Cyber Security for Small Business: Costs and Priorities
A small business does not need a security program. It needs a short list of things done properly, in a particular order, with a clear view of what each one costs before the money is committed.

A restaurant group with 40 staff, a two-partner law firm, a machine shop whose website takes deposits. None has a security team, none wants a security program, and all three arrive at the same question: what has to be done, in what order, and what does it cost. A business with 12 people and a fixed budget cannot act on a list of good ideas. It needs to know which item comes first and what the first year adds up to.
This page answers both. The controls come from the guidance the FTC, CISA and NIST publish for exactly this reader. The threat data comes from the section of Verizon's 2026 breach report that covers small and medium-sized businesses on their own. The prices come from published price lists, and where a number is a vendor's list rather than a market average, the sentence carrying it says so.
What Is Cyber Security for Small Business?
Cyber security for a small business is the work of protecting the accounts, devices, money and customer data of a company that has nobody whose job it is to protect them. The threats are not smaller than the ones a bank faces. The staffing is. That difference is why the right answer is almost always a short list of controls that keep working without supervision, rather than a scaled-down copy of the enterprise version.
CISA puts the mismatch plainly on its page for small and medium businesses: small businesses hold information criminals want, and often have fewer resources committed to protecting it. Closing that gap is a budgeting exercise more than a technical one.
The map most guidance borrows is the NIST Cybersecurity Framework, whose six functions are govern, identify, protect, detect, respond and recover. The FTC recommends it to small businesses in its own cyber security guidance, and it is worth knowing because insurers, larger customers and auditors all speak in those terms. It is a map, not the work. A ten-person company that has completed govern and identify but never turned on multi-factor authentication has done nothing at all. It is also not a firewall purchase, because most of what goes wrong never crosses your network, and not a compliance certificate, because passing an audit and being hard to attack are different achievements.
Do Small Businesses Need Cyber Security?
Yes, and the evidence is more specific than the usual warnings. Verizon's 2026 Data Breach Investigations Report gives small and medium-sized businesses their own section rather than burying them in an average, and the numbers there describe a category being worked through steadily rather than occasionally.
Those are counts of cases inside one report's dataset, not a share of all small businesses, and no honest page can tell you the odds that your company is hit this year. What the data does settle is the shape of the harm. In Verizon's 2026 Breach Impact Study, summarized for smaller companies, the worst 2.5 percent of cases produced a financial loss worth more than 7 percent of the affected business's revenue. For a company turning over $4 million, that is more than $280,000 in a year when the plan was to grow.
The second reason arrives through the front door. Larger customers, insurers and public-sector buyers now put security questions in their contracts, and a small supplier that cannot answer them loses work. Plenty of businesses reach this page because a customer sent a questionnaire, not because anything went wrong.
Why Small Businesses Are a Target
Almost nobody chooses your company. Criminal operations scan the whole internet for a product version with a known flaw, or buy a list of stolen passwords and try them everywhere. Your business appears in the results, and it is a target because it answered, not because it was selected. That is why "we are too small to be interesting" is both true and irrelevant.
Two things do make a smaller company more likely to be hurt once found. Time, because an unpatched service or a reused password stays that way for longer when nobody owns the job. And recovery, because a company without tested backups has to negotiate rather than restore.
The Biggest Cyber Security Threats to Small Businesses
The threat list is short and has barely changed in five years. The ranking has. In the small and medium-sized business section of the 2026 DBIR, the initial access breakdown puts exploitation of vulnerabilities at 26 percent, credential abuse at 13 percent and phishing at 9 percent. Unpatched software is now the most common way in, ahead of anything a person clicks, which reverses the order most owners expect.
- A service is foundAutomated scanning finds an out-of-date remote access tool, firewall or web application
- It is exploited or a password is reusedA published flaw, or a credential bought from an earlier breach elsewhere
- Access is sold or usedEmail is read, invoices are studied, file shares are opened
- Money or data leavesA changed bank account on an invoice, or files copied out before encryption
- The business noticesUsually when a customer calls or a ransom note appears, not when it starts
- Patched software and MFA end it at step twoThe two controls that break the chain before it reaches anything valuable
Ransomware closes companies rather than embarrassing them, because it takes the systems and the backups in the same move. Verizon's small-business section says plainly that small organizations are disproportionally impacted by it.
Business email compromise is the quiet one. Nothing is encrypted and no alarm sounds. Somebody reads the mailbox for a few weeks, learns which supplier gets paid on which day, and sends a real-looking invoice with new bank details. The loss is a single wire transfer, and whether it comes back turns almost entirely on speed: the FBI's Recovery Asset Team froze 58 percent of the $1.16 billion it was asked to freeze in 2025, and the money it cannot reach is the money reported late.
Phishing and fake login pages remain the way most passwords are lost. Training everyone to spot a phishing email is cheap and it works, as long as it is practice rather than a once-a-year video.
A breach at somebody else is the category most small businesses underrate, and the DBIR puts a third party in 55 percent of small-business breaches. Your accounting platform, booking system or phone provider has an incident, and it becomes your notification obligation.
How to Protect a Small Business From Cyber Attacks
The controls below are in spending order, which is the part that decides whether a fixed budget lands well. Each closes more risk per dollar than the one after it, and a company that stops after the first four is in better shape than one that bought a security appliance and left multi-factor authentication for later.

How Much Does Cyber Security Cost for a Small Business?
Nobody publishes a market average for this, so what follows is built from prices you can open and check yourself, with the source named next to each figure. Treat it as a floor and a ceiling for tooling rather than a quote.
The free tier is genuinely useful and most companies never open it. CISA's Cyber Essentials is written for leaders of small businesses and organizes the work into six elements, with a starter kit and toolkits behind it. CISA's Cyber Hygiene Services, which cover vulnerability scanning and web application scanning, are available at no cost to eligible organizations. NIST runs a Small Business Cybersecurity Corner with quick start guides and topic guidance, all freely available. The FTC's small-business material is free, and the SBA's guidance points to the FCC's Small Biz Cyber Planner 2.0, which helps build a custom cybersecurity plan. A company that works through those has done a consultant's opening engagement for nothing.
Endpoint and email security, per seat, from two published price lists. Microsoft publishes its small and medium business security prices directly: Microsoft Defender for Business at $3.00 per user per month billed annually, and Microsoft 365 Business Premium, which bundles the productivity apps with the security tooling, at $22.00 per user per month billed annually. CrowdStrike publishes Falcon Go at $7.99 per device per month or $59.99 per device billed annually, capped at 100 devices, with Falcon Pro at $99.99 and Falcon Enterprise at $184.99 per device per year. Both of those are list prices from the vendors' own pages, not negotiated rates, and both are the kind of number a reseller discounts.
Run those against a real company and the arithmetic stops being abstract. Endpoint protection for a company of 25 costs $900 a year at Microsoft's per-user Defender for Business price, $1,499.75 at CrowdStrike's per-device Falcon Go price, or $2,499.75 at Falcon Pro. A bundled productivity and security suite for the same 25 people is $6,600 a year at Microsoft's published Business Premium price, and $2,640 for 10 people. Password management and backup vary too widely by product for a published range to mean much.
Services are the line that moves. Outsourced monitoring is priced per endpoint or per user per month, published pricing is rare, and quotes vary more than buyers expect because the variables are unequal: how many systems the provider is fed, how long logs are kept, and what the provider is allowed to do at three in the morning without calling you. The comparison that decides it is not the subscription against zero but the subscription against hiring, and with the Bureau of Labor Statistics median wage for an information security analyst at $129,180 as of May 2025, a rota that genuinely covers nights and weekends is a six-figure line before anyone has been recruited.
Cyber insurance is priced on your revenue, sector and controls, not on a rate card. The FTC's cyber insurance guidance is the clearest free explanation of what you are buying: first-party coverage pays your own losses, meaning legal advice on notification obligations, data recovery, customer notification and call center costs, lost income and forensic investigation, while third-party coverage pays claims made against you. It also gives the two questions worth asking, which are whether the insurer will defend you in a lawsuit or regulatory investigation, and whether there is a breach hotline answering every day at all hours. Insurers price on whether you have multi-factor authentication and tested backups, so the controls above lower the premium as well as the risk.
The loss side is where the famous number misleads. IBM's Cost of a Data Breach Report 2026 puts the global average at USD 4.99 million, up 12 percent on the year, and that figure gets quoted at small businesses constantly. It does not describe them. IBM states its own method: it excludes very small and very large breaches, and the breaches it studied ranged from 2,590 to 115,380 compromised records. The figures that do describe smaller companies come from Verizon's Breach Impact Study, built on roughly 70,000 cyber insurance claims: insurable losses on claims made between 2019 and 2024 rose from roughly $60,000 to around $100,000, and in the worst 2.5 percent of small-business cases the loss exceeded 7 percent of revenue.

What Are the 5 C's of Cyber Security?
The answer circulating for this question is change, compliance, cost, continuity and coverage. It is worth knowing because interviewers and consultants use it, and worth being honest about: it comes from consulting material rather than any standards body. NIST does not publish it, CISA does not publish it, and no auditor will accept it as a framework.
The published version of the same idea is CISA's Cyber Essentials, which organizes small-business security into six elements rather than five C's: yourself, meaning the leader who has to fund it; your staff; your systems; your surroundings, meaning who can reach the digital workplace; your data; and your crisis response. Those six make a better checklist because each has a toolkit behind it, and because the first is an honest admission that in a small company the owner decides this or nobody does.
When to Hire a Cyber Security Firm
Three triggers, all of them about capacity rather than sophistication. A customer or insurer asks a question you cannot answer in writing, which is a documentation and assessment job. Or you hold data that would end the business if it leaked and nobody is watching the systems overnight. Or an incident is already in progress, at which point you are buying incident response and the priority is speed rather than fit.
What separates two firms at the same price is narrower than the brochures suggest. Ask which systems are covered at the quoted number and what identity, cloud and email coverage costs on top. Ask exactly what the firm will do without calling you first, because a service needing approval for every action is a notification service priced as a response service. Ask for attestations that can be checked, such as SOC 2 or ISO 27001, rather than logos. And note how fast they answered your first email, because that is the only sample of their response time you get before signing.
The service most small companies end up buying is managed detection and response, a rented team that watches your endpoints, identities and cloud accounts around the clock and is permitted to contain what it finds. It is the right purchase once identity, devices and backups are handled, and the wrong one before then.
Small Business Cyber Security Checklist
Everything above, in the order to do it. The first six items cost nothing but time.
Key takeaways
- Small-business security is a short list of controls that keep working unattended, not a scaled-down enterprise program.
- Unpatched internet-facing software is now the most common way in for small companies, at 26 percent, ahead of credential abuse at 13 percent and phishing at 9 percent.
- A third party was involved in 55 percent of small-business breaches, so vendor incidents are your incidents.
- Multi-factor authentication, a password manager, automatic updates and a tested backup close most of the risk and cost almost nothing.
- Published list prices put endpoint protection for a company of 25 between $900 and $2,500 a year, and a bundled security and productivity suite at $6,600.
- The USD 4.99 million average breach cost is not a small-business number, by the report's own stated method.
- Hire a firm once identity, devices and backups are handled, not before.
Common questions
Do small businesses need cyber security?
Yes. Verizon's 2026 breach report gives small and medium-sized businesses their own category and logged 7,256 incidents in it, 7,152 with confirmed data disclosure, in one year of data. But no report can hand you your own odds, so the practical case is the stronger one: multi-factor authentication, updates and tested backups cost almost nothing and remove most of the risk whatever those odds turn out to be.
How much does cyber security cost for a small business?
The federal guidance is free. Tooling runs per seat: Microsoft publishes Defender for Business at $3.00 per user per month billed annually and Microsoft 365 Business Premium at $22.00, and CrowdStrike publishes Falcon Go at $59.99 per device per year. That puts endpoint protection for a company of 25 between $900 and $2,500 a year at list prices. Monitoring and insurance are quoted individually and are the lines that move.
What are the 5 C's of cyber security?
Change, compliance, cost, continuity and coverage. It is a consulting mnemonic rather than a published standard, and no auditor treats it as a framework. CISA's Cyber Essentials is the published equivalent for the same reader, organized into six elements: yourself, your staff, your systems, your surroundings, your data and your crisis response.
What is the first thing a small business should do about cyber security?
Turn on multi-factor authentication for the company email accounts. Email is the password reset route to everything else, so protecting it protects the rest by default. It takes an afternoon, costs nothing on most business plans, and no purchase on any vendor page beats it.
Is cyber security still worth it in 2026?
The question usually means whether the spending is proportionate. The first tier obviously is: multi-factor authentication, patching and backups pay for themselves against a single incident. Monitoring, compliance evidence and a fractional security officer earn their price once there is enough at stake, and are premature before that.
Does a small business need cyber insurance?
Most do, and larger customers increasingly require it. The premium is set on revenue, sector and the controls you can evidence rather than a rate card, so working through the checklist above lowers what you pay as well as what you risk. Before signing, settle the two questions the FTC's guidance puts first: whether the insurer will defend you, and who answers the phone at three in the morning.
Can a small business handle cyber security without an IT team?
The first six controls, yes. Multi-factor authentication, a password manager, automatic updates, tested backups, wireless security and a payment rule are owner-level decisions that need no specialist. What cannot be done without help is watching systems overnight and responding to an incident in progress.
What free cyber security resources are there for small businesses?
Four federal ones, all free to use. CISA's Cyber Essentials, with its starter kit and toolkits. NIST's Small Business Cybersecurity Corner. The FTC's small-business guidance and its Data Breach Response guide. And the SBA's page, which routes you on to the FCC's Small Biz Cyber Planner 2.0 and to CISA's no-cost vulnerability scanning.
How do I train employees on cyber security?
Short and repeated beats long and annual. Twenty minutes twice a year on recognizing fake messages, plus a standing rule that no payment detail changes without a phone call, covers most of what training can achieve. Simulated phishing helps when it is practice rather than a test people are trying to pass, and the owner sits through the same session as everyone else.
When should a small business hire a cyber security firm?
At one of three moments: a customer or insurer asks a security question you cannot answer in writing, you hold data whose loss would end the business and nobody is watching the systems overnight, or something is already happening. Before those, the money goes further on the controls in the checklist above.
On this page
- What Is Cyber Security for Small Business?
- Do Small Businesses Need Cyber Security?
- Why Small Businesses Are a Target
- The Biggest Cyber Security Threats to Small Businesses
- How to Protect a Small Business From Cyber Attacks
- How Much Does Cyber Security Cost for a Small Business?
- What Are the 5 C's of Cyber Security?
- When to Hire a Cyber Security Firm
- Small Business Cyber Security Checklist

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.