main logo icon

Published on

October 1, 2026

|

30 min read

Small Business Cybersecurity Statistics 2026: Attacks, Costs and Readiness (US and Canada)

Small business cybersecurity statistics for 2026 from primary sources in the US and Canada: Verizon, Statistics Canada, FBI IC3, Coalition, Hiscox, CFIB, the SBA and the Canadian Centre for Cyber Security, with every sample and data window stated.

Arafat Afzalzada

Arafat Afzalzada

Founder

Network SecuritySocial Engineering

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Ransomware appeared in 83% of small and medium-sized business breaches in the Verizon 2026 Data Breach Investigations Report, against 48% of all breaches. The Verizon 2026 Breach Impact Study puts the median loss on a US small business insurance claim at about US$38,000, but the worst 2.5% of those claims cost more than 7% of revenue, a ratio that did not go over 2% in the top 2.5% of mid-market and large-company claims. In the US, 56% of 1,000 small businesses surveyed by Hiscox suffered at least one cyber attack in the past 12 months; in Canada, Statistics Canada found 14.3% of firms with 10 to 49 employees impacted by a cyber security incident in 2023. Business email compromise and funds transfer fraud made up 58% of Coalition's 2025 claims across policyholders of every size, and the FBI logged US$3.05 billion in BEC losses in 2025. The readiness gap is measurable: in 2023, 5.7% of small Canadian firms ran recurring mandatory security training, against 52.3% of large firms. Every figure carries its primary source, sample and data window.

Ransomware appeared in 83% of breaches at small and medium-sized businesses in the Verizon 2026 Data Breach Investigations Report, against 48% of breaches across all organizations, and Verizon counts any organization with fewer than 1,000 employees as small. The same research team's 2026 Breach Impact Study, built on US cyber insurance claims, puts the median loss on a small business claim at about US$38,000, yet in the worst 2.5% of those claims the loss ran to "over 7%" of the insured company's revenue, a ratio that "did not go over 2% in the top 2.5% extreme cases" for mid-market and large-enterprise claims. In Canada, Statistics Canada found that 14.3% of businesses with 10 to 49 employees were impacted by a cyber security incident in 2023. The pattern in both countries is the same: opportunistic attacks, measured against much smaller balance sheets.

Four forces shape small business cyber risk in 2026. Ransomware and extortion: Coalition's 2026 Cyber Claims Report recorded initial ransom demands up 47% to an average of more than US$1 million across its policyholders of every size, even as a record 86% of businesses hit by ransomware refused to pay. Email and payment fraud: business email compromise (BEC) and funds transfer fraud made up 58% of Coalition's 2025 claims across policyholders of every size, and the FBI's 2025 Internet Crime Report logged US$3.05 billion in BEC losses. Exploited vulnerabilities and stolen credentials: exploitation of vulnerabilities was the initial access vector in 26% of small and medium-sized business breaches in the Verizon 2026 Data Breach Investigations Report, ahead of credential abuse (13%) and phishing (9%). A measurable readiness gap: only 5.7% of Canadian firms with 10 to 49 employees ran recurring mandatory security training in 2023, against 52.3% of large firms. This reference is written for owners, office managers and IT leads at firms with 10 to 250 staff, and for the managed service providers, brokers and journalists who advise them.

This post is the Stingrai research team's canonical 2026 reference for small business cybersecurity statistics in the United States and Canada. It assembles more than 150 figures from 11 primary publishers: Verizon (the Data Breach Investigations Report and the Breach Impact Study), Statistics Canada, the Canadian Federation of Independent Business (CFIB), the FBI's Internet Crime Complaint Center (IC3), Coalition, Hiscox, IBM, the Identity Theft Resource Center (ITRC), the US Small Business Administration's Office of Advocacy, the Communications Security Establishment and its Canadian Centre for Cyber Security, and the Canadian Anti-Fraud Centre. Lead data is 2025 claims, complaints and breach telemetry (calendar 2025 for the FBI and Coalition, November 2024 to October 2025 for Verizon's breach dataset), the freshest available; primary publishers have not released full-year 2026 reports as of October 2026, and Statistics Canada's newest published survey cycle covers 2023. Every stat carries its source, year, sample and methodology window so any claim can be audited inline.

Key small business cybersecurity statistics at a glance (2026)

Key takeaways

  • A small business loses less per claim, but in the worst cases far more per dollar of revenue. The Verizon 2026 Breach Impact Study puts the median small business claim at about US$38,000, against about US$283,000 for large enterprises, but the worst 2.5% of small business claims reached "over 7%" of revenue, while for mid-market and large-enterprise claims the ratio "did not go over 2% in the top 2.5% extreme cases". Plan response budgets and insurance limits for that tail, not for the median.

  • Ransomware is concentrated in small business breaches. Ransomware appeared in 83% of SMB breaches in the Verizon 2026 Data Breach Investigations Report, against 48% of all breaches, and about 96% of ransomware victims with a known size were SMBs. Canada's Cyber Centre assesses ransomware actors as "almost certainly opportunistic".

  • In Coalition's book, email and payment fraud are the most frequent claims and ransomware the costliest. Business email compromise and funds transfer fraud were 58% of Coalition's 2025 claims across policyholders of every size, at average losses of US$27,000 and US$141,000, while ransomware claims averaged US$269,000. Among 15,431 US small business claims in the Verizon 2026 Breach Impact Study (incidents from 2019 to October 2025), ransomware was the more frequent incident type (39%, against 19% for business email compromise).

  • How a survey counts decides the headline. The share of small businesses hit in a year runs from 14.3% (Statistics Canada, incidents the business judged impactful) to 56% (Hiscox, US firms reporting at least one attack) to 81% (ITRC, an opt-in survey counting security or data breaches). Each figure is accurate for what it measures; none is a universal attack rate.

  • The readiness gap is measurable, and it sits in basic controls. In Statistics Canada's 2023 data, 15.4% of small firms had a written policy for internal cyber risks (66.3% of large firms), 17.8% applied operating system security patches monthly or more often (72.4%), and 22.3% had no cyber risk management arrangements at all (3.1%).

Methodology

Sources used: the Verizon 2026 Data Breach Investigations Report (published May 19, 2026; more than 31,000 incidents and more than 22,000 confirmed breaches in 145 countries between November 1, 2024 and October 31, 2025; its small and medium-sized business section covers organizations with fewer than 1,000 employees); the Verizon 2026 Breach Impact Study (June 2026; 69,683 US cyber insurance claims contributed through CyberAcuView, 38,181 of them with paid losses, for incidents from January 1, 2019 to October 31, 2025; SMB means annual revenue under US$25 million); Statistics Canada's Canadian Survey of Cyber Security and Cybercrime 2023 (The Daily, October 21, 2024, and data tables 22-10-0001-01, 22-10-0076-01, 22-10-0130-01 and 22-10-0133-01; 12,462 enterprises with 10 or more employees, a 71% response rate, collected January to March 2024 about calendar 2023); CFIB's Your Voice member surveys (October 2022, 4,639 respondents; August 2024, 2,340; September 2025, 2,478); the FBI IC3 2025 Internet Crime Report (April 2026; 1,008,597 complaints filed in 2025); Coalition's 2026 Cyber Claims Report (March 5, 2026; claims from January 1 to December 31, 2025 across more than 100,000 policyholders in the US, Canada, the UK, Australia and Germany); the Hiscox Cyber Readiness Report 2025 (September 2025) and its 2026 US focus (February 2026), both drawn from a Wakefield Research survey of 5,750 businesses with fewer than 250 employees in seven countries, 1,000 of them in the US, fielded July 29 to August 8, 2025; the IBM Cost of a Data Breach Report 2026 (July 2026; 602 organizations breached between March 2025 and February 2026); the ITRC 2025 Business Impact Report (December 2025; 662 owners and executives at firms with 500 or fewer employees, recruited through SurveyMonkey in August 2025); the SBA Office of Advocacy's Frequently Asked Questions About Small Business (February 2026); the Communications Security Establishment's Get Cyber Safe Awareness Tracking Survey 2026 (fielded by Phoenix SPI from January 9 to 29, 2026, including 300 owners and managers of businesses with up to 100 employees); the Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026 (October 30, 2024, based on information available to September 20, 2024) and its Baseline Cyber Security Controls for Small and Medium Organizations; and the Canadian Anti-Fraud Centre's 2025 fraud statistics (February 2026).

Date cutoff: October 1, 2026. Each figure is quoted in the currency its publisher used, US$ for the US publishers and Coalition and C$ for Statistics Canada, CFIB and the Canadian Anti-Fraud Centre, and nothing is converted. Verizon figures are reproduced unmodified. Survey shares are given with their base (all respondents, impacted firms, firms that paid a ransom, or insurance claims), because a share of claims is not a share of businesses. IBM's 2026 report does not break costs out by organization size, so no IBM small business cost is quoted. Statistics Canada cost-per-firm cells for small businesses that are flagged as too unreliable to publish were not used. Coalition's full report is gated, so only the figures Coalition published on its report page, in its press release, in its launch blog post and on its key-findings sheet appear here. Statistics Canada collected its 2025 survey cycle from January 14 to March 31, 2026, and those results had not been released by the cutoff. Stats that could not be reached on at least one verification pass against a named primary source were dropped rather than estimated.

How each source defines a small business

Source

Who counts as small

Geography

Data window

Verizon 2026 Data Breach Investigations Report

Fewer than 1,000 employees

145 countries

November 1, 2024 to October 31, 2025

Verizon 2026 Breach Impact Study

Annual revenue under US$25 million

United States

Incidents from January 1, 2019 to October 31, 2025

Statistics Canada CSCSC 2023

10 to 49 employees (medium 50 to 249, large 250 or more)

Canada

Calendar 2023

Hiscox Cyber Readiness Report

Fewer than 250 employees

US, UK, France, Germany, Spain, Ireland, Portugal

12 months to August 2025

CFIB Your Voice surveys

Independent business members, reported in bands from 0 to 4 up to 100 to 499 employees

Canada

12 months to August 2024 (fraud survey)

CSE Get Cyber Safe survey

Up to 100 employees

Canada

January 2026

ITRC Business Impact Report

500 or fewer employees

United States

12 months to August 2025

SBA Office of Advocacy

Independent business with fewer than 500 employees

United States

February 2026 edition

Coalition Cyber Claims Report

Not defined; headline figures cover policyholders of every size, and firms above US$100 million in revenue are also reported as their own segment

US, Canada, UK, Australia, Germany

Calendar 2025

How many small businesses these figures describe

The United States has 36,207,130 small businesses, defined by the SBA Office of Advocacy as independent businesses with fewer than 500 employees. They are 99.9% of all firms and employ 45.9% of private sector employees, or 62.3 million workers. Most have no staff at all: 82.3%, or 29,811,495 firms, are nonemployers, which leaves 6,395,635 small employer firms. In Canada, the target population of the 2023 Canadian Survey of Cyber Security and Cybercrime included approximately 170,000 small businesses with 10 to 49 employees, 30,000 medium-sized and 5,000 large businesses. Statistics Canada's frame starts at 10 employees, so the smallest Canadian businesses sit outside its survey.

How often are small businesses hit by cyber attacks?

Between one in seven and four in five small businesses report being hit in a given year, depending on who is asked and what counts as a hit. The lowest figure comes from the only mandatory, government-run survey in the set; the highest comes from an opt-in panel that counts any security or data breach.

Source and sample

Small business definition

What was counted

Result

Statistics Canada CSCSC 2023 (12,462 enterprises, mandatory survey)

10 to 49 employees

Impacted by at least one cyber security incident in 2023

14.3%

CFIB Your Voice, October 2022 (4,639 members)

Independent business members

A random cyberattack in the past year; a targeted attack

45% random; 27% targeted

CFIB Your Voice, August 2024 (1,990 answered)

Members from 0 to 4 up to 100 to 499 employees

Attempted or successful fraud in the past 12 months

50% overall; 46% at 0 to 4 employees, 72% at 100 to 499

Hiscox Cyber Readiness Report 2026, US focus (1,000 US firms)

Fewer than 250 employees

At least one cyber attack in the past 12 months

56%

Hiscox Cyber Readiness Report 2025 (5,750 firms in seven countries)

Fewer than 250 employees

At least one cyber attack in the last 12 months

59%

ITRC 2025 Business Impact Report (662 owners and executives, SurveyMonkey panel)

500 or fewer employees

A security breach, a data breach or both in the past year

81%

Sources: Statistics Canada, table 22-10-0076-01; CFIB, December 2022; CFIB, The Cost of Fraud, September 2024; Hiscox Cyber Readiness Report 2026, US focus; Hiscox Cyber Readiness Report 2025; ITRC 2025 Business Impact Report.

The spread is a definitions problem, not a contradiction. Statistics Canada asks only about incidents that impacted the business, and its note to readers says "incidents that businesses deemed not impactful are not captured in these indicators", so failed or harmless attempts drop out. Hiscox counts any cyber attack and reports an average of 2.38 attack attempts per US business. CFIB's 2024 figure covers fraud of any kind, and its 2022 survey separated random from targeted attacks. The ITRC sample was recruited from SurveyMonkey's opt-in respondent panel and leans toward the larger end of small business, with 24% of respondents at firms of 51 to 200 employees and 25% at firms of 201 to 500. Quote each figure with its definition, and compare like with like.

Grouped bar chart of the share of Canadian businesses impacted by a cyber security incident in 2019, 2021 and 2023, by firm size

Figure 1: Share of Canadian businesses impacted by a cyber security incident, by firm size, 2019, 2021 and 2023. Small means 10 to 49 employees, medium 50 to 249 and large 250 or more. Source: Statistics Canada, table 22-10-0076-01.

The share of small Canadian firms reporting an impactful incident fell from 18.4% in 2019 to 16.2% in 2021 and 14.3% in 2023, and the decline ran across every size band; large firms fell furthest, from 43.5% to 29.9%. Large firms were still about twice as likely as small firms to report an impactful incident in 2023 (29.9% against 14.3%). Spending moved the other way: Statistics Canada reports that recovery spending across Canadian businesses with 10 or more employees doubled from approximately C$600 million in 2021 to C$1.2 billion in 2023.

CFIB's member surveys show the same size gradient for fraud. In its August 2024 survey, 46% of businesses with fewer than five employees had experienced attempted or successful fraud in the past 12 months, rising to 50% at 5 to 19 employees, 54% at 20 to 49, 68% at 50 to 99 and 72% at 100 to 499 (n=1,990). CFIB's most recent survey dedicated to cyberattacks, from October 2022 (4,639 respondents), found that 45% of small businesses had experienced a random cyberattack in the past year and 27% a targeted one.

What hits small businesses: ransomware, stolen credentials and exploited vulnerabilities

Ransomware is the defining small business breach. In the Verizon 2026 Data Breach Investigations Report, ransomware appeared in 83% of breaches at organizations with fewer than 1,000 employees (n=6,182), followed by use of stolen credentials (39%) and exploitation of a vulnerability (30%). Across all breaches in the same report, "Ransomware grew again to 48% of all breaches, up from 44% from the previous year." Verizon's own summary of the segment reads: "Small organizations are disproportionally impacted by Ransomware".

Metric

Verizon 2026 Data Breach Investigations Report, SMBs (fewer than 1,000 employees)

Frequency

7,256 incidents, 7,152 with confirmed data disclosure

Top patterns

System Intrusion, Basic Web Application Attacks and Social Engineering represent 100% of breaches

Threat actors

External (100%)

Actor motives

Financial (100%)

Top action varieties (n=6,182)

Ransomware 83%, Use of stolen creds 39%, Exploit vuln 30%, Phishing 10%, Other 2.1%, Pretexting 1.4%

Initial access vectors

Exploitation of vulnerabilities 26%, Credential abuse 13%, Phishing 9%

Data compromised

Internal 97%, Credentials 31%, System 1%, Other 1%

Other metrics

Third-party 55%, Human element 45%

Source: Verizon 2026 Data Breach Investigations Report, small- and medium-sized businesses section and Figure 101.

Two numbers in the segment need context. Verizon writes that "about 96% of Ransomware victims were SMBs", counted among the ransomware cases where the organization's size is known. Size is unknown for most of the dataset: Table 3 of the report counts 7,153 breaches at small organizations (1 to 1,000 employees), 466 at large organizations (1,000+) and 15,006 where size is unknown, out of 22,625. (Table 3's count of 7,153 small-organization breaches differs by one from the 7,152 in Verizon's SMB section; both figures are Verizon's.) And exploitation of vulnerabilities, the top initial access vector for SMB breaches at 26%, reached 31% across all breaches, and Verizon now calls it "the most common initial access vector for breaches".

Stolen credentials feed the same pipeline. In the Verizon 2026 Data Breach Investigations Report's analysis of credential leaks among ransomware victims, "Small organizations represented in this dataset experienced a median of seven credential leak events over the course of the year, while larger organizations faced around 20."

Canada's National Cyber Threat Assessment 2025-2026 puts it plainly: "We assess that ransomware actors are almost certainly opportunistic and do not target specific industries." The Cyber Centre judges that ransomware "will almost certainly continue to be the most impactful cyber threat facing Canadian organizations in the next two years", and its own incident data shows that "ransomware incidents have grown, on average, 26% year-over-year since 2021", with the 2024 figure projected from the first six months of that year.

In the FBI's complaint data, the most reported industries for ransomware outside critical infrastructure are professional practices and trades. IC3 received 3,611 ransomware complaints in 2025 with US$32,320,105 in reported losses, a figure the FBI says "does not normally include estimates of lost business, time, wages, files, or equipment". Of the more than 1,400 ransomware complaints from businesses and organizations not related to a critical sector, the most reported industries were legal services (18%), contracting services such as electricians and general contractors (17%), engineering and architectural services (10%), consulting services (7%) and non-critical manufacturing (5%) (FBI IC3 2025 Internet Crime Report).

What a cyber incident costs a small business

The median US small business cyber insurance claim represents a loss of about US$38,000. That is the finding of the Verizon 2026 Breach Impact Study, which measured "ground-up" losses, the total incurred loss on a claim plus its deductible, on US cyber insurance claims from CyberAcuView members for incidents between January 1, 2019 and October 31, 2025. Verizon leaves out the "zero-dollar claims," where "either nothing was paid out to the claimant or no reserve was set aside". The median rises to about US$96,000 for mid-market companies (US$25 million to US$250 million in revenue) and about US$283,000 for large enterprises. Measured against revenue, the order flips: the worst 10% of small business claims cost "as high as 3% of revenue", the worst 2.5% cost "over 7%", and for mid-market and large-enterprise claims the ratio "did not go over 2% in the top 2.5% extreme cases".

Two-panel chart of approximate median insured loss per claim by company size and of loss as a share of revenue in the most severe claims, from the Verizon 2026 Breach Impact Study

Figure 2: Approximate median economic impact per US cyber insurance claim by company size, and loss as a share of revenue in the most severe claims, incidents from January 1, 2019 to October 31, 2025; revenue bracket n=24,873, small business revenue ratio n=8,138. Source: Verizon 2026 Breach Impact Study.

The Verizon 2026 Breach Impact Study's small business segment covers 15,431 claims, 11,996 of them with recorded losses. Ransomware was the incident type in 39% of those claims and business email compromise in 19%. Of known total losses, response and recovery accounted for 40%, losses to the threat actor for 29% and unknown types for 13%. These are insurable losses only: Verizon notes that the dataset "does not estimate uninsured losses, reputational damage or non-claim costs", and describes insurable loss as "likely a conservative lower bound of the actual economic losses of the incidents".

Coalition's claims data gives averages rather than medians, and covers its own policyholders of every size rather than the market. Across more than 100,000 policyholders in the US, Canada, the UK, Australia and Germany, claims frequency rose 3% in 2025 while average severity fell 19% to US$116,000. Ransomware was the costliest claim type at an average of US$269,000; funds transfer fraud averaged US$141,000 and business email compromise US$27,000. Businesses with more than US$100 million in revenue faced "a claims frequency five times higher than that of smaller organizations", and 64% of closed claims were resolved with no out-of-pocket loss to the policyholder (Coalition, March 2026).

Cost measure

Population

Figure

Source

Median economic impact per claim

US insureds with revenue under US$25 million, incidents 2019 to 2025

About US$38,000

Verizon 2026 Breach Impact Study

Average loss per claim, all types

Coalition policyholders of every size, 2025

US$116,000

Coalition 2026 Cyber Claims Report

Average ransomware claim

Coalition policyholders of every size, 2025

US$269,000

Coalition 2026 Cyber Claims Report

Average funds transfer fraud claim

Coalition policyholders of every size, 2025

US$141,000

Coalition 2026 Cyber Claims Report

Average business email compromise claim

Coalition policyholders of every size, 2025

US$27,000

Coalition 2026 Cyber Claims Report

Average cost among firms that lost money to fraud of any kind (preliminary)

CFIB members, 12 months to August 2024

C$7,800

CFIB, The Cost of Fraud

Recovery spending, all small firms combined

Canadian firms with 10 to 49 employees, 2023

Approximately C$300 million

Statistics Canada

Average cost of a data breach

602 breached organizations, breaches of 2,590 to 115,380 records

US$4.99 million global; US$11.5 million US

IBM Cost of a Data Breach Report 2026

In Canada, Statistics Canada measures spending rather than loss per incident. Small businesses with 10 to 49 employees spent approximately C$300 million recovering from cyber security incidents in 2023, the same as medium-sized businesses, while large businesses spent about C$500 million. On prevention and detection, small businesses spent C$2.6 billion, out of C$11.0 billion across all businesses. Among small businesses impacted by an incident, 15.1% reported additional repair or recovery costs, 13.5% a loss of revenue and 22.6% that the incident prevented the use of resources or services (Statistics Canada, table 22-10-0133-01). CFIB's August 2024 survey adds the member's view: 36% of businesses that experienced fraud of any kind suffered losses, at an average financial cost of C$7,800, a figure CFIB reports from preliminary survey results (CFIB).

Hiscox's US report lists the consequences that followed a cyber attack: 31% "incurred costs to notify customers", 28% "saw a reduction in business performance", 26% "incurred substantial fines" and 25% "indicated the solvency or viability of their company was materially threatened" (Hiscox, February 2026). The US report does not state the base for these shares; the seven-country 2025 report gives its own fine figure (33%) as a share of firms that were attacked: "One third (33%) of affected firms incurred fines significant enough to damage their financial health".

The claim figures above sit far below the multimillion-dollar breach averages that are often quoted alongside small business statistics. IBM's Cost of a Data Breach Report 2026 puts the global average cost of a data breach at a record US$4.99 million and the US average at a record US$11.5 million, but it studied 602 organizations breached between March 2025 and February 2026, with breaches of 2,590 to 115,380 compromised records, and it does not break results out by organization size. It is the right benchmark for a large breach; it is not a small business statistic. Our data breach statistics for 2026 cover the cross-industry figures.

Ransomware: who pays, and what happens after

Most ransomware victims do not pay, according to every dataset here except one survey of small and medium-sized enterprises.

Dataset

Population

Finding

Statistics Canada CSCSC 2023

Canadian businesses with 10 or more employees hit by ransomware in 2023

88% did not pay; of those that paid, 84% paid less than C$10,000 and 4% more than C$500,000

Coalition 2026 Cyber Claims Report

Coalition policyholders of every size hit by ransomware in 2025

A record 86% refused to pay

Verizon 2026 Data Breach Investigations Report

Ransomware victims in Verizon's dataset, all sizes

69% of ransomware victims didn't pay; median ransom paid US$139,875, down from US$150,000 in the previous year (a restated figure: Verizon notes its 2024 and 2023 medians "are different from the ones we published in the 2025 DBIR"; the Verizon 2025 Data Breach Investigations Report had published US$115,000)

Hiscox Cyber Readiness Report 2025

Businesses with fewer than 250 employees in seven countries that suffered ransomware

80% paid; 60% of payers recovered all or part of their data

Sources: Statistics Canada; Coalition; Verizon 2026 Data Breach Investigations Report; Hiscox, September 2025.

The Hiscox result is the outlier, and its US cut shows that paying often does not end the incident. Of US businesses that paid a ransom, only 50% recovered all of their data, 27% sustained another attack, and victims paid a ransom an average of 2.24 times to recover. In the seven-country survey, for 31% of those who paid, the attackers demanded more money.

Demands keep rising even as more victims refuse to pay. Coalition recorded initial ransom demands up 47% to an average of more than US$1 million in 2025; 70% of its ransomware claims involved both encryption and data theft, and its incident response team negotiated ransom payments down by an average of 65% (Coalition 2026 Cyber Claims Report). In Canada, 13% of businesses impacted by a cyber security incident in 2023 reported a ransomware attack, up from 11% in 2021. In the CSE's January 2026 survey of businesses with up to 100 employees, 16% of owners and managers were concerned about their company's data being held for ransom, 17% said their company was not prepared to defend against ransomware and a further 16% were unsure. For payout trends across all company sizes, see our ransomware payout statistics for 2026.

Business email compromise and payment fraud

Business email compromise carried the second-largest reported losses in the FBI's 2025 complaint data, after investment fraud. IC3 received 24,768 BEC complaints in 2025 with US$3,046,598,558 in reported losses, up from 21,442 complaints and US$2,770,151,146 in 2024, and businesses reported losses over US$30 million to BEC scams involving AI. The FBI describes BEC as "a scam targeting businesses or individuals working with suppliers and/or businesses regularly performing wire transfer payments."

Insurance claims show how it turns into losses. In Coalition's 2025 data, which cover policyholders of every size, BEC and funds transfer fraud made up 58% of all claims. BEC claim frequency rose 15% while average severity fell 28% to US$27,000, and funds transfer fraud accounted for 27% of claims at an average of US$141,000 (Coalition press release). Email compromise is a common route to payment fraud but not a required one: 52% of funds transfer fraud claims originated as a BEC and 71% "were a direct result of social engineering" (Coalition 2026 Cyber Claims Report), and 39% of funds transfer fraud events "occurred without any confirmed email compromise" (Coalition blog, March 5, 2026). Coalition clawed back US$21.8 million in stolen funds, an average of US$202,000 per recovery (Coalition press release). In the Verizon 2026 Breach Impact Study, BEC was the incident type in 19% of 15,431 US small business claims (incidents from 2019 to October 2025).

In Canada, the Canadian Anti-Fraud Centre records these frauds as spear phishing, which it defines as fraudsters "pretending to be from legitimate sources to convince businesses or individuals to send them money", from executive and supplier spoofs to payroll diversion. Spear phishing produced C$67.9 million in reported losses across 813 reports and 571 victims in 2025, the second-largest loss category after investment fraud, out of more than C$704 million in total reported fraud losses. Among CFIB members that encountered fraud in the 12 months to August 2024 (n=982), 85% saw attempted email scams and phishing that caused no loss and 9% fell victim; 54% saw attempted malicious software and 8% fell victim. Fraudulent payments (19% victims) and chargebacks (16% victims) were less common but more often caused losses. Our phishing statistics for 2026 cover the wider phishing landscape.

Readiness: what small businesses have in place

Small businesses run far fewer of the basic controls that insurers, auditors and the Cyber Centre ask about. Statistics Canada's 2023 survey measured each arrangement directly, by firm size.

Paired bar chart comparing cyber security arrangements at small and large Canadian businesses in 2023

Figure 3: Cyber security arrangements at small (10 to 49 employees) and large (250 or more) Canadian businesses, 2023, share of businesses. Source: Statistics Canada, table 22-10-0130-01.

Arrangement (Canada, 2023)

Small (10 to 49)

Medium (50 to 249)

Large (250 or more)

All

Cyber risk insurance

19.1%

32.8%

58.0%

22.3%

Written policy to manage internal cyber security risks

15.4%

37.3%

66.3%

20.3%

Written policy to report cyber security incidents

10.5%

27.7%

57.7%

14.4%

Monthly or more frequent operating system patching for security

17.8%

38.7%

72.4%

22.6%

Monthly or more frequent software patching for security

18.2%

35.6%

64.2%

22.1%

Recurring mandatory cyber security training

5.7%

21.9%

52.3%

9.5%

Business continuity plan covering cyber threats

6.3%

21.2%

51.0%

9.9%

A consultant or contractor manages cyber security risks

37.1%

44.5%

48.3%

38.6%

No cyber risk management arrangements

22.3%

10.8%

3.1%

19.9%

Source: Statistics Canada, table 22-10-0130-01, private sector, 2023.

The same survey found that 5.2% of small businesses had no cyber security measures of any kind in place, against 0.4% of large businesses, and that only 25.5% of small firms used software and application security measures, against 80.6% of large firms (Statistics Canada, table 22-10-0001-01).

The CSE's Get Cyber Safe Awareness Tracking Survey 2026 adds a January 2026 snapshot of Canadian businesses with up to 100 employees, based on 300 owners and managers. Most respondents (77%) said their company had taken steps to protect itself against cyber threats; 4% said no measures had been taken and 18% were unsure. Against ransomware specifically:

Measure against ransomware (CSE survey, January 2026, n=300)

2026

2024

Use MFA

55%

46%

Keep operating systems, software and apps updated

52%

50%

Regularly back up company files

45%

46%

Use anti-virus software

42%

52%

Educate employees

35%

31%

Store file back-ups offline

34%

36%

Limit access to software

33%

26%

Restrict employees from installing or running software

30%

28%

Run simulations of ransomware attacks

11%

8%

Source: Get Cyber Safe Awareness Tracking Survey: 2026 Final Report, prepared by Phoenix SPI for the Communications Security Establishment.

Nearly a quarter (23%) of respondents did not know whether their company had done anything to protect itself from ransomware, and half said recovering from an attack would take some effort (38%) or would be difficult (13%).

Insurance coverage depends on who is asked. Statistics Canada, sampling Canadian businesses with 10 to 49 employees, found cyber risk insurance at 19.1% of small firms in 2023. Hiscox's 2025 survey of the people responsible for cyber security strategy at firms under 250 employees in seven countries found that 71% had a cyber policy or cyber coverage within another policy, from 65% at firms with ten or fewer employees to 79% at 11 to 49 and 82% at 50 to 249. The two figures describe different populations, and neither cancels the other. The Cyber Centre's Baseline Cyber Security Controls for Small and Medium Organizations recommends that organizations "consider purchasing a cyber security insurance policy" that covers incident response and recovery. For what underwriters ask before they bind a policy, see what cyber insurance underwriters actually ask about penetration testing and our cyber insurance statistics for 2026.

Responsibility for security at small firms has shifted toward outside help. In the CSE survey, 33% of business respondents outsource IT support, and the share of owners and managers who personally handle their company's IT fell from 47% in 2020 to 23% in 2026. Statistics Canada found that 37.1% of small firms used a consultant or contractor to manage cyber security risks in 2023. That makes the managed service provider part of the attack surface. The Verizon 2026 Data Breach Investigations Report also records third-party involvement in 55% of SMB breaches, but that metric is wider than outsourcing: it "combines three different kinds of business relationship archetypes", including breaches made possible by "a vulnerability in a vendor product". CFIB found in 2022 that only 11% of members had offered mandatory cybersecurity training in the past year, and in its September 2025 survey 35% of respondents (2,355 answered) named cybersecurity and privacy concerns as a challenge when using or adopting digital tools.

What this means for small business defenders

  1. Test the systems attackers reach first. Exploitation of vulnerabilities was the top initial access vector in SMB breaches (26%) in the Verizon 2026 Data Breach Investigations Report, and ransomware appeared in 83% of them. An external network penetration test of internet-facing systems and a web application penetration test of the customer portal or online store find those exposures before an attacker does. The Cyber Centre's baseline controls already ask small and medium organizations to "ensure that their websites address the OWASP top 10 vulnerabilities".

  2. Put a second channel on every payment change. Business email compromise and funds transfer fraud were 58% of Coalition's 2025 claims across policyholders of every size, and 39% of funds transfer fraud events involved no confirmed email compromise. Verify changes to bank details by calling a number already on file, require two people to approve a new payee, and test the process with phishing simulation campaigns that include payment-change pretexts.

  3. Close the basic gaps first. Monthly operating system patching (17.8% of small Canadian firms in 2023), recurring training (5.7%) and a written incident reporting policy (10.5%) are inexpensive next to a claim. The Cyber Centre's baseline control BC.5.1 asks organizations to "implement two-factor authentication wherever possible", and 55% of small businesses in the CSE survey use MFA against ransomware.

  4. Rehearse ransomware recovery. Only 11% of small Canadian businesses run ransomware simulations and 34% store backups offline (CSE, January 2026), and half say recovery would take some effort (38%) or be difficult (13%). A tabletop exercise and a restore test from offline backups show whether the business can keep operating without paying.

  5. Size insurance for the tail, not the median. The median small business claim in the Verizon 2026 Breach Impact Study is about US$38,000, but the worst 2.5% exceeded 7% of revenue, and only 19.1% of small Canadian firms carried cyber risk insurance in 2023. Check limits and sublimits against the worst case for your revenue rather than the median claim.

Frequently Asked Questions

What percentage of small businesses experience a cyber attack?

It depends on what is counted. In the US, 56% of 1,000 small businesses with fewer than 250 employees reported at least one cyber attack in the past 12 months in a survey fielded from July 29 to August 8, 2025 (Hiscox Cyber Readiness Report 2026, US focus). In Canada, Statistics Canada found that 14.3% of businesses with 10 to 49 employees were impacted by a cyber security incident in 2023, counting only incidents the business judged impactful (Statistics Canada). When small businesses are breached, ransomware is usually involved: it appeared in 83% of small and medium-sized business breaches in the Verizon 2026 Data Breach Investigations Report.

How much does a cyber attack cost a small business?

The median US small business cyber insurance claim represents a loss of about US$38,000, against about US$283,000 for large enterprises, according to the Verizon 2026 Breach Impact Study, which counts businesses with revenue under US$25 million as small and medium-sized. The worst 2.5% of small business claims cost over 7% of revenue. Averages run higher and cover businesses of every size: across all Coalition policyholders, 2025 claims averaged US$116,000 overall and US$269,000 for ransomware (Coalition). In Canada, 36% of CFIB members that experienced fraud of any kind, not only cyber fraud, in the 12 months to August 2024 lost money, at an average cost of C$7,800, a figure CFIB reports from preliminary survey results (CFIB).

Are small businesses targeted by ransomware more than large companies?

Small businesses dominate ransomware breach data, although attackers are opportunistic rather than selective. In the Verizon 2026 Data Breach Investigations Report, ransomware appeared in 83% of breaches at organizations with fewer than 1,000 employees, against 48% of all breaches, and about 96% of ransomware victims with a known size were SMBs. The Canadian Centre for Cyber Security assesses that "ransomware actors are almost certainly opportunistic and do not target specific industries" (National Cyber Threat Assessment 2025-2026).

What is the most common cyber attack on small businesses?

By insurance claim volume, it depends on whose claims are counted: business email compromise and funds transfer fraud made up 58% of Coalition's 2025 claims across policyholders of every size (Coalition 2026 Cyber Claims Report), while ransomware was the incident type in 39% of 15,431 US small business claims (incidents from 2019 to October 2025) and business email compromise in 19% in the Verizon 2026 Breach Impact Study. By breach data, it is ransomware, which appeared in 83% of SMB breaches in the Verizon 2026 Data Breach Investigations Report, followed by use of stolen credentials at 39%. By attempts, it is phishing: 85% of CFIB members that encountered fraud reported attempted email scams and phishing that caused no loss, and 9% fell victim (CFIB).

Do small businesses pay ransomware demands?

It depends on the dataset, and the largest ones cover businesses of every size. Statistics Canada found that 88% of Canadian businesses with 10 or more employees hit by ransomware in 2023 did not pay, and 84% of those that paid paid less than C$10,000 (Statistics Canada). A record 86% of Coalition policyholders of all sizes hit by ransomware refused to pay in 2025 (Coalition). The one dataset limited to small and medium-sized firms points the other way: in Hiscox's 2025 survey of firms under 250 employees in seven countries, 80% of ransomware victims paid (Hiscox, September 2025), and in its US cut, only 50% of businesses that paid recovered all of their data (Hiscox, February 2026).

How many small businesses have cyber insurance?

In Canada, 19.1% of businesses with 10 to 49 employees had cyber risk insurance in 2023, against 58.0% of businesses with 250 or more employees (Statistics Canada, table 22-10-0130-01). Hiscox's 2025 survey of the people responsible for cyber security at firms under 250 employees in seven countries found that 71% had a cyber policy or cyber coverage within another policy, including 65% at firms with ten or fewer employees (Hiscox). The gap reflects different samples rather than a contradiction.

How many small businesses are there in the US and Canada?

The United States has 36,207,130 small businesses, meaning independent firms with fewer than 500 employees, which make up 99.9% of all firms and employ 45.9% of private sector employees, according to the SBA Office of Advocacy in February 2026. Of these, 6,395,635 have paid employees. Statistics Canada's 2023 cyber security survey covered approximately 170,000 small businesses with 10 to 49 employees and 30,000 medium-sized businesses with 50 to 249 employees (Statistics Canada). Statistics Canada's survey frame starts at 10 employees and excludes public administration, so these are not counts of all Canadian small businesses.

Why do small business cybersecurity statistics disagree?

Each source defines both "small business" and "attack" differently. The Verizon 2026 Data Breach Investigations Report counts organizations under 1,000 employees as small, the Verizon 2026 Breach Impact Study uses revenue under US$25 million, Statistics Canada uses 10 to 49 employees and Hiscox uses fewer than 250 employees. Statistics Canada counts only incidents the business judged impactful (14.3%), Hiscox counts any attack (56% in the US), and the ITRC counts security or data breaches in an opt-in panel (81%). Quote each figure with its definition and its sample.

Where can I get the latest small business cybersecurity data?

Go to the primary publishers. The newest editions are the Verizon Data Breach Investigations Report (May 2026) and Breach Impact Study (June 2026), the FBI IC3 Internet Crime Report (April 2026), Coalition's Cyber Claims Report (March 2026), the Hiscox Cyber Readiness Report (September 2025, with a US focus in February 2026), the CSE's Get Cyber Safe tracking survey (2026 report), and Statistics Canada's Canadian Survey of Cyber Security and Cybercrime, whose 2023 cycle was released in October 2024 and whose 2025 cycle was collected from January to March 2026. Our data breach statistics for 2026 track the cross-industry numbers.

Put these numbers to work

The figures above describe the risk; a penetration test shows which of it applies to your own systems. Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.

For a small business, human-led testing means two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications, with 18 published CVEs across the team and Hall of Fame listings at Apple, Google and the US Department of Defense. The work targets what the data above says gets exploited: the internet-facing network and remote access, Microsoft 365 and Entra ID sign-in, the customer portal or online store, and the payment-change process staff use every week. Each confirmed finding is posted to the PTaaS portal with a proof of concept and remediation guidance, retesting of fixed findings is included, and human-led and hybrid engagements include an attestation letter for auditors, insurers and customer questionnaires. Engagements run as a one-time annual test or as a continuous program.

The published entry point is the Autonomous Pentest at US$3,000 per assessment, or US$650 per month on a 12-month plan, covering one web application and its APIs and carrying a "No High or Critical Finding = Don't Pay" guarantee. The Hybrid Pentest, in which Stingrai's penetration testers and its Snipe agent test together throughout, is US$6,800 per assessment or US$1,275 per month on a 12-month continuous program, for the same one-application scope (pricing). Network, office, cloud and social engineering tests are quoted to scope (get a quote). Stingrai's penetration testing supports your PCI DSS, HIPAA and cyber insurance programs with pentest evidence your auditors and underwriters can use. For budgeting, see penetration testing cost in 2026 and the average cost of a penetration test in Canada, and to compare providers that work with firms of 10 to 250 staff, see our ranking of the best penetration testing companies for small businesses.

References

  1. Verizon. 2026 Data Breach Investigations Report. May 19, 2026. https://www.verizon.com/dbir. More than 31,000 incidents and more than 22,000 confirmed breaches in 145 countries, November 1, 2024 to October 31, 2025; the small and medium-sized business section covers organizations with fewer than 1,000 employees.

  2. Verizon. 2026 Breach Impact Study. June 2026. https://www.verizon.com/dbir. 69,683 US cyber insurance claims contributed through CyberAcuView for incidents from January 1, 2019 to October 31, 2025; the SMB segment covers insureds with revenue under US$25 million.

  3. Statistics Canada. Impact of cybercrime on Canadian businesses, 2023 (The Daily). October 21, 2024. https://www150.statcan.gc.ca/n1/daily-quotidien/241021/dq241021a-eng.htm. Canadian Survey of Cyber Security and Cybercrime, 12,462 enterprises with 10 or more employees, 71% response rate.

  4. Statistics Canada. Table 22-10-0076-01, Types of cyber security incidents that impact enterprises by industry and size of enterprise. https://www150.statcan.gc.ca/t1/tbl1/en/tv.action?pid=2210007601. Survey cycles 2017 to 2023.

  5. Statistics Canada. Table 22-10-0130-01, Use of risk management arrangements by industry and size of enterprise. https://www150.statcan.gc.ca/t1/tbl1/en/tv.action?pid=2210013001. Policies, insurance, patching, training and continuity planning by firm size.

  6. Statistics Canada. Table 22-10-0001-01, Cyber security measures enterprises have in place by industry and size of enterprise. https://www150.statcan.gc.ca/t1/tbl1/en/tv.action?pid=2210000101. Technical security measures by firm size.

  7. Statistics Canada. Table 22-10-0133-01, Impacts of cyber security incidents on enterprises by industry and size of enterprise. https://www150.statcan.gc.ca/t1/tbl1/en/tv.action?pid=2210013301. Impacts as a share of enterprises impacted by incidents.

  8. Statistics Canada. Canadian Survey of Cyber Security and Cybercrime (CSCSC), survey information. https://www.statcan.gc.ca/en/survey/business/5244. Collection dates for the 2025 cycle, January 14 to March 31, 2026.

  9. Canadian Federation of Independent Business. The Cost of Fraud: How Small Business Owners Are Tackling Risks and Challenges. September 24, 2024. https://www.cfib-fcei.ca/hubfs/Fraud%20report-EN-2024.pdf. Your Voice survey of 2,340 members, August 8 to 21, 2024.

  10. Canadian Federation of Independent Business. Nearly half of small businesses have experienced random cyberattacks in the past year (news release). December 8, 2022. https://www.cfib-fcei.ca/en/media/nearly-half-of-small-businesses-have-experienced-random-cyberattacks-in-the-past-year. Your Voice survey of 4,639 members, October 6 to 31, 2022.

  11. Canadian Federation of Independent Business. Your Voice Survey Results, September 2025. November 2025. https://www.cfib-fcei.ca/hubfs/Your%20Voice%20Survey%20September%202025_111225.pdf. 2,478 members, September 11 to 25, 2025, including challenges with digital tools.

  12. FBI Internet Crime Complaint Center. 2025 Internet Crime Report. April 2026. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf. 1,008,597 complaints filed with IC3 in 2025.

  13. Coalition. 2026 Cyber Claims Report (report page and key findings). March 2026. https://www.coalitioninc.com/claims-report/2026. Claims from January 1 to December 31, 2025 across more than 100,000 policyholders.

  14. Coalition. Coalition's 2026 Cyber Claims Report Finds Initial Ransom Demands Surged 47% But Most Businesses Refuse to Pay (press release). March 5, 2026. https://www.coalitioninc.com/announcements/2026-cyber-claims-report. Frequency, severity and claim-type averages for 2025.

  15. Hiscox. The Hiscox Cyber Readiness Report 2026, US focus. February 2026. https://www.hiscox.com/documents/Hiscox-Cyber-Readiness-Report-2026.pdf. 1,000 US small businesses with fewer than 250 employees, surveyed by Wakefield Research from July 29 to August 8, 2025.

  16. Hiscox. Hiscox Cyber Readiness Report 2025. September 2025. https://www.hiscoxgroup.com/hiscox-cyber-readiness-report-2025. 5,750 businesses with fewer than 250 employees in the US, UK, France, Germany, Spain, Ireland and Portugal.

  17. IBM. Cost of a Data Breach Report 2026. July 2026. https://www.ibm.com/reports/data-breach. 602 organizations breached between March 2025 and February 2026; no breakdown by organization size.

  18. Identity Theft Resource Center. 2025 Business Impact Report. December 2025. https://www.idtheftcenter.org/wp-content/uploads/2025/11/ITRC-2025-Business-Impact-Report.pdf. 662 owners and executives at firms with 500 or fewer employees, recruited through SurveyMonkey in August 2025.

  19. US Small Business Administration, Office of Advocacy. Frequently Asked Questions About Small Business. February 2026. https://advocacy.sba.gov/2026/02/03/frequently-asked-questions-about-small-business-2026/. Counts of US small businesses and their share of employment.

  20. Communications Security Establishment. Get Cyber Safe Awareness Tracking Survey: 2026 Final Report (prepared by Phoenix SPI). March 2026. https://epe.bac-lac.gc.ca/100/200/301/pwgsc-tpsgc/por-ef/communications_security_establishment/2026/052-25-e/report.html. 2,330 online Canadians, including 300 owners and managers of businesses with up to 100 employees, January 9 to 29, 2026.

  21. Canadian Centre for Cyber Security. National Cyber Threat Assessment 2025-2026. October 30, 2024. https://www.cyber.gc.ca/en/guidance/national-cyber-threat-assessment-2025-2026. Threat assessment based on information available to September 20, 2024, including Cyber Centre ransomware incident data.

  22. Canadian Centre for Cyber Security. Baseline Cyber Security Controls for Small and Medium Organizations (version 1.2). https://www.cyber.gc.ca/en/guidance/baseline-cyber-security-controls-small-and-medium-organizations. Baseline controls for organizations with fewer than 500 employees.

  23. Canadian Anti-Fraud Centre. Top 10 frauds in 2025. February 2026. https://antifraudcentre-centreantifraude.ca/features-vedette/2026/02/top-fraud-2025-fraudes-plus-courantes-eng.htm. Fraud reports, victims and losses reported to the CAFC in 2025.

  24. Coalition. 5 Essential Insights From Our 2026 Cyber Claims Report (blog). March 5, 2026. https://www.coalitioninc.com/blog/cyber-insurance/2026-cyber-claims-report.

  25. Verizon. 2025 Data Breach Investigations Report. April 2025. https://www.verizon.com/dbir. Published the calendar-2024 median ransom payment of US$115,000 that the 2026 edition restates.

0 views

0

X

Related reading

Best Penetration Testing Companies for Construction and Engineering Firms (2026)
Network SecuritySocial Engineering

Best Penetration Testing Companies for Construction and Engineering Firms (2026)

The best penetration testing companies for construction and engineering firms in 2026, ranked, with what CMMC, CPCSC, owners and insurers actually require.

30 min read

Best Enterprise Penetration Testing Companies (2026): Ranked for Global Programs, Procurement and Continuous Coverage
Network SecurityWeb App Security

Best Enterprise Penetration Testing Companies (2026): Ranked for Global Programs, Procurement and Continuous Coverage

The best enterprise penetration testing companies in 2026, ranked on capacity, CREST and threat-led schemes, vendor security, MSA terms and board reporting.

31 min read

Best Penetration Testing Companies for Hotels and Hospitality (2026): Ranked for PCI DSS, Guest Data and Franchise Networks
Network SecurityWeb App Security

Best Penetration Testing Companies for Hotels and Hospitality (2026): Ranked for PCI DSS, Guest Data and Franchise Networks

The best penetration testing companies for hotels and hospitality groups in 2026, ranked, with what PCI DSS 11.4, the FTC Marriott order and PIPEDA require.

31 min read

Contents

X