IT security: Why small businesses in particular are targeted by cyberattacks
Reading time: 8 minutes
As a company that does not generate millions in turnover or manage large volumes of sensitive customer or patient data, one often lulls oneself into a false sense of security and mistakenly believes that cybersecurity is an issue exclusively for large organisations. However, the notion that cybercriminals have nothing to gain from small businesses is a common – and costly – misconception. In fact, small and medium-sized enterprises are not overlooked simply because of their size. On the contrary, their size often makes them a prime target. In our article, you’ll find out how small businesses are targeted and what specific steps you can take to protect yourself.
IT security for small businesses in Germany
Bitkom, the trade association for the German information and telecommunications sector, estimates the annual cost to the German economy of theft, espionage and sabotage at 289.2 billion euros in its study on economic security 2025. Cyberattacks alone account for 202.4 billion euros of this figure. Around 87 % of the companies surveyed were affected during the study period.
The fact that these attacks are by no means confined to large corporations is made clear by Germany's Federal Office for Information Security’s (BSI) annual report on IT security in Germany for the year 2025. According to the report, around 80 % of the reported attacks were directed against small and medium-sized enterprises. In its 2025 Federal Cybercrime Situation Report, Germany's Federal Criminal Police Office (BKA) also recorded 1,041 reported ransomware attacks, which is 10 % more than in the previous year. At 90 %, small and medium-sized enterprises are once again the group most severely affected.
These figures dispel the myth that small businesses are uninteresting targets. So why are small businesses targeted so frequently?
What makes small businesses so attractive to cyber-attacks?
The vast majority of attacks are automated
Malware and botnets constantly scan the internet for vulnerable systems, open ports, outdated software or weak login credentials. Whether the target is an international corporation or a small trade business with twelve employees is irrelevant in this initial phase. Anyone who leaves a gap open will be hit. At the same time, there is a shift away from a few elaborate attacks towards a multitude of smaller, easily executable attacks.
The weakest link in the supply chain
Small firms often misjudge their own role within the wider structure of the supply chain. Suppliers, service providers or specialist craft businesses are now closely connected to their partners digitally. For attackers, this weakest link becomes a gateway through which they can reach the targets of real interest further up the chain. Your size therefore does not protect you; on the contrary, it can make you a preferred point of entry.
Cybercrime-as-a-Service lowers the barrier to entry
In the ‘Cybercrime-as-a-Service’ business model, malware and complete attack services are offered like off-the-shelf products. Attacks therefore require neither in-depth technical knowledge nor significant investment. This significantly lowers the barrier to entry and increases the number of potential attackers, at the expense of those companies that previously considered themselves too insignificant.
The security gap: perceived vs. actual security
According to the BSI, small and medium-sized enterprises meet, on average, only around 56 % of the basic IT security requirements and regularly overestimate their own level of protection. Attackers exploit this gap between perceived and actual security. When companies believe themselves to be secure without actually being so, they fail to take the measures needed to ward off cyber risks and ensure their business continuity.
The most common entry points for cybercrime
In practice, it is primarily the following recurring patterns that cybercriminals use to cause damage to small businesses:
Phishing
A deceptively genuine invoice from a long-standing business partner, a purported message from the company’s bank, or an urgent request from a supposed line manager can trick employees into thoughtlessly clicking on links, attachments and the like. Such attacks are aimed directly at people.
Ransomware
In ransomware attacks, company data is encrypted in order to extort a ransom from the victims. According to Bitkom, 34 % of the companies surveyed suffered damage caused by ransomware within a year, followed by DDoS attacks (25 %) and other malware (24 %).
Accesses
Weak or reused passwords and the absence of a second factor of authentication leave the door wide open to attackers. This risk is exacerbated by out-of-date software and inadequately secured remote access, for example when working from home or whilst on the move.
Why are small businesses hit harder by the damage?
The fear of ransom demands often overshadows the consequences of cyber-attacks, which cause far greater damage. Following a ransomware attack, in many cases it is not just the IT systems that come to a standstill, but the entire business: Orders cannot be processed, invoices cannot be issued and customers cannot be served. Every day of downtime results in an immediate loss of turnover, and unlike a large corporation, a small business rarely has the reserves to bridge a prolonged interruption.
On top of the downtime come the costs of recovery, potential fines and reporting obligations in the event of a personal data breach under the GDPR, as well as the loss of trust among customers and partners, which is difficult to quantify.
A large corporation can more easily absorb the impact of a successful attack. Small businesses, on the other hand, are hit particularly hard. For them, a serious cyber incident therefore poses an immediate threat to the very foundations of their business. This is precisely where it becomes clear why business continuity – that is, the ability to maintain business operations even in an emergency – is a matter of survival for small businesses.
Staying operational: communication as an underestimated emergency factor
Whether an incident turns into a minor disruption or a full-blown crisis is often decided in the first few hours – and thus depends on the ability to communicate.
It is precisely when swift and coordinated action is crucial that the very tools you would normally rely on often fail. If the primary communication channels are compromised, email inboxes and video-conferencing tools are no longer available. If, at that moment, you do not know how to reach your staff, you will lose valuable time. Yet in an emergency, communication must take place in several directions at once:
- The workforce needs clear instructions and new communication channels.
- Customers and business partners expect open and reliable information; otherwise, there is a risk of a lasting loss of trust that could threaten the very survival of the business.
- There are legal obligations towards the authorities; for example, a data protection incident must be reported to the GDPR within 72 hours.
For this communication to succeed at all, it must function independently of the affected systems. Contact lists, emergency numbers and a coordinated communication plan must therefore be stored in a single location that remains accessible even when the primary channels are down. A resilient communication capability in an emergency is the cornerstone of business continuity.
Business continuity for SMEs
IT security for small businesses: Your action plan
However serious the situation may be, there is little cause for resignation: as most attacks are automated and seek out the easiest opportunity, even a solid level of basic protection shifts the cost-benefit balance against the attackers. A business by no means needs to mobilise the resources of a large corporation to become significantly less vulnerable to attack. Effective IT security for small businesses does not start with expensive specialist solutions, but with the consistent implementation of the basics:
Can be implemented immediately:
- Enable multi-factor authentication (MFA) for all key access points: this is one of the most effective measures and is already included in many systems.
- Introduce password management: this replaces weak and reused passwords.
- Keep your systems up to date: install any outstanding security updates and enable automatic updates to be prepared for new threats.
In the short term:
- Set up regular, off-site backups and test the recovery process in case of an emergency.
- Review remote access permissions and consistently revoke access that is no longer required.
- Raise your staff’s awareness of phishing and the increased risks of email fraud resulting from the use of artificial intelligence.
Embed this in your structure:
- Draw up a clear contingency plan and a robust business continuity strategy, and test the measures regularly to ensure you remain capable of acting in the event of a failure. Practical guidance on this is provided by the BSI Standard 200-4, which helps small businesses in particular to develop and establish a robust business continuity management (BCM) system whilst conserving resources.
- Prepare communication channels independent of the primary system that are immediately available in an emergency.
- View IT security as an ongoing process and as a responsibility of senior management.
Conclusion
The situation reports from the BSI, BKA and Bitkom paint a consistent picture: Cybercriminals are not looking for the largest company, but the one that is easiest to target. Smaller companies, in particular, are the main focus. That is why it is so important to consistently implement the fundamentals of IT security for small businesses and to take business continuity seriously.