SMBs with under 250 employees now account for 63% of all data breaches - more than enterprises by a factor of four. The reason is rarely sophisticated. It is usually one account, one click, and no one whose job it was to notice.
In March 2026, Proton published the first major update to its Data Breach Observatory, covering breach data traded across dark web markets throughout 2025 and into early 2026. The numbers landed differently than the usual enterprise headlines.
Small and medium businesses - those with between 1 and 249 employees - accounted for 63% of all breaches recorded. Enterprises with more than 1,000 employees accounted for 14%. The gap is not a rounding error. It reflects something structural about how smaller businesses operate.
Why small businesses are the primary target
The economics are straightforward. Attackers are not choosing small businesses despite their size. They are choosing them because of it.
SMBs run the same Microsoft 365 tenants, the same cloud storage, the same remote access tools as the companies they supply. But they typically have no one watching the logs, no enforced multi-factor authentication, and no patching discipline. The same vulnerability that takes an enterprise security team four days to close stays open in a small business for months.
Ransomware gangs confirmed this shift in Q2 2026. Analysis of more than 200 ransomware leak sites found that companies with fewer than 200 employees and under $25 million in revenue were the most-attacked segment - 769 confirmed US victims in a single quarter.
The single account problem
68% of SMB phishing breaches start with a single untrained employee. Not a system vulnerability. Not a sophisticated zero-day. One person clicking one link, or one password reused across one too many services.
The pattern repeats because of how small businesses are structured. The founder or owner is typically managing cybersecurity the same way they manage everything else - personally, reactively, and between other things. 84% of SMB owners report self-managing their cybersecurity. That means the person approving invoices, interviewing candidates, and chasing late payments is also the person who set up the email system three years ago and has not reviewed access permissions since.
When that one account gets compromised, there is no containment layer underneath it.
What the bill actually looks like
Enterprise breach coverage focuses on regulatory fines and remediation costs spread across legal departments and security teams. For a business under 50 people, the arithmetic is different.
IBM's 2026 data puts the average US breach cost at $10.22 million - a significant event for any organization. The equivalent figure for small businesses runs closer to $1.6 million. That number sounds smaller. For a business running on tight margins, it represents payroll, the line of credit, and years of accumulated margin in a single incident. 60% of small businesses that suffer a significant cyberattack close within six months.
The breach does not arrive as a fine from a regulator. It arrives as system downtime, customer notification obligations, forensic investigation costs, and the permanent loss of accounts that walked out the door when trust did.
Getting out of the loop
The Proton analysis recommended multi-factor authentication across all accounts, strong password policies, and employee training. These are correct. They are also the kind of recommendations that get added to a list and never implemented, because the founder is the one who would need to enforce them, and the founder is already the bottleneck for twelve other things.
The actual exit from this pattern is not more security awareness. It is removing the founder from the loop for the decisions that create exposure in the first place. Access reviews, offboarding checklists, authentication enforcement - these are not tasks that require judgment. They are tasks that require a process that runs without someone having to remember to run it.
A business that has documented who has access to what, and has a process that removes access when someone leaves, has already closed the attack surface that accounts for the majority of SMB breaches. That is not a security program. It is an operations discipline that happens to make the business harder to breach.
Photo by Towfiqu barbhuiya on Unsplash. Free to use under the Unsplash License.