Menu
Business.com aims to help business owners make informed decisions to support and grow their companies. We research and recommend products and services suitable for various business types, investing thousands of hours each year in this process.
As a business, we need to generate revenue to sustain our content. We have financial relationships with some companies we cover, earning commissions when readers purchase from our partners or share information about their needs. These relationships do not dictate our advice and recommendations. Our editorial team independently evaluates and recommends products and services based on their research and expertise. Learn more about our process and partners here.
Secure your network and devices and prepare for the costs.
Cyberattacks on big corporations are certainly newsworthy. However, hackers frequently target small businesses in data breaches and other digital intrusions. Cybersecurity incidents can paralyze your business and destroy customer trust — and recovering can be expensive. To help prevent these devastating consequences, it’s crucial for businesses of all sizes to put cybersecurity safeguards in place.
Like many core business functions, cybersecurity incurs expenses. But how much should you budget for your company’s cyberdefenses? We’ll look at best practices for cybersecurity budget planning, outline cyberattack costs and share various types of cyberincidents to be aware of.
Mark Cunningham-Dickie, senior incident responder at Quorum, cautioned that cybersecurity risks affect businesses of all sizes — not just the major corporations. “While you do see a lot of big names on data leak sites, it’s not that there aren’t SMBs [small and medium-sized businesses] in among them,” Cunningham-Dickie explained. “It’s just that SMBs are more likely to pay ransoms because they don’t have the reputation, the insurance, the war chests, legal advice and backing, the recovery mechanisms and, potentially, the regulatory oversight that the big players do.”
Indeed, small businesses are increasingly targeted. According to Netwrix Research Lab’s 2023 Hybrid Security Trends Report, 68 percent of all organizations surveyed — large and small — had experienced a cyberattack in the past 12 months. According to Tripwire’s recent Business Impact Report, 73 percent of small business respondents reported experiencing data breaches or cyberattacks within the previous year.
Here are some benefits of establishing a cybersecurity budget for your small business:
The cybersecurity arena is massive. As you build your budget, consider prioritizing the following investment areas:
If you’re not convinced that your company needs a cybersecurity budget, consider that your business won’t be the only victim of a cyberattack; your employees, customers and strategic partners will also experience the fallout. The only way to prevent an attack is to strengthen your understanding, posture and defenses — a process that merits investment for every small business.
Cybersecurity spending is often tied to a business’s overall information technology (IT) budget, which takes into account the company’s size and IT infrastructure. According to the Spiceworks 2025 State of IT report, 64 percent of companies globally plan to increase their IT budgets for the following reasons:
According to the 2024 Security Budget Benchmark Report, businesses globally spend an average of 13.2 percent of their IT budgets on cybersecurity. For example, if a company pays $3,000 monthly to an IT-managed service provider to cover its IT needs, its cybersecurity budget would be about $396 per month.
However, according to Ted Miracco, CEO of Approov, the exact percentage of total IT spending on cybersecurity will vary widely by industry, company size, compliance mandates, data sensitivity and more. “Different industries have varying benchmarks for cybersecurity spending, typically between 7 percent and 20 percent of the overall IT budget,” Miracco explained.
Miracco noted that defense contractors, technology companies and healthcare businesses tend to spend more of their IT budgets on cybersecurity, while manufacturing and retail industries spend less, averaging about 10 percent.
“The IT budget really should be a function of the actual data being stored or processed,” Miracco advised. “For example, financial, healthcare and personal data poses greater risks than other forms of data, and these data sources are most likely to be attacked by ransomware groups and/or nation-states.”
Here are a few tips for deciding on your cybersecurity spending:
Cyberattacks cause significant damage and expense. According to IBM’s 2024 Cost of a Data Breach report, the global average cost of a data breach increased to $4.88 million, up 10 percent from 2023; the average cost per breached record was $173.
The true cost of a data breach isn’t always immediately known, particularly for small businesses.
Potential direct costs include the following:
Potential indirect costs include the following:
Taking crucial cybersecurity steps can mitigate the damage and reduce the costs resulting from a data breach. These steps include having an incident response team and cybersecurity plan in place, using encryption, conducting employee training and securing cyber insurance.
The concept of “cyberresilience” is growing in importance. Given the potential expenses and negative impacts of a data breach on a small business, any budget you dedicate to improving your company’s cybersecurity posture is well spent.
Your in-house IT team or outsourced IT partner should stay vigilant about the following cyberattack types. Some are obvious, while others are more overlooked attack vectors.
A DoS attack is designed to overwhelm a machine or network’s resources so the intended users cannot access the system. It is executed by bombarding the specified target with a flood of traffic or information to crash the system.
Unlike other types of cyberrisks, DoS attacks do not directly benefit the attacker. For example, a competitor might initiate a DoS attack to disrupt your website and gain an advantage or the attack could serve as a diversion for a larger cyberthreat, such as ransomware deployment.
A DDoS attack is the same as a DoS attack but is launched from multiple host computers. This type of attack overwhelms a company’s website or online service, causing it to malfunction or become inaccessible.
There are different types of DoS and DDoS attacks, but here are the most common — and how to prevent them:
Phishing attacks are a common cyberthreat in which attackers send emails that appear to be from trusted sources. The goal is to gain personal information, like usernames and passwords or to cause someone to take a specific action, such as downloading malware onto their machine.
A spear-phishing attack is similar, but instead of casting a wide net, attackers target individuals and take time to research victims and create personal, relevant messages.
The best way to prevent phishing attacks within your company is to train your staff on what to look for and how to spot risky emails and links.
As the name implies, an MITM attack occurs when attackers insert themselves between a user and the services they interact with. Common types of MITM attacks include session hijacking, IP spoofing, DNS spoofing and replay attacks.
No single method can prevent all types of MITM attacks. However, encryption and digital certificates help prevent attackers from inserting themselves between users and servers.
Additional safeguards include:
These attacks spread malware far and wide. An attacker looks for insecure websites to hack and plants malicious code throughout the site. When a user visits a hacked website, they may unintentionally download and install malicious code or be redirected to a site created by the attacker. Unlike other types of cyberthreats, a drive-by download doesn’t require the user to take an action, like clicking a button or opening an email, to be infected. They merely have to visit a website.
The best way to prevent this type of attack is to train your staff to keep their internet browsers and operating systems updated and avoid insecure websites. If your business manages its own websites, you should also implement robust website security practices, including regular updates and vulnerability assessments.
Obtaining a user’s password is among the oldest, most common and most effective cyberattack forms. Hackers can steal passwords in several ways:
To protect your company from password attacks:
Cybersecurity is no longer a “nice to have” — it’s a must-have item for businesses and a necessary budget item. A comprehensive cybersecurity program doesn’t have to cost a lot, but it requires prioritization and commitment from leadership, IT and other employees.
No matter how much you dedicate to cybersecurity, however, there are no 100-percent protection guarantees. Your best bet is to deploy a multifaceted, ongoing cybersecurity program using a combination of resources, testing, training and time.
Cunningham-Dickie emphasized that proactive cybersecurity efforts are key to reducing risks and deterring attackers. “The earlier you detect a threat and, the better you are at countering attacks, the less likely opportunistic attackers are going to have an impact on you,” Cunningham-Dickie explained. “They will just move on to the next potential victim.”
The cost of a comprehensive cybersecurity program is a small price to pay for the peace of mind you’ll enjoy knowing that your company is better protected.
Jennifer Dublino contributed to this article.