“We’ll Get to It Later”: Why Small Business Owners Can’t Afford to Deprioritize IT and Security

If you run a small business, IT and security probably live on the same mental shelf as a dozen other “important, but not urgent” projects — somewhere behind sales, behind hiring, behind whatever fire is actually burning this week. That instinct makes sense. Nothing about a firewall or a password policy generates revenue tomorrow, and when budget and time are both scarce, it’s easy to justify pushing it to “once we’re bigger.”

Here’s the problem with that instinct: the data doesn’t support “we’re too small to matter.” It says close to the opposite.

 

The scary stat you've heard is fake — the real one is still bad enough

You’ve probably seen the claim that 60% of small businesses close within six months of a cyberattack. It shows up constantly — in vendor pitch decks, in blog posts, occasionally in government guidance. We’re not going to use it, because it isn’t real. There’s no verifiable study behind it, and the organization most often credited as the source, the National Cyber Security Alliance, publicly walked the number back years ago and stopped using it themselves.

We’re telling you that not to downplay the risk, but because the actual data doesn’t need the exaggeration. Verizon’s 2025 Data Breach Investigations Report found that 19% of small businesses face bankruptcy following a cyberattack. A separate 2025 survey by StrongDM found that 75% of small and midsize businesses say they couldn’t continue operating at all if hit with a serious ransomware attack. Those numbers don’t need rounding up to be a reason to act.

You're not too small to be a target — you're a preferred one

The “nobody would bother hacking us, we’re too small” logic has it backwards. Attackers aren’t manually choosing targets by company size and reputation; they’re running automated campaigns against whoever has the weakest defenses, and small businesses disproportionately fit that description. Verizon’s 2025 report found that ransomware was present in 88% of small business breaches, more than double the rate at large organizations. Small businesses aren’t slipping through the cracks of a system built for bigger targets — in a lot of ways, they’re the preferred target, precisely because dedicated security staff and formal IT governance are rare at that size.

Being small doesn’t make you invisible. It makes your defenses, or lack of them, more attractive.

Credibility is the real currency — not just your data

Here’s the part that tends to get underweighted in these conversations: the damage isn’t only financial or operational. It’s relational, and it lands directly on the thing a small business depends on most — a client’s trust that when they hear from you, it’s actually you.

Business email compromise, where an attacker impersonates a trusted contact through a spoofed or hijacked email account, is one of the most financially damaging categories of cybercrime tracked anywhere. The FBI’s Internet Crime Complaint Center recorded just over $3 billion in reported BEC losses in 2025 alone, making it the second-most costly crime category in the entire report. And that figure only captures the incidents where money moved. It doesn’t capture the client who got a phishing email that looked like it came from your business, didn’t fall for it, but now hesitates before clicking anything from your domain again.

That hesitation is the real cost. A client doesn’t parse the technical root cause of why your email got spoofed. They just know an interaction with your business made them feel less safe, and in a relationship built on trust — which is most small business relationships — that’s expensive in a way that doesn’t show up on an invoice.

What "later" actually costs

The math on deferring security work rarely works the way it feels like it should. Waiting doesn’t make the eventual work cheaper or smaller; it just moves it from a planned project on your own timeline to an emergency response on someone else’s — usually an attacker’s, sometimes a client’s, occasionally a regulator’s. Crisis-mode remediation costs more, takes longer, and happens under conditions where you’re also managing damage to relationships and reputation at the same time, instead of before either is on the line.

None of this requires an enterprise security budget to meaningfully address. Basic hygiene — email authentication so your domain can’t be easily spoofed, a real password and access policy, a plan for who does what if something does go wrong — closes a large share of the gap that makes small businesses attractive targets in the first place. The scale of the fix is usually proportional to the scale of the business. What isn’t proportional is the cost of skipping it entirely.

Treat it like infrastructure, not a luxury

Nobody debates whether a growing business needs a business bank account or basic bookkeeping — those are treated as foundational, not optional, regardless of how small the company still is. Security and IT governance deserve the same status. Not because every small business needs a full-time IT department, but because the baseline protections that keep a business’s data, systems, and communications trustworthy are part of what makes the business viable to do business with in the first place.

“We’ll get to it later” assumes later is a safer, cheaper, less disruptive time to deal with this than now. For most small businesses, it isn’t. It’s just later.

Related articles