Skip to main content
Cyber Resilience7 min read

Cybersecurity for Small Businesses: The Layered Defence That Actually Works

"The most common attacks on small businesses in 2026 - phishing, ransomware, business email compromise - aren't stopped by antivirus alone. They're stopped by three layers of defence, each with a predictable cost."

Author

Lior Refael

Published

Jan 20, 2026

Back to Articles

The most common attacks hitting small businesses right now

The threats facing small businesses have changed. Attackers don't need to be sophisticated - they use automated tools that scan thousands of businesses a day looking for the same predictable gaps: weak passwords, unpatched software, no MFA, no email authentication.

The attacks actually hitting businesses in Israel and across Europe in 2026:

The most common attacks hitting small businesses right now

Phishing

How it starts
Fake email tricks employee into entering credentials
Typical cost to an SMB
€1,000-€15,000 in recovery and lost time
Prevented by
MFA + email filtering

Ransomware

How it starts
Encrypts your files; demands payment to unlock
Typical cost to an SMB
€5,000-€50,000+ in recovery, downtime, ransom
Prevented by
Endpoint protection + immutable backup

Business email compromise

How it starts
Attacker impersonates the CEO or a supplier to authorise a transfer
Typical cost to an SMB
€3,000-€100,000+ (often not recoverable)
Prevented by
DMARC + employee training

Credential stuffing

How it starts
Leaked password from another breach used to access your systems
Typical cost to an SMB
Variable; leads to other attacks
Prevented by
Password manager + MFA

None of these require a sophisticated attacker. They're automated. A 10-person accountancy firm in Berlin has the same exposure as a 10-person law firm in Tel Aviv.

If you take one number from this article, take this one: 96% of ransomware victims in Verizon's 2026 dataset were small and medium businesses[1]. And ransomware is not receding - it has grown as a share of all breaches in each of the last three reporting years.

Share of breaches involving ransomware, by DBIR edition

Percentage of analysed breaches

2024 edition
2025 edition
2026 edition

Ransomware moved from a third of breaches to nearly half in two reporting years. In the same 2026 dataset, 96% of ransomware victims were small and medium businesses.

Show the data
Column chart showing ransomware present in 32% of breaches in the 2024 DBIR, 44% in the 2025 edition and 48% in the 2026 edition - a rising share over three consecutive reports.
Percentage of analysed breachesBreaches involving ransomware
2024 edition32%
2025 edition44%
2026 edition48%

Source: Verizon Business, 2026 Data Breach Investigations Report (2026)

The delivery method has shifted, though, and that matters for where you spend. In Sophos's 2026 survey, malicious email and phishing together accounted for around half of all ransomware incidents[2] - which is why the work below starts with identity and email rather than with anti-malware.

The three layers that do the work

The layering below is not our invention. It is the same baseline that CISA publishes for small businesses in Cyber Essentials[3] and that the Israel National Cyber Directorate sets out in its defence methodology for organisations[4] - identity first, then devices, then recoverable data.

Layer 1: Identity and access control

This is the most important layer, and it is where the evidence is strongest. Microsoft's measurement study of Entra accounts found MFA reduced the risk of compromise by 99.22% across the population, and by 98.56% even for accounts whose password had already leaked[5]. Over 97% of identity attacks Microsoft observes are password attacks[6] - which is precisely the category MFA removes.

  • MFA on every account - Google Workspace and Microsoft 365 both include MFA at no extra cost. Enable it for everyone, unconditionally.
  • A business password manager - 1Password Business or equivalent. Stops credential reuse and makes phishing attacks harder to exploit.
  • Conditional Access - blocks login attempts from unrecognised devices or locations, even with valid credentials.

Layer 2: Endpoint protection

Every device that accesses your data is a potential entry point.

  • Microsoft Defender for Business - included in M365 Business Premium. Monitors device behaviour, blocks malicious files, and alerts on suspicious activity.
  • Intune device management - ensures every device is encrypted, updated, and compliant before it can access company data.
  • Patch management - unpatched software is the second most common attack vector. Intune pushes updates automatically.

Layer 3: The backup safety net

If layers 1 and 2 fail (and occasionally they will), a tested backup is what separates a bad day from a business-ending event.

  • Acronis Cyber Protect with immutable storage - ransomware cannot modify or delete these backups even with admin access.
  • Tested restores - a backup you've never tested is not a backup. Quarterly restore tests confirm you can actually recover.
  • Off-site replication - data stored in multiple physical locations means a single incident (fire, theft, ransomware) cannot destroy everything.

What this costs for a 10-person business

What this costs for a 10-person business

Identity

Tools
M365 Business Premium (includes MFA + Conditional Access) + 1Password
Typical monthly cost
€280-€350

Endpoint

Tools
Included in M365 Business Premium (Defender + Intune)
Typical monthly cost
-

Backup

Tools
Acronis Cyber Protect
Typical monthly cost
€100-€200

Total

Tools
Typical monthly cost
€380-€550/month

This is not a marketing estimate - these are the actual current pricing ranges for a 10-person business in 2026. The loss figures in the table above are not scare tactics either: IBM's Cost of a Data Breach study puts the global average breach cost in the millions, with the smallest organisations in the study still averaging six figures[7], and the FBI's IC3 reporting shows business email compromise losses concentrated in exactly the five- and six-figure band[8]. A €5,000-€50,000 recovery bill for a 10-person firm is the optimistic end of that distribution.

Email authentication: the one technical fix most SMBs haven't done

SPF, DKIM, and DMARC are three DNS records that authenticate your email. Without them, anyone can send an email that appears to come from your domain - which is exactly how business email compromise works.

Setting these up takes about 2 hours. Your email provider's documentation covers the exact steps. This is one of the highest-ROI security improvements a small business can make, and it's free.

Questions we get asked

Sources

Every figure in this article traces back to a named source. Where we quote our own numbers, they come from work we have done with small businesses in Israel and across Europe, and we say so.

  1. 2026 Data Breach Investigations ReportVerizon Business · 2026Ransomware present in 48% of breaches; 96% of ransomware victims were SMBs; human element in 62% of breaches. (opens in a new tab)
  2. The State of Ransomware 2026Sophos · 2026Malicious email and phishing drive roughly half of ransomware incidents; mean recovery cost of USD 1.7M excluding ransom. (opens in a new tab)
  3. Cyber Essentials for Small BusinessesCISA (US Cybersecurity & Infrastructure Security Agency) · 2025Government baseline control set for small organisations: identity, devices, data recovery. (opens in a new tab)
  4. Cyber Defense Methodology for an OrganizationIsrael National Cyber Directorate (INCD) · 2025Israeli national guidance on layered organisational cyber defence for smaller organisations. (opens in a new tab)
  5. How effective is multifactor authentication at deterring cyberattacks?Microsoft · 2023MFA reduced compromise risk by 99.22%, and by 98.56% where the password had already leaked. (opens in a new tab)
  6. Microsoft Digital Defense Report 2025Microsoft · Oct 2025Identity attacks up 32% in H1 2025; over 97% of identity attacks are password attacks; AI-generated phishing markedly more effective. (opens in a new tab)
  7. Cost of a Data Breach ReportIBM Security / Ponemon Institute · 2025Measured breach cost distribution used to ground the loss ranges quoted for small businesses. (opens in a new tab)
  8. Internet Crime ReportFBI Internet Crime Complaint Center (IC3) · 2025Reported loss bands for business email compromise and related SMB-facing fraud. (opens in a new tab)
  9. ENISA Threat LandscapeEuropean Union Agency for Cybersecurity (ENISA) · 2025European threat picture and prime threats affecting small organisations. (opens in a new tab)
  10. Small Business Guide: Cyber SecurityUK National Cyber Security Centre · 2025The baseline control set a small organisation should implement first, from a national authority. (opens in a new tab)

Figures last checked 28 July 2026

Not sure how exposed your business actually is?

Book a free 30-minute security review. We'll check your MFA status, email authentication, and backup setup - and tell you exactly what's missing.