Continuing our “Cybersecurity in Numbers” series — this installment addresses one of the most persistent misconceptions among small and medium business owners: “we’re too small to be a target.”
Where the number comes from, and why it needs context
The 43% figure traces back to Accenture’s 2019 research and has remained the most widely cited statistic in the industry regarding attacks on small businesses. In fairness, it’s not the most current figure, and the situation hasn’t improved since 2019 — if anything, the share of attacks targeting small and medium businesses appears to have grown further.
More recent data from Verizon’s Data Breach Investigations Report (DBIR) 2025 confirms the same trend through different metrics: small and medium businesses recorded nearly 4 times more confirmed breaches than large organizations. And 88% of breaches in the small and medium business segment involved ransomware — compared to 39% at large companies.
Why small businesses are attractive targets
Smaller cybersecurity budgets — often none at all
Fewer dedicated security staff — security responsibilities are often spread thin or absent entirely
Easier access to customer and partner data — while that data holds the same value to attackers as it would at a large company
A false sense of security — the belief that “this doesn’t apply to us” lowers vigilance across the organization
What this means in practice
A small business isn’t a less attractive target than a large corporation — often, it’s an easier one. Attackers care less about company size and more about how easily they can reach money or data.
What can be done without a large budget
Regular, even brief, employee training on recognizing phishing and fraud schemes
Backing up critical data — in a ransomware attack, this is often what determines whether a company has to pay
A basic vulnerability audit — reviewing access rights, passwords, and security settings at least once a year
Registering with the GAZPD personal data holder registry if the company handles customer data — not just a legal requirement, but a good prompt to review data protection systematically
Company size doesn’t protect against the consequences of a cyberattack — if anything, it can increase exposure. The encouraging part is that basic protection for a small business doesn’t require a large corporate budget — it can start with simple, low-cost steps.