Tuesday, October 6, 2026

Small business cybersecurity: The low-cost basics that stop most attacks

Posted

For many small business owners, cybersecurity sits somewhere below invoices, payroll, and the customer waiting at the counter. With so much going into running a business, investment in cybersecurity often falls to the back burner.

But cybersecurity can often be cheaper and easier than owners think. Below, Xero explores how the highest-return cybersecurity controls are typically free or low-cost, yet adoption remains a problem.

Why attackers target small businesses

Business owners may think they’re too small to matter, but this idea isn’t actually true. Small and medium businesses record nearly four times as many confirmed breaches as large organizations, according to the Verizon 2025 Data Breach Investigations Report (DBIR). Attackers like easy targets, and businesses with 20 or fewer staff usually have fewer defenses than large enterprises.

The good news: Most incidents are rarely business-ending. Hiscox found that while 56% of U.S. small businesses had at least one cyber attack between mid-2024 and mid-2025, only 25% said it threatened their business viability. The risk is real, but most of the time it’s survivable.

The rare attack can cause lasting damage. According to a recent IBM report, a data breach averages $10.22 million in the U.S. That’s usually for larger companies. Small businesses likely won’t see a bill that large, but when cash flow is your lifeline, any unexpected costs can feel huge. While most attacks are survivable, the rare bad ones can threaten a business, which makes a strong case for closing the easy gaps first.

Low-cost defenses most owners skip

The protections that block most of these attacks are cheap or free, but they often don’t get used. Take multi-factor authentication (MFA), for example. This is a system requiring a second check before logging in, most often found with software that includes financial or sensitive data. According to JumpCloud, only 27% of businesses with 25 or fewer employees use MFA, even though it’s one of the highest-return controls a small team can turn on.

The same gap shows up in other places. According to Guardz 2025 SMB Cybersecurity Report:

  • Only 34% of small businesses have a written incident response plan (what to do when a cyberattack happens)
  • Twenty-seven percent have no cyber insurance
  • Most owners improvise when an attack happens, which is the worst time to figure out a plan

This gap is how attackers get in. Stolen passwords were the primary action in 33% of small-business breaches, per the Verizon DBIR report, which is exactly what MFA blocks off.

How AI is changing the threat

With the rise of AI tools, cyber attacks are increasing. AI-generated text in spam emails doubled over two years, according to Verizon’s DBIR research. The old advice of watching out for typos and clumsy grammar is no longer sufficient. AI models can write clean, personalized phishing at scale and mimic the tone of a supplier or manager. This makes phishing and ransomware campaigns cheaper for cyberattackers to run. Deepfake impersonation of a voice or face adds another layer of false credibility.

This changes what defense and protection around cybersecurity needs to be in the age of AI. Verification should be at the forefront of this plan. Before any money moves or passwords change, actually verify who’s asking. Call the number you know, or confirm through a separate channel. Trust the person, not the message.

A cybersecurity checklist to run this week

Follow these high-return steps to protect against cyber attacks:

  1. Turn on MFA everywhere it’s offered, starting with email and banking.
  2. Use a password manager so every account gets a long, unique password.
  3. Keep software and devices updated, and switch on automatic updates where possible.
  4. Back up critical data on a regular schedule, and test that it actually works.
  5. Add a verification step for any change to payment details or supplier bank accounts.
  6. Train the team to treat urgency and pressure in a message as warning signs.
  7. Write a simple incident plan that names who to call and what to do first.

These small steps can result in a huge payoff, and a lot of them are just habits.

Attacks on small businesses are common and rising. The defenses that actually work are simple. The only real step is turning on the basics.

This story was produced by Xero and reviewed and distributed by Stacker.