The Top 5 Cyber Threats to Small Businesses, by the Numbers

Written by

in

,

By J. Mesa

Small businesses face growing risk from cyberattacks and organized digital crime. Hacking tools are easy to obtain, and attackers use them to steal sensitive information, disrupt operations, or extort payment.

Numbers make the risk concrete. This post walks through five common threats, what studies say each one costs, and how to defend against it.

A note on the numbers

The cost figures below come from industry reports published around 2020, and several of them measure organizations larger than a small business. Use them to compare the threats and to see the scale. Your own costs will depend on your size, your data, and how prepared you are.

1. What is ransomware, and what does it cost?

Ransomware encrypts a company’s data and demands payment for the key to unlock it. A victim faces financial loss and damage to its reputation.

Datto’s Global Ransomware Report 2020 found an average ransom of $5,600 among small businesses, and an average downtime cost of $274,200. The downtime cost nearly fifty times the ransom.

How to defend:

  • Keep offline, tested backups
  • Patch systems, and put internet-facing ones first
  • Require multi-factor authentication on remote access
  • Train staff to spot phishing

2. What is phishing, and what does it cost?

Phishing tricks people into giving up login credentials or financial information through fake emails and messages that appear to come from legitimate sources. Attackers use what they collect to enter company systems or steal data.

PhishMe’s 2017 Enterprise Phishing Resiliency and Defense Report put the average cost of a successful phishing attack on a mid-sized company at $1.6 million.

How to defend:

  • Train employees with real examples
  • Turn on multi-factor authentication
  • Use email filtering
  • Confirm payment requests by phone

3. What is malware, and what does it cost?

Malware is software built to damage or disrupt a computer system or to steal from it. The category includes viruses, spyware, trojans, and ransomware.

Accenture’s research in 2020 put the average cost of a malware attack at $2.6 million.

How to defend:

  • Run security software on every device
  • Keep software updated
  • Limit administrator rights
  • Block downloads from untrusted sources

4. What is a denial of service attack, and what does it cost?

A denial of service (DoS) attack floods a website or network with traffic until legitimate users can’t reach it. When the traffic comes from many sources at once, it is a distributed denial of service, or DDoS, attack.

Estimates from 2020 put the cost at $20,000 to $40,000 per hour of outage.

How to defend:

  • Use a hosting or DNS provider that includes DDoS protection
  • Put a content delivery network in front of your website
  • Know who to call at your provider when an attack starts

5. What is an insider threat, and what does it cost?

An insider threat comes from inside the organization. It can be an employee who steals data on purpose, or one who exposes it by accident.

The Ponemon Institute’s Cost of Insider Threats study found an average annual cost of $8.76 million in 2018, rising to $11.45 million in 2020.

How to defend:

  • Give each person access to only what the job requires
  • Remove access on an employee’s last day
  • Log and review access to sensitive data
  • Train staff on safe data handling

Which threat is most common for small businesses?

Phishing. It is cheap to send, it reaches every employee, and it opens the door to most other attacks, including ransomware and payment fraud. If you can fund only one defense, make it phishing training with multi-factor authentication.

Why do attacks cost so much?

The ransom or the stolen money is a small part of the bill. The larger costs come from:

  • Downtime. Sales and work stop.
  • Recovery. Investigators, IT labor, and replacement equipment.
  • Legal and notification costs.
  • Lost customers and damaged reputation.

The Datto figures show the pattern. Being down costs more than the ransom.

What is organized digital crime?

Many attacks come from organized groups that run like businesses. They have developers, support staff, and affiliates. Some sell ransomware as a service: one group builds the tool, and others rent it and share the profits.

That model means an attacker needs little skill to hit a small business. It also means the attacks are well tested.

Who is behind attacks on small businesses?

  • Criminal groups seeking money
  • Individual opportunists using rented tools
  • Insiders, through intent or error
  • Automated scanners that look for weak systems across the whole internet

Most of them are not targeting you by name. They are looking for any business with an open door.

How does a small business protect itself?

Technology:

  • A firewall and security software
  • Multi-factor authentication
  • Automatic updates
  • Tested backups
  • Monitoring for suspicious activity

People:

  • Regular cybersecurity training
  • A simple way to report suspicious messages

Process:

  • Strict rules for who can access company information and systems
  • A written incident response plan
  • A review of access and controls every quarter

How do I estimate my own exposure?

  1. Work out what one day of downtime costs you in lost sales and wages.
  2. Count the customer and employee records you hold.
  3. Ask how long a full restore from backup would take.
  4. Multiply the daily cost by the restore time.

That figure is a floor. It leaves out legal costs and lost customers.

Are these numbers still accurate?

The reports cited here date from 2017 to 2020, and costs have risen since. Newer editions of the same studies show higher figures each year. The ranking and the lesson hold: downtime and recovery cost far more than the attack itself, and prevention costs far less than either.

Should I work with a cybersecurity consultant?

A consulting service gives a small business a direct route to protection. A consultant identifies the threats that apply to your operations, ranks them, and helps you fix the most serious ones first. That saves you from buying tools you don’t need.

Your next step

Small businesses face a rising threat from hackers and organized digital crime. Investing in effective security and educating your employees protects you. Cerberus Cybersecurity offers risk and compliance assessments that show which of these five threats put your business at the most risk. Contact us to schedule one.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *