payment is not the cost. In documented incidents, the ransom — if paid — is typically the smallest line item. The downtime, the IR engagement, the legal requirements, and the recovery work collectively cost more than the ransom in the majority of cases. A business that pays $50,000 in ransom and gets its files back still faces $60,000–$200,000 in additional recovery costs. "Just pay the ransom" is not a business continuity plan.
The prevention math — why 47% of small businesses having zero cybersecurity budget makes no sense
A small business implementing the five controls from our previous post — help desk verification policy, number matching MFA, credential monitoring, vendor access audit, and external attack surface monitoring — can be done for as little as $0 in the first year using free tools and policy changes. Even a comprehensive SMB security package including a business password manager, credential monitoring, and endpoint protection runs $5,000–$15,000 annually.
Cost of recovery
$120,000+
VikingCloud 2025 minimum average for a ransomware incident — before ransom, before legal fees, before reputational damage. Can exceed $1.24 million for complex incidents.
Cost of prevention
$5,000–$15,000
Annual cost of a comprehensive SMB security program covering credential monitoring, endpoint protection, password management, and training. 50–60x cheaper than recovery.
Prevention is documented to cost 50 to 60 times less than recovery. And yet 47% of businesses with fewer than 50 employees have zero cybersecurity budget. The reason isn't cost — it's belief. 59% of SMB owners with no security believe they are too small to be attacked. This is the most expensive misconception in small business finance — because attackers specifically target SMBs precisely because this belief is so widespread.
The five numbers that change how every SMB owner thinks about this
1️⃣49% — the probability your business is attacked this year
Nearly 1 in 2
Total Assure's 2026 research across 2,800 North American small businesses found a 49% annual cyberattack rate. In any given year, nearly half of all small businesses experience at least one cyberattack requiring response. The instinct that says "I probably won't be targeted" is statistically wrong for almost half of the businesses that share it.
2️⃣$254,000 — the average loss per incident in 2026
Most can't absorb it
$254,000 is the average. For the average small business with fewer than 20 employees, that represents months of revenue — not a line item that can be absorbed without fundamentally disrupting operations. The 40% of SMBs who say a $100,000 attack would end their business are being precise: the average attack is two and a half times that threshold.
3️⃣34% — the proportion of SMBs with a formal incident response plan
Only 1 in 3
Only 34% of small businesses have a formal incident response plan — meaning 66% would face a $254,000 average incident with no documented playbook. IBM data shows a tested incident response plan reduces breach cost by $232,007. That single document — which a small business can create in an afternoon — saves more than most businesses spend on security in five years.
4️⃣75% faster recovery — the documented impact of a tested IR plan
Most underused tool
Businesses with tested incident response plans recover 75% faster and spend 60% less on breach remediation than those without. The 21-day average downtime drops to roughly 5 days with a tested plan. The difference in downtime cost alone — 16 additional days of lost revenue — typically exceeds the cost of creating the plan in the first place.
5️⃣19% face bankruptcy — the verified post-attack business failure rate
Still 1 in 5
The Verizon DBIR 2025 puts post-attack bankruptcy risk at 19% for SMBs. One in five small businesses that experiences a significant cyberattack faces bankruptcy proceedings. Combine that with the 75% survivability concern and 40% saying a $100K attack would end their business, and the picture is consistent: a significant cyberattack is an existential event for a meaningful proportion of small businesses.
The insurance instinct deserves scrutiny here. 73% of SMBs fail cyber insurance assessments, and those that do have coverage face sublimits, exclusions, and compliance requirements that can void coverage for the exact scenarios most likely to trigger a claim. The average cyber insurance payout covers a fraction of the documented $254,000 average loss. Insurance is a recovery tool, not a prevention strategy — and it works only if the claim is approved, which requires meeting security requirements that overlap directly with the five controls in our previous post.
The one calculation every SMB owner should run right now
Here's the calculation. Take your monthly revenue. Multiply by 1.5 — that's the average downtime plus recovery period for an SMB ransomware incident (roughly 6 weeks of disrupted operations). Add $50,000 for professional incident response and legal costs at the low end. Add whatever your ransom might be if you have no backups. That total is your realistic exposure.
Now compare it to $5,000–$15,000 per year for prevention — or $0 for the five free controls in our previous post.
The 75% of SMB owners who say they couldn't survive ransomware have, consciously or not, already run this calculation. They know their cash reserves. They know their margins. They know that 21 days of downtime plus $100,000 in recovery costs would not leave the business standing. What most of them haven't done is use that knowledge to justify the afternoon it takes to implement the controls that would prevent it.
The Veriti Spottr CyberScore gives SMB owners an objective assessment of where their business sits against the documented attack vectors, what's exposed, and which controls would have the highest impact on their actual risk. The 75% survivability concern is real. The math behind it is verified. The controls that change the math cost less than one day of the downtime they prevent. The CyberScore tells you exactly where to start.
Comments
Post a Comment