Cybersecurity Essentials for Business Owners
A 2026 guide to the threats that actually cause breaches, the controls that stop them, and how to prioritize when you don't have a security team.
Most cybersecurity advice written for small businesses is several years out of date, and the parts that aged badly are the parts business owners rely on most. The way attackers get in has changed. The way ransomware makes money has changed. The controls that insurers and customers demand have changed.
This guide is SOMOS Technology's plain-language briefing for owners and executives of small and mid-sized businesses. It is built on the 2026 Verizon Data Breach Investigations Report, IBM's 2026 Cost of a Data Breach Report, the FBI's 2025 Internet Crime Report, CIS Critical Security Controls v8.1, and NIST Cybersecurity Framework 2.0. Every statistic is sourced.
What changed between 2021 and 2026
If you read a cybersecurity guide five years ago, most of its advice is still correct. Several of its core assumptions are not.
ThenNow
Stolen passwords were the leading way in.Exploiting unpatched software is, at 31% of breaches — ahead of credential abuse at 13% for the first time.
Phishing emails gave themselves away.AI writes them. Voice cloning calls your finance team as the CEO. One in four malicious breaches is now AI-enabled.
Ransomware encrypted your files.It steals the data first, threatens publication, contacts your customers — and hunts your backups before anything else.
Your risk stopped at your own network.48% of breaches involve a third party. Your vendors' security is now your security.
MFA was considered enough.Stolen session tokens and help-desk impersonation walk straight past it. Phishing-resistant MFA is the new baseline.
Antivirus caught the malware.Attackers increasingly bring none — they use your own admin tools. 60% of breaches now follow this pattern.
What has not changed: the fundamentals still decide outcomes. Patch quickly. Enforce strong authentication everywhere, including service accounts. Keep an isolated backup and test it. Know what you own. Watch your logs. Have a plan and rehearse it. Nearly every headline breach of the last two years failed at one of these.
The numbers that matter
How attackers get in
-
31% — vulnerability exploitation, now the leading initial access vector
-
16% — social engineering
-
13% — credential abuse (though it appears in 39% of full attack chains)
These do not total 100%: many breaches have no single determinable entry point.
What it costs
-
$4.99M — global average cost of a data breach, a record high and up 12% in one year
-
$11.5M — US average, more than double the global figure
-
$6M — average cost of an AI-enabled breach, roughly $1M above average
-
$20.9B — reported to the FBI across more than one million complaints in 2025, up 26%
-
$3.04B — business email compromise losses alone
-
~$2M — average saving for organizations using security AI and automation, who also contain breaches about two months faster
Why small businesses are hit hardest
Ransomware appeared in 88% of small-business breaches compared with 39% at large organizations. A large company absorbs a breach. A 30-person firm often does not — the loss of operations, customer trust and cash flow arrives all at once.
Only 37% of breached organizations encrypted sensitive data both at rest and in transit — a control that is largely free and already built into software you own.
The threat landscape in 2026
AI-generated phishing and spear phishing
Generative AI removes every tell staff were trained to spot: broken grammar, odd phrasing, generic greetings. Spear phishing was once reserved for high-value targets because research took hours per message. That cost has collapsed, and the economics that protected small businesses no longer apply. Mobile-centric lures — voice calls and SMS — now succeed at rates about 40% higher than email.
Business email compromise
BEC involves no malware. An attacker gets into or convincingly imitates a mailbox, watches for weeks, learns how you pay your bills, then intervenes with new wire instructions inside a real conversation thread. It clears every technical filter you own. The defenses are unglamorous: enforced MFA, out-of-band verbal confirmation of payment changes, and DMARC at enforcement.
Deepfakes, vishing and help-desk impersonation
Voice cloning needs only seconds of reference audio. Attackers call finance staff as the CEO and call IT help desks posing as a locked-out employee needing an MFA reset. Identity verification at the help desk — scripted, evidence-based, and immune to urgency — is now a frontline control.
Ransomware and multi-point extortion
Modern crews exfiltrate first, then encrypt, then threaten to publish. Some skip encryption entirely and extort on stolen data, which means a clean backup no longer guarantees a clean outcome. Ransomware-as-a-service has lowered the skill floor dramatically.
Stolen credentials, infostealers and session hijacking
Infostealer malware runs briefly on a laptop — often a personal one — harvests every saved password, cookie and session token, and sells the bundle within hours. A valid session cookie lets an attacker walk past a correct password and a correct MFA prompt. Half of ransomware victims had a credential-theft event in the 95 days before the attack.
Vulnerability exploitation and edge devices
Attackers now move from published vulnerability to working exploit in hours rather than months, while most businesses patch monthly or quarterly. Internet-facing edge devices — VPN concentrators, firewalls, remote access gateways — are the favorite target. Only 26% of vulnerabilities on the CISA Known Exploited Vulnerabilities list were fully remediated last year, down from 38%.
Third-party and supply chain compromise
Your security posture now includes everyone who holds your data or connects to your systems. Root causes are mundane: missing MFA on a shared tenancy, a vendor account with more access than the engagement required, an integration token never revoked after a project ended.
Cloud and SaaS identity attacks
Most small businesses no longer have a network worth attacking — they have a Microsoft 365 tenancy and two dozen SaaS applications. The perimeter is the identity, and the attack surface is every consent grant, OAuth token, guest account and legacy protocol still enabled.
Shadow AI
Staff paste contracts, customer records and financial data into AI tools that were never reviewed or approved. One in five organizations reported a breach targeting an AI model or application, with compromised APIs and plug-ins (27%) and cloud misconfigurations (27%) the leading causes. An acceptable-use policy, a short list of sanctioned tools, and access controls handle most of this risk — but only if they exist beforehand.
The frameworks: NIST CSF 2.0 and CIS Controls v8.1
Two frameworks matter for most businesses, and they work together rather than competing.
NIST Cybersecurity Framework 2.0 organizes security into six functions: Govern, Identify, Protect, Detect, Respond, Recover. Govern was added in the 2.0 release and reflects an important shift — cybersecurity is a business governance decision, not an IT task.
CIS Critical Security Controls v8.1 tells you what to actually do. It contains 18 controls and 153 specific safeguards, prioritized by defensive value.
Implementation Groups: where to start
Not every business can implement 153 safeguards. CIS sorts them into three groups:
-
IG1 — Essential Cyber Hygiene (56 safeguards). The realistic first-year target for most small and mid-sized businesses, and the defenses that stop the most common attacks.
-
IG2 (74 additional). For organizations with multiple departments, regulated data and greater risk exposure.
-
IG3 (23 additional). For enterprises with dedicated security staff facing sophisticated adversaries.
Each group includes everything below it. Start with IG1 and finish it before moving on.
The 18 CIS Controls
#ControlIG1 safeguards
01Inventory and Control of Enterprise Assets2 of 5
02Inventory and Control of Software Assets3 of 7
03Data Protection6 of 14
04Secure Configuration of Enterprise Assets and Software7 of 12
05Account Management4 of 6
06Access Control Management5 of 8
07Continuous Vulnerability Management4 of 7
08Audit Log Management3 of 12
09Email and Web Browser Protections2 of 7
10Malware Defenses3 of 7
11Data Recovery4 of 5
12Network Infrastructure Management1 of 8
13Network Monitoring and Defense0 of 11
14Security Awareness and Skills Training8 of 9
15Service Provider Management1 of 7
16Application Software Security0 of 14
17Incident Response Management3 of 9
18Penetration Testing0 of 5
Compliance is no longer optional
Security used to be discretionary for small businesses. Increasingly it is not — not because a regulator is watching, but because your insurer, your bank and your largest customers ask for evidence before they will do business with you.
CMMC: the near-term deadline
If you are anywhere in the defense supply chain, this is the most time-sensitive item in this guide. The DFARS acquisition rule took effect 10 November 2025, making Cybersecurity Maturity Model Certification a condition of contract award. Phase 2 begins 10 November 2026, when third-party C3PAO certification becomes the standard for Level 2 on new and renewing contracts handling Controlled Unclassified Information.
Readiness typically takes 9 to 12 months. It is built on NIST SP 800-171 — which CIS IG1 and IG2 work already covers a meaningful share of. Waiting until a solicitation lands is waiting too long.
Cyber insurance
Insurers now require attested evidence of MFA, endpoint detection and response, immutable and tested backups, security awareness training, and an incident response plan. Inaccurate attestations are grounds for denial of a claim.
Other obligations
-
PCI DSS 4.0 — fully in force if you take card payments
-
HIPAA — continued scrutiny on risk analysis, encryption and access controls
-
California CCPA/CPRA — breach notification duties, data minimization, consumer rights
-
Customer contracts — often the strictest requirement you face, arriving via vendor security questionnaires
Your first 90 days
Days 1–30: Find out where you stand
-
Run asset and software discovery; reconcile against what you believe you own
-
Audit every account for MFA, including admin, service and vendor accounts
-
Confirm backups exist, are isolated, and can actually be restored
-
Identify internet-facing devices and check firmware and patch status
-
List every vendor holding your data or connecting to your systems
Days 31–60: Close the highest-risk gaps
-
Enforce phishing-resistant MFA with no exceptions
-
Turn on automated OS and third-party application patching
-
Deploy managed endpoint detection and response with 24/7 review
-
Implement an immutable backup copy and schedule restore tests
-
Set DMARC to enforcement and enable DNS-layer filtering
Days 61–90: Make it durable
-
Launch continuous security awareness training with realistic simulations
-
Write the incident response plan; keep an offline copy; name decision-makers
-
Centralize logging with retention that meets your obligations
-
Separate administrator accounts from daily-use accounts
-
Run a tabletop exercise with your leadership team
Six questions worth answering today
The gaps that show up in breach post-mortems are rarely exotic. If you cannot answer one of these confidently, that is not a crisis — it is simply where to start.
-
Could you produce a current list of every device and application on your network today? (CIS Controls 1 & 2)
-
Is multi-factor authentication enforced on every account, including service and admin accounts? (CIS Control 6)
-
Has anyone restored from backup in the last twelve months to prove it works? (CIS Control 11)
-
Do you have a written incident response plan, and does anyone have a copy offline? (CIS Control 17)
-
Is someone reviewing security alerts outside business hours? (CIS Control 13)
-
Do you know which vendors hold your data or connect into your systems? (CIS Control 15)
Frequently asked questions
How much does a data breach cost a small business?
The global average is $4.99 million and the US average is $11.5 million, but those figures are driven by large organizations. For a small business the proportional impact is worse rather than smaller: operational downtime, customer loss and cash flow disruption arrive simultaneously, and ransomware appears in 88% of small-business breaches.
What are the CIS Controls?
The CIS Critical Security Controls are a prioritized set of 18 controls and 153 specific safeguards published by the Center for Internet Security. Unlike broader frameworks that describe what to protect, they specify measurable actions in the order that delivers the most defensive value per unit of effort.
What is CIS Implementation Group 1?
IG1 is the 56 safeguards that CIS defines as essential cyber hygiene — the foundational defenses every organization should have regardless of size. It is the realistic first-year target for most small and mid-sized businesses.
When is the CMMC deadline?
The DFARS rule making CMMC a condition of contract award took effect 10 November 2025. Phase 2 begins 10 November 2026, when third-party certification becomes the standard for Level 2 contracts involving Controlled Unclassified Information. Readiness typically takes 9 to 12 months.
Does a small business really need managed cybersecurity?
CIS Control 13 — network monitoring and defense — contains no IG1 safeguards, which reflects reality: continuous monitoring requires either a security team or a partner. Most small businesses cannot staff a 24/7 security operation, which is precisely why managed detection and response exists.
Book a free Future Proof Audit
SOMOS Technology is a full-spectrum managed IT and cybersecurity provider based in Santa Clarita, California, serving small and mid-sized businesses across the United States. We are not here to sell you every control in this guide — we are here to work out which ones remove the most risk for your business, implement them properly, keep them working, and be the people you call when something happens.
We will review your environment against the CIS essential cyber hygiene safeguards and give you a prioritized, costed gap report you can keep, with no obligation.
Request your audit → | 661-467-0023
Sources: Verizon 2026 Data Breach Investigations Report; Verizon 2025 DBIR (small-business cohort); IBM Cost of a Data Breach Report 2026 (Ponemon Institute); FBI Internet Crime Complaint Center 2025 Annual Report; Center for Internet Security, CIS Critical Security Controls v8.1; NIST Cybersecurity Framework 2.0. CIS Controls® is a registered trademark of the Center for Internet Security, Inc. Control summaries here are SOMOS' own paraphrases; refer to the official CIS publication for authoritative text.

