Small and medium-sized businesses like to think of cybersecurity as an enterprise problem—something for companies with dedicated SOCs, seven-figure security budgets, and rooms full of analysts. The 2026 Small Business Cybersecurity Awareness & Practices Survey, released by the National Cybersecurity Alliance (NCA) in partnership with U.S. CISA, tells a different story.
Drawing on responses from 1,000 SMB leaders across 10 industries—from two-person shops to mid-market companies with a thousand employees—the survey paints a picture of a segment that is engaged, resourced with basic tools, and dangerously overconfident about what those tools actually protect against.
The report frames its findings around four tensions: confidence that outpaces readiness, security tools that are adopted but not operationalized, AI that's been embraced faster than it's been governed, and a workforce that wants training but doesn't have a clear roadmap to get it. None of these are failures of intent; they're failures of infrastructure, guidance, and prioritization. And for SMBs operating with a fraction of enterprise resources, that distinction matters enormously.
The most unsettling number in the report isn't the breach rate—it's the uncertainty around it. A combined 56.1% of SMBs could not confirm a clean security record over the past 12 months: 50.5% reported a confirmed or suspected incident, and another 5.6% simply didn't know whether they'd been breached at all. That last figure is the real story. For a large share of small businesses, the risk isn't just that an attacker gets in—it's that nobody would necessarily notice if they did.
That blind spot tracks closely with resourcing. Detecting an intrusion requires logging, monitoring, and someone with the time to review alerts—infrastructure that's often the first thing cut when a business is deciding where to spend a limited IT budget. Unsurprisingly, incidence rates were highest in sectors that are both attractive targets and heavily software-dependent: technology, software, and telecom organizations reported the highest rate of confirmed, suspected, or uncertain incidents at 76.4%, followed by financial services and insurance (67.1%), healthcare (58.2%), and manufacturing (58.1%).
The confidence paradox
Here's where the report gets uncomfortable. Despite nearly three-quarters of leaders (72.3%) saying their cyber risk has increased or stayed the same over the past year, 86.3% still rate their confidence in managing that risk as medium to very high, and 58.8% say they're highly confident they could recover quickly from being knocked offline for a day or more.
That gap between perceived and actual readiness is, in the report's own words, one of the most consequential findings in the survey—and it's easy to see why. Confidence that isn't backed by tested capability doesn't just fail to help during an incident; it actively works against preparedness by removing the urgency to invest in it. A leadership team that feels secure has little incentive to fund the unglamorous work of logging, tabletop exercises, or backup testing.
Tools without practices: the maturity gap
Perhaps the clearest illustration of that gap shows up in the survey's security-control data. SMBs have largely done the easy part—adopting tools—but not the harder part of configuring and enforcing them.
-
86.8% of organizations have implemented multi-factor authentication, but only 51.1% require it across all key business accounts. More than a third (35.7%) only require it for "some" accounts—leaving exactly the kind of inconsistent coverage that attackers use to find a path of least resistance.
-
88.4% of businesses have backups, but only 61.4% have actually tested them. That means more than a quarter of the SMB market is relying on backups they have never verified will actually restore their data—a fact many won't discover until they're mid-ransomware-incident and it's too late to do anything about it.
-
Only 23.7% of organizations review cybersecurity as a business risk monthly—the report's benchmark for the ideal cadence. The plurality (32.1%) default to quarterly reviews, and nearly 38% evaluate security only "sometimes," "rarely," or "never," suggesting that for a large share of the market, security is still a periodic checkbox rather than a continuous operating concern.
The pattern here isn't a lack of investment—it's a lack of operationalization. Buying MFA and buying backup software are both budget-line decisions a single IT lead or outsourced provider can make in an afternoon. Enforcing MFA everywhere, testing backups on a schedule, and reviewing risk monthly are ongoing practices that require sustained attention—exactly the resource SMBs have the least of.
If the security-tool data show a maturity gap, the AI data show an outright governance vacuum. AI use among SMBs has reached 87.3%, driven mostly by the desire to save time or automate routine work (cited by 49.1% of respondents). But only 45.6% of organizations have implemented formal guidelines for how AI should be used, meaning more than half the market has employees making real-time decisions about what data goes into a prompt with no policy to guide them.
The report's segmentation by company size adds useful nuance here. Smaller firms adopt AI more cautiously overall—20% of companies under 50 employees report no AI adoption at all, versus just 2.3% of the largest firms surveyed—but that caution doesn't necessarily translate to governance. It just means fewer employees are exposed to the risk today, not that the risk is managed. And general-purpose consumer tools like ChatGPT, Google Gemini, and Microsoft Copilot dominate usage across every size band, which matters because free consumer-tier AI tools typically come with weaker data-handling guarantees than their business or enterprise counterparts.
This is precisely the kind of risk that compounds quietly. An employee pasting a customer list or a contract into a free AI tool to summarize it isn't a dramatic breach—it's an invisible one, with no alert, no log, and no way to know it happened unless a policy existed to prevent it in the first place.
What this means for the one- or two-person security team
The survey's leadership demographics are worth sitting with: every respondent held decision-making authority, and this ranged from C-suite executives at micro-businesses down to managers at mid-market companies. At a huge share of the organizations represented in this report, "the security team" is not a team; it's one IT generalist, an outsourced MSP, or an owner who also handles security between other responsibilities.
For that person, the findings translate into a fairly specific set of priorities, roughly in this order.
-
Close the enforcement gap on tools you already own before buying new ones. If MFA is deployed but not required everywhere, or backups exist but have never been restored in a test, those are zero-cost fixes—a policy change and a calendar reminder, not a new line item.
-
Build a lightweight AI acceptable use policy now, even a one-pager. The report's own recommendation—write down what can never go into a public AI tool (customer data, PII, financial records, trade secrets), and specify which tools are approved—is achievable in an afternoon and closes the single largest AI-related exposure without slowing anyone down.
-
Put a recurring risk review on the calendar, even quarterly. The data shows breached organizations review risk monthly at nearly double the rate of unbreached ones (31.5% vs. 19.8%)—a habit worth building before an incident forces it, not after.
-
Write down an incident response plan before you need one. The gap here is stark: 74.9% of breached organizations have a documented, followed response plan, compared with just 51.5% of organizations that haven't been breached—and unbreached organizations are five times more likely to have no plan at all (30.3% vs. 5.9%). A plan doesn't require a large team to write; it requires an hour and a template, several of which are freely available from CISA and the NCA.
The throughline across all four: a lean security function doesn't need more tools. It needs to spend its limited time closing the gap between what's already been purchased and what's actually enforced, tested, or documented. That's a fundamentally different (and cheaper) problem than the one most vendor pitches are selling.
Lessons for larger enterprises, too
It's tempting for security leaders at well-resourced enterprises to read this report as a small-business problem. The uncomfortable truth is that the underlying pattern—tools adopted, practices not operationalized—shows up at every size of organization, just with more zeros attached to the tools.
A few findings apply well beyond the SMB segment.
-
The confidence paradox scales up. Large organizations with mature security programs are just as capable of mistaking tool ownership for risk reduction. A Fortune 500 company that has deployed MFA, EDR, and a SIEM but hasn't validated that those tools are configured correctly, monitored consistently, or tested under realistic conditions is exhibiting the same maturity gap this report documents at the SMB level—just with a bigger budget cushioning the blind spot.
-
The "breached organizations are better prepared" finding is a warning, not a comfort. The survey shows that breach victims consistently report stronger MFA enforcement, tested backups, documented incident response plans, and more frequent risk review than organizations that haven't been breached. That's true at every company size, and it means most organizations, regardless of resources, are still building real preparedness reactively rather than proactively. Enterprises that treat a near-miss or a peer company's breach as their forcing function are running the same experiment SMBs are, just with higher stakes.
-
AI governance lagging adoption is a universal-enterprise problem, not a small-business one. Larger SMBs in this survey (501–1,000 employees) actually show higher AI-driven customer service and innovation use cases than smaller firms, and layer AI more deeply into existing software—meaning the governance gap doesn't close as organizations scale, it just gets embedded more deeply into more workflows. Enterprise security and legal teams racing to keep AI acceptable-use policies current with Copilot, Gemini, and agentic tools rolling out across departments are fighting the exact same governance lag this report identifies among two-person shops—just at a scale where the blast radius of an ungoverned AI decision is considerably larger.
The 2026 Small Business Cybersecurity Awareness & Practices Survey doesn't describe a segment of the market that's ignoring cybersecurity. It describes a segment that has bought the tools, wants the training, and consistently underestimates how much distance remains between "we have MFA" and "we are protected." SMB leaders' own responses point to the fix: 55.7% say they're likely to participate in free or low-cost training in the next six months, and their top requests—employee training, leadership guidance on risk management, and incident response templates—are exactly the kind of low-cost, high-leverage resources that close the gap between adoption and operationalization.
A couple of sessions at SecureWorld conferences this fall will address how to manage cybersecurity at SMBs. At SecureWorld Seattle on November 5, Scott Benson, Director, Cybersecurity & Infrastructure, at Mud Bay, will present on "From Overwhelmed to AI-Enabled: Practical Cyber Defense for SMBs."
Here are Benson's thoughts on the survey results:
-
"Testing security controls is a critical and often overlooked component of any cybersecurity program. Test detections, validate controls and coverage, test your backups, and make sure they are immutable. This needs to be part of a regular routine, not a one-time event."
-
"I'm surprised at the expressed confidence of 86% of respondents in being able to manage current and increasing cybersecurity risks. MFA is being bypassed, vulnerability discovery has never been easier, social engineering is rampant. I expect most organizations to experience an increase in security incidents, with multiple simultaneous incidents becoming the norm. I don't think most SMBs are prepared for that."
-
"AI adoption rate in business with fewer than 50 employees is shockingly low. Is this due to lack of understanding of how to effectively leverage AI? The Four Best Practices for AI Adoption are outstanding recommendations for any business getting started with AI and governance. Adversaries are leveraging AI. Businesses that don't adopt AI to assist in their defensive capabilities are at a distinct disadvantage."
At SecureWorld Twin Cities on November 19, Tina Meeker, Deputy CISO at Old Republic, and Tony Taylor, CISO at Land O'Lakes, will talk about how they serve as vCISOs to help their co-op members and internal stakeholders with smaller cybersecurity teams. The presentation is titled, "Cybersecurity without the Fortune 500 Budget: 10 Essential Practices Every Small and Mid-Sized Business Must Master."

