The 5 Most Common Cyberattacks on Small Businesses
Phishing & Business Email Compromise (BEC)
CRITICALRansomware
CRITICALCredential Stuffing & Password Attacks
HIGHMalware via Malicious Websites and Downloads
HIGHInsider Threats and Departing Employee Access
MODERATEThe 10-Step Cybersecurity Baseline for Small Businesses
Enable MFA on every account — no exceptions
Email, banking, accounting software, payroll, CRM, cloud storage. Use an authenticator app (Google Authenticator, Authy, Microsoft Authenticator) — not SMS, which can be SIM-swapped. This single control stops 99%+ of remote access attacks.
Implement the 3-2-1 backup rule
3 copies, 2 media types, 1 offsite. Cloud backup services: Backblaze Business ($99/year/computer), Acronis ($6/month/workload), Veeam. Test a restore monthly — a backup you've never restored from is untested.
Keep all software and operating systems updated
Enable automatic updates for Windows/macOS, Microsoft 365, QuickBooks, browsers, and all installed software. 85% of successful cyberattacks exploit vulnerabilities with available patches — attackers know when patches are released and target unpatched systems immediately.
Set up DMARC, DKIM, and SPF for your email domain
These three DNS records prevent attackers from sending email that appears to come from your domain — protecting your customers and business partners. Setup takes 30–60 minutes through your domain registrar or a free tool like DMARCLY or EasyDMARC. Start with "p=none" policy and move to "p=reject" after monitoring.
Use a password manager — no shared or reused passwords
Bitwarden (free for personal, $3/month/user for teams), 1Password ($3/user/month), LastPass Business ($4/user/month). Every system gets a unique, generated password. Never reuse passwords across systems. Never share login credentials between employees — each person gets their own account.
Secure your Wi-Fi network
WPA3 encryption (if your router supports it) or WPA2 minimum. Separate guest network for visitors, vendors, and personal devices — never share your business network password. Change your router admin password from the default. Enable firewall. Replace consumer routers with business-grade hardware (Ubiquiti, Cisco Meraki, or similar).
Endpoint protection on all devices
Microsoft Defender (built into Windows, free) + Malwarebytes Business ($4.17/endpoint/month) is a solid small business stack. Ensure endpoint protection is installed on every computer — including personal laptops used for business. Mobile Device Management (MDM) for phones that access business email.
Establish a wire transfer verification protocol
All wire transfer requests received by email — regardless of sender — must be verbally confirmed by phone to a known number (not one provided in the email) before execution. This one protocol prevents most BEC wire fraud. No exceptions for the CEO or CFO. Frame it as a compliance requirement, not distrust.
Run phishing awareness training and simulations
KnowBe4, Proofpoint Security Awareness Training, or SANS Security Awareness all offer simulated phishing campaigns — you send fake phishing emails to employees and track who clicks. Employees who click receive immediate training. Free options: CISA has free phishing simulation tools. The FTC has free cybersecurity training for small businesses at ftc.gov.
Create an incident response plan before you need one
Write a one-page document: who to call when a breach occurs (IT contact, cyber insurance carrier's 24/7 hotline, your attorney, your bank), what to preserve (don't immediately reboot or wipe systems — preserve forensic evidence), what to shut down first. Having this plan saves hours of chaotic decision-making when seconds matter.
The 3-2-1 Backup Rule — In Detail
The 3-2-1 Rule: 3 Copies, 2 Media Types, 1 Offsite
3 copies of your data
Working copy + 2 backup copies. If your working copy is ransomware-encrypted and one backup is also compromised, you still have a third clean copy to restore from.
2 different types of media
Internal drive / server + external hard drive OR cloud backup. The goal is that a single failure (hardware crash, ransomware that spreads locally) doesn't wipe all copies simultaneously.
1 copy stored offsite
Cloud backup (Backblaze $99/year/computer, Acronis $6/month, Amazon S3, or Microsoft Azure Backup) provides geographic and network separation. Ransomware that encrypts your local files and local network storage CANNOT reach properly configured cloud backups. This is your ransomware recovery plan.
A USB external hard drive plugged into your computer when ransomware strikes will be encrypted along with everything else. If cloud backup sync runs on the infected machine, ransomware may also encrypt cloud synced files (Dropbox, Google Drive, OneDrive sync). The critical word is "offsite" — not just online. Use a cloud backup service with versioning and immutable backups (Backblaze, Acronis, Veeam) that maintains prior versions even if the current copy is deleted or encrypted.
What Cyber Liability Insurance Covers (and What It Doesn't)
| Coverage Category | Typically Covered? | Notes |
|---|---|---|
| Ransomware payment negotiation and payment | Usually (sub-limit) | Most policies include a breach coach and ransom negotiator; ransom payment often subject to a sub-limit |
| Data recovery and restoration | Yes | Cost to restore files from backup or rebuild encrypted systems |
| Business interruption / lost revenue | Yes | Revenue lost during the period systems are down; waiting period (deductible) typically 8–24 hours |
| Notification costs | Yes | Legally required customer and employee notifications when their data is breached; credit monitoring costs |
| Incident response / forensics | Yes | Cost to investigate how the breach occurred; required to determine scope |
| Public relations / reputation management | Sometimes | Some policies include PR crisis management; often optional endorsement |
| Third-party liability (customer lawsuits) | Yes | Customers who sue you because their data was breached; legal defense and settlements |
| Social engineering / BEC wire fraud | Sometimes | Requires a specific social engineering endorsement — not always included in base cyber policy |
| Theft by employee | No | Covered by crime insurance / employee dishonesty bond — separate policy |
| Physical hardware damage | No | Covered by commercial property insurance |
| Patent / IP infringement | No | Separate IP insurance policy required |
Free Government Cybersecurity Resources
CISA Small Business Resources
cisa.gov/small-business — free vulnerability assessments, guides, and cybersecurity training specifically for small businesses. CISA offers free cybersecurity evaluations for small businesses in critical infrastructure sectors.
NIST Cybersecurity Framework
csrc.nist.gov/projects/small-business — NIST's Small Business Cybersecurity Corner provides a simplified version of the NIST CSF designed for small businesses without dedicated IT staff.
SBA Cybersecurity Resources
sba.gov/managing-business/cybersecurity — free online courses, guides, and webinars on cybersecurity basics. The SBA's Learning Center has free self-paced cybersecurity courses.
FTC Cybersecurity for Small Business
ftc.gov/tips-advice/business-center/cybersecurity — short, practical guides on phishing, ransomware, vendor security, and secure remote access. Free printable materials for employee training.
Frequently Asked Questions
- What is the most common cyberattack on small businesses?
- Phishing is the most common — 94% of malware is delivered via email. Business Email Compromise (BEC), a form of targeted phishing, caused $2.9 billion in US losses in 2023 according to the FBI, with average losses of $125,000 per incident. Ransomware is the second most common and most financially damaging — average ransom demand in 2025 was $2.73 million, and total recovery costs (including downtime and forensics) often exceed the ransom itself. The good news: multi-factor authentication stops 99%+ of both phishing and credential-based attacks.
- What is the 3-2-1 backup rule?
- Keep 3 copies of your data, on 2 different types of media, with 1 copy stored offsite. Example: working files on your computer (copy 1) + daily backup to an external hard drive on a different network (copy 2) + daily cloud backup to Backblaze, Acronis, or Veeam (copy 3, offsite). The offsite cloud copy is your ransomware recovery plan — if ransomware encrypts your local files and local backup drive, the properly configured cloud backup can restore everything. Test your backups monthly by actually performing a restore — a backup you've never restored is a backup you can't rely on.
- Does cyber liability insurance cover ransomware?
- Most cyber liability policies cover ransomware through: ransom payment (typically subject to a sub-limit, with a breach coach to negotiate the payment down), data recovery and restoration costs, business interruption for the downtime period, and incident response (forensics). However, coverage increasingly requires that reasonable security controls were in place at the time — particularly MFA. Many insurers now require MFA as a coverage prerequisite; lack of MFA can void claims or result in significant coverage reduction. Always review your specific policy's conditions and exclusions before a claim, not after.
- What free cybersecurity resources are available for small businesses?
- Free resources: CISA (cisa.gov/small-business) offers free vulnerability assessments and guides. NIST's Small Business Cybersecurity Corner provides a simplified version of the NIST Cybersecurity Framework. SBA (sba.gov/managing-business/cybersecurity) offers free online courses and webinars. FTC (ftc.gov/tips-advice/business-center/cybersecurity) offers short, practical attack-specific guides and employee training materials. Cloudflare Gateway offers free DNS filtering. Bitwarden offers a free tier for password management. Google Workspace accounts include free phishing simulation tools.