Cybersecurity: small businesses are not ready. And it will cost them.
Talk to five owners of small businesses and you get the picture: cybersecurity is still a vague, distant, almost abstract idea. As long as no ransomware freezes the screen of Chantal in accounting, everyone carries on as before.

Talk to five owners of small businesses and you get the picture: cybersecurity is still a vague, distant, almost abstract idea. As long as no ransomware freezes the screen of Chantal in accounting, everyone carries on as before.
But "as before" is over.
Attacks today do not target "the big companies." They target the vulnerable. And when you look at the state of the networks, the passwords, the digital habits in some organizations, you don't have to look very far.
Why have small businesses become the number one target?
Nobody is too small to get wrecked.
Let's drop the myth of "nobody cares about us."
It isn't you they attack. It's your exposed surface.
A badly closed RDP port, an Excel file left in a public cloud, a VM that was never patched.
It's like leaving the door open and hoping no thief walks by.
Criminal groups don't do surgical targeting. They automate.
They scan, they test, they get in.
And when they see you have no MFA, no backup, no plan B,
they encrypt everything. Then they wait.
This is no longer a hunch. In its 2025 Cyber Threat Overview, ANSSI establishes that very small businesses, SMEs and mid-size companies now account for 48% of ransomware victims, against 37% a year earlier, and that the number of attacks doubled between 2020 and 2025. The target is not shifting towards smaller organizations because they have something precious to hide, but because they are easier to open.
The real problem isn't the technology, it's the denial
In a lot of small businesses, you're still stuck at Windows 7, Outlook 2013 and password123.
Not out of stupidity. Out of fatigue. Out of lack of time. Out of exhaustion.
Because when you have ten people, and you handle HR, clients, suppliers, the new regulations that only France knows the secret of, the new taxes and the URSSAF reassessment, cybersecurity comes last.
And yet it's the thing that can bring it all to a halt.
The figures tell the same story. According to the 2025 barometer of cyber maturity in small businesses published by Cybermalveillance.gouv.fr, 80% of owners admit they are not prepared for an attack or do not know whether they are, 58% believe they are unable to assess the consequences, and 29% flatly consider that cybersecurity is not a priority, a share up eleven points in one year. Denial is not receding, it is gaining ground.
Is having an IT provider enough?
"We have a provider."
Great. And how many clients does he work for? 40? 60?
Do you really think he'll jump on his keyboard at 3 a.m. when everything is frozen?
Security isn't a subscription.
It's a culture. A governance. Something that starts with the owner.
And as long as cybersecurity is pushed to the bottom of the org chart, it protects nothing.
Delegating is not protecting. The same barometer notes that a quarter of small businesses use no specialized external support at all, and that the barriers they report are not only financial: lack of knowledge comes first (63%), ahead of budget (61%) and lack of time (59%). A provider plugs in tools. He does not decide, in your place, what matters for your company.
What does a cyberattack really cost?
You have probably heard the shock figure: "60% of small businesses close within six months of a cyberattack." It is false. That statistic was never sourced, and the organization it is attributed to publicly disowned it in 2022. An owner who waves it around discredits the rest of his argument.
The verifiable reality is less spectacular, but it is enough. According to work relayed by LeMagIT, a company's risk of failure rises by around 50% in the six months following the public disclosure of an attack, and the determining factor is not the technical outage, it is the damage to reputation and the handling of the crisis. In other words: it isn't the ransomware that kills the company, it's the trust it drives away.
No budget? Not an excuse
No, you don't have 500k to put into a SOC. We know.
But that's no reason to do nothing.
The problem isn't money. It's inertia.
There are basic things that cost next to nothing:
- A real password policy (and no, not saved in the browser).
- Backups that are offline and tested.
- Two-factor authentication on work accounts.
- A PC that isn't used to visit dodgy sites during the smoke break.
- A simple plan: if we get hit, what do we do?
And these basics still aren't in place. The Cybermalveillance barometer shows that only 26% of small businesses have enabled two-factor authentication, and that barely more than half apply a password policy. These are not expenses, they are decisions. The day a credential leaks, it is that box, ticked or not, that makes the difference between an incident and a disaster.
How is AI changing the threat?
It's already here. On the attackers' side.
It automates phishing, writes the emails, gets past the filters.
You think a badly written email with "URGENT TRANSFER" is outdated?
Now they write like your clients.
And soon it'll be your voice they imitate.
Or your CEO's.
If you think "AI is a problem for later," you're already behind.
"Soon" has already arrived. In 2024, an employee of the engineering multinational Arup approved fifteen transfers worth 25.6 million dollars after a video call in which the chief financial officer and his colleagues were all AI-generated deepfakes built from public images, as CNN reported. French government services now document these AI-boosted CEO fraud scams, and ANSSI has devoted a full threat assessment to generative AI in the service of attackers. Your CEO's voice, meanwhile, is already online: conference talks, podcasts, corporate videos.
Where do you start, right now?
I'm not saying you should turn your small business into a bunker.
I'm saying you have to start. Move. Act.
Not because ANSSI tells you to.
Not because it's trendy.
But because you won't get a second chance.
And above all, because in the world of tomorrow, companies that don't know how to protect themselves will no longer inspire trust.
Not from their clients.
Not from their partners.
Not from insurers.
And least of all from attackers, who are waiting for one thing only: for you to do nothing.
The good news is that you don't need a perfect plan.
You need a first move.
Block off half a day, put your CFO, your "IT person" and a real specialist around the table, make the list of the 10 things to fix first and deal with them one by one. Not in 2030.
This quarter.
And if you don't know which end of the list to pick up, Cybermalveillance.gouv.fr provides free self-assessments and incident response sheets.
After that, you'll breathe easier. And above all, you'll finally send a clear message: here, we don't play with fire anymore.
Sources
- 2025 Cyber Threat Overview, ANSSI: Ma Sécurité, French Ministry of the Interior.
- 2025 barometer of cyber maturity in very small businesses and SMEs: Cybermalveillance.gouv.fr.
- Business failure after a cyberattack, the "60%" myth and credible figures: LeMagIT.
- Deepfake fraud at Arup, 25.6 million dollars: CNN Business, 16 May 2024.
- Ransomware, incident response sheet: Cybermalveillance.gouv.fr.
- Generative AI in the face of cyberattacks, CERTFR-2026-CTI-001: ANSSI / CERT-FR.
- Scams using artificial intelligence: Ma Sécurité, French Ministry of the Interior.
Frequently asked questions
Why would a small business be the target of a cyberattack?
Because criminal groups don't do surgical targeting: they automate, scan and test. It isn't the company that's targeted but its exposed surface, like a badly closed RDP port or a machine that was never updated. In 2025, very small businesses, SMEs and mid-size companies accounted for 48% of the ransomware victims recorded by ANSSI.
Are small businesses really targeted more than before?
Yes. According to ANSSI's 2025 Cyber Threat Overview, the share of very small businesses, SMEs and mid-size companies among ransomware victims went from 37% in 2024 to 48% in 2025, and the number of attacks doubled between 2020 and 2025. Smaller organizations have become the main target because they are the least protected.
Can a small business close down after a cyberattack?
The figure of "60% of small businesses closing within six months" is a myth that was never sourced, and the organization it is attributed to disowned it in 2022. Credible data mostly shows that the risk of business failure rises by around 50% in the six months following the disclosure of an attack, the determining factor being reputational damage rather than the technical outage.
Is budget the main barrier to cybersecurity in small businesses?
No. According to the 2025 Cybermalveillance.gouv.fr barometer, the barriers reported are first a lack of knowledge (63%), then budget (61%) and lack of time (59%). Yet basic measures cost very little: a password policy, offline and tested backups, two-factor authentication, and a simple action plan.
Is having an IT provider enough to stay protected?
No. A provider often manages dozens of clients and can't cover everything. Security is a culture and a governance that must start with the owner, not just a subscription. A quarter of small businesses have no specialized external support at all.
How does AI change the threat for small businesses?
AI is already used by attackers to automate phishing, write credible emails and get past filters. It also serves to clone voices and faces: in 2024, the engineering firm Arup lost 25.6 million dollars after a video call made up entirely of deepfakes impersonating its chief financial officer.
Where do you start, concretely?
Block off half a day this quarter, bring together the CFO, the IT person and a real specialist, list the ten points to fix first and deal with them one by one. What matters is making a first move, not having a perfect plan. Cybermalveillance.gouv.fr offers free self-assessments and incident response sheets to get going.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
