You've probably seen this one: "60% of small businesses close within six months of a cyberattack." It shows up in vendor pitch decks, conference keynotes, and no shortage of consultant websites — sometimes ours, if we're not careful. We looked into where it actually comes from, and it's worth a second look before you repeat it.

Where the number comes from

The figure traces back to a single source from around 2012–2013, and it has been recirculated across hundreds of articles since without much scrutiny of the original data or methodology. That's not automatically disqualifying — old research isn't always wrong — but a number that's over a decade old, describing a threat landscape that looked very different back then, deserves a second source before anyone builds a budget argument on it.

What more recent data actually shows

More careful, recent analysis paints a less extreme but still serious picture. Verizon's 2025 breach report puts the share of small businesses facing bankruptcy after a significant attack at closer to one in five. Separately, a 2025 industry survey found that roughly 40% of small businesses said an attack costing $100,000 would end their company — which is a statement about vulnerability, not a measured outcome, but it's a meaningfully different claim than "most businesses close."

Why this distinction matters: if the scary number turns out to be shaky, it gives people a reason to dismiss the whole warning — including the parts that are well supported. The real data doesn't need the exaggeration.

The case for caring anyway

Even the more conservative numbers describe a real risk. A single ransomware incident averages well into six figures in recovery costs once you count downtime, forensic work, and legal fees — and that's before anything is paid to an attacker, which we'd never recommend doing anyway. Nearly half of businesses under 50 employees currently put zero dollars toward cybersecurity, which means the businesses least prepared to absorb that cost are often the ones with the least protection against it in the first place.

None of that requires an inflated statistic to be worth acting on. It just requires an honest look at what a bad month would actually cost your business, and whether the basics — backups, multi-factor authentication, a plan for who does what if something goes wrong — are actually in place.

Want the honest version for your business?

We'll tell you your actual exposure — no inflated stats required.

Get a plain-English assessment