Basic cybersecurity is the cheapest insurance your business never buys
Data breach costs just hit a record high, and small businesses take the worst of it because they carry the least protection. The fix isn't a security budget. It's four habits, built once, that run themselves.
A data breach now costs $4.99 million on average, a record high, up 12 percent in a single year (IBM, Cost of a Data Breach Report 2026). That number belongs to organizations of every size, and small businesses are not exempt from it. They are the more frequent target, and they carry the least cushion to absorb the hit. The fix is not a security budget. It is four habits, most of them free, that a lot of small operations still haven’t gotten around to.
The math you’re actually exposed to
Attackers do not size up a business before they hit it. They scan the internet for whatever is exposed, a weak password, an unpatched system, an account with no second factor, and act on whatever answers. That is the core finding behind the Verizon 2026 Data Breach Investigations Report: 31 percent of breaches now start with an exploited software vulnerability, which has overtaken stolen credentials as the single most common way attackers get in (Verizon, 2026 Data Breach Investigations Report). Ransomware shows up in 48 percent of all breaches tracked this year. Payouts are shrinking as more businesses refuse to pay, but the disruption still lands the same way: a locked system, a stalled week, customers you cannot reach.
When Verizon’s earlier reporting broke breach costs out by organization size, businesses under 500 employees landed in the $3.31 million range, up 13.4 percent from the year before (IBM, Cost of a Data Breach Report, 2023 data for organizations under 500 employees). Even the low end of that range is a bad year, and most small operations do not have a bad year built into the plan.
Where the risk is actually moving
The attacks are also getting faster and cheaper to run. “The cyber landscape has changed dramatically with the rapid adoption of artificial intelligence. In the frenzied race to harness the potential of AI, organizations often find themselves up against the clock, eager to deploy AI without first assessing their foundational cybersecurity measures,” said Limor Kessem, X-Force Cyber Crisis Management Global Lead at IBM (IBM Think, 2025). AI-driven attacks climbed 56 percent this year (IBM, Cost of a Data Breach Report 2026), and Verizon’s data shows the same shift in tactics: phishing attempts are moving from email to mobile, where click rates run 40 percent higher, because a text or a call is a lot harder to second-guess than an email at a desk.
None of this requires a bigger business to become a bigger target. It just requires an exposed login, an unpatched app, or a phone that answers the wrong text.
Four habits that cost almost nothing and close most of the gap
This is where the good news actually is. CISA and the SBA both publish the same short list of practical fixes, and none of them require a security hire (CISA, “Cyber Guidance for Small Businesses”; SBA, “Strengthen your cybersecurity”):
- Turn on multi-factor authentication everywhere it exists, starting with email and accounting software. Any MFA beats no MFA, and a passkey or authenticator app beats a text code.
- Keep software patched automatically. Most successful attacks exploit a fix that already existed and was never installed. Turning on auto-update is the cheapest security control you own.
- Back up your data, and actually test the restore. Plenty of businesses discover their backup was broken the same week they needed it. A backup nobody has restored is a hope, not a plan.
- Take admin rights off everyday accounts. The account you use to answer email should not also be able to install software. Separating the two stops a lot of malware before it starts.
Every one of those is a system, not a one-time task: something you configure once and it keeps working without you thinking about it again. That is the same principle behind every other operational fix worth making.
The Trade Script connection
This is the same instinct that shows up in the rest of the systems we build: get it right once, and it keeps protecting the business without needing daily attention. When we stand up a client’s website, booking flow, or automated outreach, MFA on every account, tested backups, and patched software are part of the build, not an afterthought bolted on later. It is a cheap add to work we are already doing, and it is a lot cheaper than explaining to customers why their information was exposed. A website and a social presence that bring in more business are only worth as much as the systems underneath them are worth trusting.
The takeaway
The businesses that get hurt worst by a breach are not the ones that got specifically targeted. They are the ones that left the easy locks unlocked. Pick the one habit above you haven’t done yet, most likely MFA on your email and your accounting software, and turn it on this week. It takes less time than the coffee break you’ll spend reading about the business that didn’t.
Sources
- Cost of a Data Breach Report 2026, IBM, 2026
- 2025 Cost of a Data Breach Report: Navigating the AI rush without sidelining security, Limor Kessem, IBM Think, 2025
- What Is the Average Data Breach Cost for Small Businesses?, citing IBM Cost of a Data Breach Report data for organizations under 500 employees, 2023
- 2026 Data Breach Investigations Report, Verizon, 2026
- Cyber Guidance for Small Businesses, CISA
- Strengthen your cybersecurity, U.S. Small Business Administration
