25+ Small Business Cyber Attack Statistics & Numbers (2024 Update)
Cyberattacks pose a significant threat to small businesses, severely affecting their operations and profits.
But just how bad can these cyber attacks get for small businesses?
With that in mind, we’ll cover eye-opening small business cyber attack statistics to show why strong cybersecurity is a must for every business.
Small Business Cybersecurity Statistics: Key Numbers
- On average, 43% of cyber attacks target small businesses.
- Cybercrime increased by 600% due to COVID-19 pandemic.
- 60% of small businesses shut down within six months of a cyberattack.
- Nearly 40% of small businesses reported data loss due to a cyberattack
- 82% of ransomware attacks are aimed at small businesses.
- 1 in 323 emails received by SMBs is malicious.
- A data breach costs an average of $3.31 million for small businesses with fewer than 500 employees.
- 95% of cybersecurity breaches are attributed to human error.
- The cost of 95% of cybersecurity incidents at SMBs ranges from $826 to $653,587.
- 5% to 20% of overall IT budgets are dedicated to security by small and medium-sized businesses.
- 43% of small to medium-sized businesses lack a recovery plan for a cybersecurity incident.
- 50% of small businesses take 24 hours or more to recover from a cyberattack.
Source:(Verizon, BM’s 2023 Cost of a Data Breach Report, Astra Security, Symantec, University of Maryland Francis King Carey School of Law, UpCity )
02.
Small Business Ransomware Statistics
Ransomware is seriously messing with small businesses, hitting their wallets and disrupting their operations big time. These stats show just how common and costly these attacks are, especially for smaller companies. With the risks growing and recovery getting tougher, it’s crucial to get a grip on what’s happening and how to protect against it:
- 85% of all ransomware targets are small businesses.
- The average cost of a ransomware attack is $26,000.
- Over the last year, US small businesses have paid more than $16,000 in ransoms.
- The number of businesses subjected to ransomware attacks increased by more than 27% in the last year.
- 37% of companies hit by ransomware had under 100 employees.
- 5% of SMBs fell victim to ransomware between 2016 and 2017.
- Manufacturing was the top industry targeted by ransomware attacks.
Sources: (Veeam’s 2023 Data Protection Trends Report, BitDefender, Statista, Linkedin, Thales Group, Small Business & Entrepreneurship Council, Verizon 2023 Data Breach Investigations Report)
03.
Small Business Cyber Attack Resulting Damage Statistics
When small businesses get hit by cyber attacks, the fallout is brutal. From long website outages to losing important data, the damage goes way beyond just losing money. It’s tough to bounce back, and many businesses don’t make it. Check out these eye-opening stats that show how serious these attacks can be:
- The average ransom payment has risen to $2 million, compared to $400,000 in 2023.
- 60% of small businesses hit by a cyber attack shut down within six months..
- 51% of small businesses report that their website is down for 8–24 hours after an attack.
- After a cyber attack, 50% of small businesses take at least 24 hours to recover.
- Nearly 40% of small businesses lose critical data due to a cyber attack.
- 42% of small businesses hit by a cyber attack suffer a financial loss.
- 32% of small businesses lose customer trust after a cyber attack.
Sources: (Linkedin, Astra Security, BM’s 2023 Cost of a Data Breach Report, Bitdefender, State of Ransomware 2024)
04.
Cost of a Cyber Attack on Small Business Statistics
Cyber attacks are hitting small and medium-sized businesses hard. These incidents don’t just mess up operations—they come with hefty price tags. As these threats get more common and complex, the costs keep climbing, making cybersecurity a top priority for SMBs. Here are some key stats showing the financial impact of cyber attacks on small businesses:
- On average, a cybersecurity incident costs SMBs $826 to $653,587.
- Cyber attacks cause an average loss of $25,000 for small and medium-sized businesses (SMBs).
- 500% jump in ransomware payments was recorded in the previous year.
- SMBs pay an average of $52,000 for each DDOS incident.
- Businesses with less than 500 employees typically incur $2.98 million per data breach.
- $165,520 is the average recovery cost for companies earning less than $10 million a year after a ransomware attack.
Sources: (Verizon, Business News Daily, Congress.gov, State of Ransomware 2024, Kaspersky, Tech Heads)
05.
SMB Cybersecurity Preparedness And Response Statistics
For small and medium-sized businesses (SMBs), dealing with cybersecurity threats is a major challenge. The stats below show just how prepared (or unprepared) these businesses are. From how much they spend on security to how long it takes to recover from an attack, it’s clear that many SMBs need to step up their cybersecurity game:
- 14% of small businesses say they are prepared to defend themselves against cybersecurity threats.
- SMBs spend between 5% and 20% of their total IT budget on security.
- An average business recovery time after an attack is 279 days.
- Following a cyber attack, 29% of businesses immediately hire professional cybersecurity help or increase their in-house IT staff.
- 83% of SMBs aren’t prepared to handle the financial fallout of a cyber attack.
- 54% of businesses admit their IT departments lack the experience to deal with complex cyberattacks.
Sources: (Insurance Journal, SBA, Tealtech, Astra Security, NinjaOne, Cyber Security Awareness)
06.
Business Email Compromise Statistics
Business Email Compromise (BEC) is a huge problem that’s hitting companies hard and costing them a lot of money. Hackers are getting really smart, using trusted emails to trick employees into transferring cash or sharing sensitive info. Check out these stats to see just how bad it’s getting and why we need to step up our security game:
- There are 15,208 business email compromises per year on average (data from 2013 to 2021).
- Business email compromises cost an estimated $8.6 billion per year.
- Business email compromise fraud costs $43 billion between 2016 and 2021.1
- Between July 2019 and December 2021, the number of business email compromise (BEC) attacks increased by 65%.
- 77% of organizations experienced business email compromise attacks, an 18% increase from 2020.
- Cybercriminals are also using company names (68%), names of individual targets (66%), and boss/managers’ names (53%) in their spear phishing emails.
- According to the Federal Bureau of Investigation’s 2021 Internet Crime Report (IC3), they received 19,954 reports of business email compromise (BEC).
How Much Do Cyber Attacks Cost Businesses
Cyberattacks cost businesses an average of $200,000 per incident, according to a recent study from Hiscox and a report from CNBC that we gather data from.
Cyber attacks are costly because they often lead to data breaches, which can damage a company’s reputation and result in financial losses. In addition, cyber attacks can cause business interruption, leading to lost revenue and additional expenses.
As a result, businesses need to be prepared to respond to cyber-attacks quickly and effectively. They also need to invest in cybersecurity measures to help prevent attacks from happening in the first place.
We hope you enjoy the small business marketing cyber attack statistics resource page and from that we learn that cyberattacks significantly threaten small businesses, affecting their operations, finances, and customer trust. Strengthening cybersecurity is crucial for small businesses. To learn more about small businesses, then go to our comprehensive small business insight page to learn more.