Daytona Beach Area (386) 238-1200
|
Orlando Area (407) 513‐4711
|

The Cybersecurity Reality for SMBs

IT Issues? Let Vann Data Help
Get Help
Mon, Aug 03, 2026 at 5:30PM

The Cybersecurity Reality for SMBs

Global cybercrime is expected to cost $10.5 trillion annually by 2025, up from $3 trillion in 2015, according to Cybersecurity Ventures. To put it in perspective, if annual cybercrime were a country, it would have the third-largest gross domestic product (GDP) worldwide. Source: The World Economic Forum 16 Jan 2025

More and more recently I have been alarmed with the increase of the frequency, and sophistication of cybersecurity attacks. As someone who is responsible for a service desk that supports over 100 clients in the Daytona Beach area, I have a front row seat to this cybersecurity war. And let’s be very clear, we are at war. Non-stop. Every day

Some will say I’m being dramatic but let me give you a view into what I see on a regular basis. Today we had a call from a client who clicked on an email and was worried that maybe he shouldn’t have. Well, he was right. Malicious code was immediately loaded onto his computer.

Yesterday, we had 2 separate clients that opened an attachment that looked like it was a legitimate document that they get regularly. Well, it wasn’t. They both had rogue remote-control software installed, their task manager disabled, and their buttons to shutdown and restart their computer removed from their windows menu.

Last week we had 3 phishing incidents. The week before 2. We have had over 30 attacks in the last couple of months across 19 different clients-that represents almost 20% of our customer base. We are averaging 2-3 events a week and we are a small boutique MSP. Imagine what the large MSPs with hundreds of customers are seeing.

I have personally seen businesses lose hundreds of thousands of dollars. I’ve seen companies Ransomwared and shut down for weeks while they recover. Can your business survive being shut down for weeks?

Thus far we’ve been able to thwart these attacks and keep our managed clients safe with little to no impact. We’ve spent a great deal of time putting together best of breed solutions to combat these threat actors but it is truly a game of whack-a-mole with much higher consequences than losing your quarter.  For those reasons and more, I wanted to put together this piece to raise awareness so that you, the business owner, can start to truly understand what you’re up against, what weapons are available to you, and how you can effectively protect yourself from becoming the next victim.

The Cybersecurity Reality for SMBs

The cybersecurity landscape has fundamentally shifted. SMBs are no longer peripheral targets; they’re the primary focus. Forty-five percent of all breaches target small and medium-sized businesses, yet many leaders still operate under the assumption that their organization is too small to matter. This misperception is not only incredibly risky, but it can end up being very expensive.

SMBs need to be aware that they are low hanging fruit for threat actors. Big businesses have big budgets. They can afford to spend a great deal of money on security solutions and people to run them. As a result, their attack surface is small, very well hardened, and monitored 24/7. They typically have a management team that is well educated in cybersecurity risks, approaches, and deterrents. They take security very seriously and expect their people and their vendors to keep them safe and make security a priority.

As an SMB it’s hard to compete with that when your budget is a fraction of theirs, you run on razor thin margins, and your people are experts at your business, not cybersecurity. If you were in a herd running away from a lion you would be at the back of the pack. You are easy prey and the threat actors know this. That’s the bad news.

The good news is there is a lot you can do to move your way up towards the front of the pack. You can eliminate 75-80% of your risk with a combination of low or no cost solutions. The key is to become aware of the risk. Hopefully some of what is included here resonates with you and piques your curiosity. Education is absolutely essential and is the most powerful weapon in this war. The human firewall is by far the easiest security control to knock over. That’s where education comes in.

The Blind Spots

Legacy Infrastructure and EOL Risk

Many SMBs run on operating systems, servers, and security tools that are end-of-life (EOL) and no longer receive security updates. These systems are not gradually becoming risky; they are actively exploited.

Breaches spanning legacy and modern systems average $5.05 million to remediate, a 26% premium compared to modernized environments. Source: IBM Cost of a Data Breach Report 2025

Misconfiguration is the Silent Killer

One of the easiest and least expensive ways to improve your security posture is proper configuration of the tools and systems you have. 

Weak or misconfigured multi-factor authentication methods, default configurations of software and applications, poor credential hygiene, and insufficient access controls are among the Top 10 security misconfigurations most frequently exploited by threat actors.  Source: NSA & CISA Top 10 Cybersecurity Misconfigurations

The Human Element

Your people are simultaneously your greatest asset and your largest vulnerability. A single phishing email or credential compromise can bypass technical controls entirely. This is the human firewall, and it is typically the weakest link. For years we have developed tools and techniques to harden our perimeter. Today’s firewall is very powerful and serves as an effective deterrent, which is why threat actors have switched their tactics. Rather than trying to get through the firewall, threat actors soon figured out the easiest way to get into your business is your employee. From stolen usernames and passwords that are readily available on the dark web to AI crafted emails with malicious links, your employees are the number one target right now.

Phishing remains the most reported cybercrime, while Business Email Compromise (BEC) remains one of the most financially devastating, accounting for more than $3 billion in losses in 2025 Source: FBI Internet Crime Complaint Center (IC3) Annual Report, 2025

So Now What?

Now that you are aware of just a few of the popular attack vectors, what can you do? How do you combat these threat actors? After you’ve fixed your configs, gotten rid of all your default passwords, and patched your vulnerabilities, there are a myriad of tools and techniques you can deploy to further combat cyber-attacks. Below are just a couple and by far the most effective.

Multi-Factor Authentication (MFA) or Two Factor Authentication (2FA)

The number one recommendation, and the most cost-effective tool that delivers the largest value per dollar, is Multi-Factor or Two-Factor Authentication. MFA/2FA is the single most powerful tool to prevent attacks. In effect, it forces the threat actor to hack through 2 distinct layers of security and stops roughly 99% of identity-based attacks. If you don’t have multifactor enabled for email, workstation login, and server login get it. Now!

Security Operations Center (SOC)

Threat actors don’t sleep. While you are sleeping, they are up actively trying to compromise your security and get into your business. Let me repeat that… While you are sleeping, threat actors are up actively trying to compromise your security and get into your business. Take a good look at your firewall logs and you will see they are persistent, they are determined, and they don’t stop. Because of this, a SOC is the number two recommendation. In the early days of cybersecurity, a SOC was an incredibly expensive option that only large corporations could afford and usually built themselves. Today that has changed. The monthly cost of having a SOC today for a 15-person company is typically under $200 a month all in. With that you get 24/7 monitoring of your network and cloud services such as email, SharePoint, and OneDrive. This includes active threat blocking, mitigation, and remediation: all day, every day. Even at 2 am while you sleep.

Security Awareness Training (SAT)

This is how you harden your human firewall. Security Awareness Training (SAT) is probably the most underrated tool in the arsenal and usually the last one purchased, but the first one purchased after a breach. Organizations implementing regular SAT see 40% reductions in phishing incidents and employees report suspicious activity 4x more frequently. Training hardens your human firewall and measurably improves security posture. Employees typically complain about Security Awareness Training but it keeps it top of mind and the numbers back up the effectiveness of it.

The AI Wildcard

The advent of AI is a double-edged sword. AI is incredibly powerful. Its adoption has skyrocketed. It’s provided us with ways to speed up business, develop applications, increase revenue and reduce costs. We’ve used it to create amazing, unimaginable things and it’s helped us develop new ways to combat cybersecurity threats. Unfortunately, the threat actors have discovered that power too.

AI has transformed phishing from mass spam into highly personalized social engineering. Today, more than 82% of phishing emails contain AI-generated content. Source: KnowBe4, Phishing Threat Trends Report (2025)

But the risks of AI don’t stop there. The more AI is rolled out, the more it is exposed. Many of these exposures are self-inflicted. Much like the misconfigurations discussed earlier, AI can NOT be rolled out “out of the box”. It must be deployed deliberately, with security controls and guardrails built in from the start. Wrapping Data Loss Prevention (DLP) and access controls around AI tools isn’t a future concern:it’s an immediate necessity to prevent leakage of Personally Identifiable Information (PII), Intellectual Property (IP) and breach.

13% of organizations reported a breach of an AI model or application; 97% of those lacked proper AI access controls. (IBM 2025) 

A Final Note: Defense in Depth-The Full Vann Data Stack

No single control wins. The most effective organizations layer their defenses, and we’re no different. We’ve built a best-of-breed stack that protects you in this ongoing war without breaking the bank. We know every spare dollar you have belongs in your business, not your security budget, so we designed protection that doesn’t make you choose between the two.

  • mEDR (Managed Endpoint Detection & Response): detect and respond to threats in real-time
  • ITDR (Identity Threat Detection & Response): protect privileged accounts and credentials
  • MFA: prevent unauthorized access even with compromised passwords
  • SAT: keep your people alert and informed
  • Backup & Recovery: ensure business continuity and ransomware resilience
  • 24/7 SOC (Security Operations Center): expert monitoring and threat hunting around the clock

Terminology

Attack Surface

 

All potential entry points and vulnerabilities attackers can exploit

 

EOL (End of Life)

 

Systems no longer receiving updates or security patches

 

mEDR

 

Managed endpoint detection and response; monitor and respond to endpoint threats

 

ITDR

 

Identity threat detection & response; protect identities and credentials

 

MFA

 

Multi-factor authentication; require two or more proof factors to access systems

 

SAT

 

Security awareness training; educate employees on security risks

 

Shadow AI

 

Unauthorized AI tools used without organizational governance or controls

 

DLP

 

Data Loss Prevention; prevent unauthorized exfiltration of sensitive data

 

SOC

 

Security Operations Center; team monitoring and responding to threats 24/7

 

Threat Actor

 

An individual or group conducting malicious cyber activity

 

Threat Vector

 

The path a threat actor uses to gain access e.g. email, system, or application vulnerability

 

Ransomware

 

Malware that encrypts data and demands payment for decryption

 

Zero Trust

 

Security model assuming all access is untrusted until verified

 

 


Bookmark & Share