What the real data says about cyberattacks on small companies
Published:
Small companies are hit disproportionately hard by cyberattacks — but the figures most often quoted on the subject do not survive checking. Below: what the annual Verizon report actually says, and what you can do about it.
Correction note (August 2026): this article previously contained two claims we have retracted. First, "60% of successful attacks target small companies", attributed to the Verizon report — we could not find that figure in it. Second, "60% of small firms that suffer a major attack close within 6 months" — a statistic the organisation usually credited with it, the National Cyber Security Alliance, has publicly disavowed: it did not come from their research, the original source cannot be verified, they removed it from their materials and do not recommend its ongoing usage. We also removed the attack-type breakdown (36/27/18/12%) and the €42,000 average cost, for which we found no source at all.
What the Verizon 2025 report says
Verizon publishes its Data Breach Investigations Report annually. The 2025 edition, released on 23 April 2025, analysed more than 22,000 security incidents, of which 12,195 were confirmed breaches:
- Ransomware appears in 88% of breaches affecting smaller organisations, against 44% across organisations of all sizes
- Credential abuse (22%) and exploitation of vulnerabilities (20%) are the leading ways in
- Third-party involvement in breaches doubled, to 30%
- The median ransom demand was USD 115,000, and 64% of victim organisations did not pay
Source: Verizon, Data Breach Investigations Report 2025. The difference from what we had published matters: it is not that "60% of attacks target small firms", but that small firms are hit by ransomware far more often and have fewer resources to recover.
5 immediate actions (under €500)
- Two-factor authentication (2FA) on all accounts — usually free. Microsoft has published that turning on multifactor authentication makes an account more than 99.9% less likely to be compromised
- 3-2-1 automatic backup — 3 copies, 2 different media, 1 offsite
- Team training — 2 hours/quarter on phishing recognition
- Automatic updates — OS, browser, CRM, all up to date
- Unique passwords + manager — each account with a different, auto-generated password