Form: Cost-of-Breach DisclosureSource: IBM Cost of a Data BreachFiled: 28 Apr 2026
DataBreachCost.comOpen calc
Independent breach-cost research, read by security and risk leaders.Sponsor this site →
Schedule 07 / SMB Cost RegisterIBM 2023 org-size breakout, the last one published

SMB headline figure

The last published average for a small business is $3.31M, for organizations under 500 employees.

IBM's headline $4.44M average is enterprise-skewed, and there is no current first-party average published for small businesses specifically. The IBM Cost of a Data Breach Report 2023 put organizations with fewer than 500 employees at $3.31M, and that was the last edition to segment by organization size: IBM dropped the breakout from its 2024, 2025 and 2026 reports. So $3.31M is the most recent first-party number, and it sits at the top of the SMB band, because a 499-employee company is not what most people mean by small. For a genuinely small business the modelled range runs $15K to $3.31M. Below: cost ranges by company size, common attack types, and an affordable defence stack by budget tier.

Under 500 emp

$3.31M

IBM 2023, last breakout

Small (10-49 emp)

$50K-$200K

Modelled range

Micro (1-9 emp)

$15K-$50K

Typical range

Global average

$4.44M

IBM 2025, all sizes

Direct answer / Average data breach cost for small businesses

The most recent published average is $3.31M for organizations with fewer than 500 employees, from the IBM Cost of a Data Breach Report 2023. That edition was the last one to segment results by organization size; the 2024, 2025 and 2026 reports do not, so no first-party average for small businesses has been published since. The number also runs high for the question most people are asking, because the bracket goes all the way up to 499 employees. Below 50 employees the cost is dominated by fixed items, forensics, legal retainer and notification, not by record counts, which is why the modelled floor is around $15K rather than a fraction of $3.31M.

Under 500 employees, last published average$3.31M (IBM 2023)
All organizations, IBM 2025$4.44M (IBM 2025)

The practical consequence: treat any single "average small business breach cost" quoted without an employee bracket and a report edition as unusable. Two figures that both claim to be the small-business average will normally be measuring different company sizes, different cost scopes, or different years.

Source: IBM Cost of a Data Breach Report 2023, organization-size breakout (fewer than 500 employees), the last edition to publish one. All-organization average from the IBM Cost of a Data Breach Report 2025. Checked 7 September 2026.

Section 07.1 / Cost ranges by size

What it actually costs at your scale

Costs scale with employee count, but unevenly. Notification per record is a fixed cost regardless of size. Forensics has a base fee. The result: smaller incidents are dominated by fixed costs, while large incidents start to track records.

Organization sizeCost range
Sole trader / micro (1-9 employees)$15K - $50K
Small (10-49 employees)$50K - $200K
Medium (50-249 employees)$200K - $1M
Mid-market (250-499 employees)$1M - $3.31M

Primary source:Organization-size figure from the IBM Cost of a Data Breach Report 2023, fewer-than-500-employee bracket, the last edition in which IBM segmented by organization size; the 2024, 2025 and 2026 editions do not. The sub-500-employee cost ranges are modelled by this site from fixed-cost floors plus per-record and business-interruption scaling, not published averages, and are labelled as modelled. Checked 7 September 2026.

Section 07.2 / Common SMB attack types

Where SMB breaches start

SMBs face a different attack mix than enterprises. Phishing dominates because SMB email security is often consumer-grade. Ransomware operators target SMBs deliberately because the pay rate is higher and detection is slower.

Phishing / Fraudulent emails targeting employees43%
Ransomware / Encryption-based extortion increasingly targeting SMBs27%
Business Email Compromise / Impersonating executives or vendors15%
Credential Stuffing / Automated login attempts with leaked passwords10%
Other / Insider threats, physical theft, misconfiguration5%

Primary source:Verizon Data Breach Investigations Report 2025 (SMB victim cohort).

Section 07.3 / Affordable defence stack

What you can do at three budget tiers

Free / low-cost controls eliminate the most common attack precursors. Paid tiers add managed-service economics. Vendor-neutral, named only by category.

Tier 1 / Free or near-free

Eliminates the precursor attacks

  • [x]Enable MFA on all accounts (email, banking, cloud services)
  • [x]Regular employee security awareness conversations
  • [x]Keep all software and operating systems updated
  • [x]Implement the 3-2-1 backup rule (3 copies, 2 media, 1 offsite)
  • [x]Use a password manager (many have free tiers)

Tier 2 / Under $5K / year

Managed defence becomes affordable

  • [x]Managed endpoint detection and response (EDR), $3-8/device/month
  • [x]Business-grade email filtering, $2-5/user/month
  • [x]Enterprise password manager, $4-8/user/month
  • [x]DNS filtering (block known malicious domains), $1-3/user/month
  • [x]Automated patch management, $2-5/device/month

Tier 3 / Under $20K / year

SMB approaches enterprise hygiene

  • [x]Managed SIEM (Security Information & Event Management)
  • [x]Annual penetration test, $5K-$15K
  • [x]Cyber insurance policy, $1K-$5K/year for small businesses
  • [x]Security awareness training platform, $15-25/user/year
  • [x]Managed firewall and intrusion detection

Primary source:Pricing aggregated from public vendor pricing pages (typical 25-100 user bands), Q1 2026.

Index / Companion schedules

Schedule F / Reference Q&A

Frequently Asked Questions