5 Power Steps to Build a Comprehensive Cyber Risk Plan

Small firms are primary targets for cyberattacks. Learn Kevin Mabry's five practical steps to protect your data and build a resilient security plan in 2026.
Building a Plan That Actually Protects Your Firm in 2026
I started Sentree Systems in 1999. Back then, cybersecurity was basically just installing a firewall and an antivirus program and calling it a day. In the 26 years since, the landscape has shifted from bored teenagers testing boundaries to highly organized, AI-powered criminal syndicates. When I sit down with a business owner today, the first thing I tell them is this: Being a small firm does not make you invisible to attackers.
In fact, as of July 2026, the data shows that small professional service firms are more attractive targets than ever. According to the Verizon 2025 Data Breach Investigations Report, 43% of all cyberattacks now target small businesses. The reason is simple: criminals expect fewer safeguards, limited monitoring, and employees who have never been shown what to watch for. If you run a law firm, an accounting practice, or a consulting group, you aren't just a business owner; you are a custodian of sensitive client data. And that makes you a high-value target.
I’ve watched firms lose everything because they assumed their "IT guy" had it covered. But generic IT support is not cybersecurity. One focuses on keeping you productive; the other focuses on keeping you safe from people trying to destroy you. You need both, but you can’t mistake one for the other. Here is how I help my clients build a comprehensive cyber risk plan that survives the modern threat landscape.
Key Takeaways:
- Small Firms are Primary Targets: 43% of all cyberattacks target small businesses, yet 47% of firms with fewer than 50 employees have zero cybersecurity budget.
- The Cost of Failure is Existential: The average data breach for a US organization hit an all-time high of $10.22 million in 2025, according to the IBM Cost of a Data Breach Report.
- The Human Factor is Key: Between 60% and 62% of breaches still involve a human element, like a clicked link or a weak password.
- Compliance is Non-Negotiable: The updated FTC Safeguards Rule now requires many professional service firms to have written risk assessments and strict MFA or face massive fines.
- Recovery Takes Weeks, Not Hours: The average downtime after a ransomware attack is now 24 days. If your business can't survive three weeks of zero operations, your current plan isn't working.
Step 1: Identify Your "Crown Jewels" and Digital Assets
I once walked into a 15-person accounting firm where the owner told me they had "nothing worth stealing." Ten minutes later, I pointed out that they held the Social Security numbers, bank details, and tax history for over 800 high-net-worth clients. That data wasn't just "worth stealing"; it was their entire reputation sitting on a single, unencrypted server in a supply closet.
The first step in any plan isn't buying software. It’s taking a hard look at what you have. I call this identifying your "Crown Jewels." You cannot protect what you haven't identified. In a professional service firm, your assets usually fall into four buckets:
- Client Data: Case files, tax returns, financial records, PII (Personally Identifiable Information).
- Financial Accounts: Your firm’s bank accounts, payroll systems, and lines of credit.
- Operational Systems: The software you use to bill, document, and communicate (Office 365, Slack, QuickBooks Online).
- Physical Devices: Not just laptops, but the phones and tablets your employees use to check work email from home.
In my experience, the biggest risk in 2026 is "Shadow IT." This is when your staff starts using personal Dropbox accounts or unauthorized AI tools to "be more efficient." When that data leaves your managed environment, you lose control of it. A comprehensive risk plan starts with a full inventory of where every piece of client data lives. If you don't know it's there, you can't secure it.
Step 2: Conduct a Realistic Risk Assessment
A risk assessment isn't just a technical checklist. It's a business exercise. I ask my clients to play the "What If" game. What if your lead attorney’s email is taken over today? What if your server is encrypted by ransomware tomorrow? How much does that cost per hour?
The numbers are sobering. The 2025 IBM report indicates that for businesses with fewer than 500 employees, the average breach cost is $3.31 million. But it’s not just the immediate recovery. It’s the "long tail" of the breach. IBM found that 47% of costs land in the first year, but 24% persist beyond two years due to litigation, lost customers, and regulatory fines.
| Metric | 2026 Reality (Average) |
|---|---|
| US Data Breach Cost | $10.22 Million |
| Small Business Breach Cost | $3.31 Million |
| Downtime After Ransomware | 24 Days |
| Breach Lifecycle (Detection to Containment) | 241 Days |
I recently worked with a boutique law firm that thought a $50,000 cyber insurance policy was enough. I had to show them that a single ransomware event, which takes an average of 24 days to recover from, would cost them nearly $53,000 *per hour* in lost billable time and recovery fees. A $50k policy wouldn't even cover the first morning of the incident. A real risk plan matches your defenses to the actual financial impact of a disaster.
Step 3: Implement Practical, Modern Controls
For decades, we focused on passwords. But as of July 2026, the game has changed. The 2026 Verizon DBIR (published in May) revealed a massive shift: for the first time in 19 years, vulnerability exploitation (31%) has overtaken stolen credentials (13%) as the top way hackers get in. This means they aren't just guessing your passwords anymore; they are looking for unpatched software and holes in your systems.
However, that doesn't mean you ignore the basics. I recommend three non-negotiables:
1. Multi-Factor Authentication (MFA) - The Right Way
If you are still using SMS (text message) codes for MFA, you are living in 2018. Hackers can easily bypass these via "SIM swapping." In 2026, the standard is FIDO2 hardware keys (like YubiKeys) or push-notification authenticator apps. The updated FTC Safeguards Rule now essentially mandates MFA for anyone handling financial data. If you don't have it, you aren't just insecure—you're non-compliant.
2. The Patching Race
Since vulnerability exploitation is now the #1 threat, your "once a month" update schedule is a death sentence. Attackers use AI to scan for new software flaws within minutes of them being announced. I tell my clients that if they aren't patching critical vulnerabilities within 24 to 48 hours, they are losing the race. Automated patch management is no longer a luxury for small firms; it is a necessity.
3. Endpoint Detection and Response (EDR)
Standard antivirus is like a lock on a door. EDR is like a security guard standing inside the building 24/7. It watches for weird behavior—like a computer suddenly trying to encrypt 5,000 files in three minutes. I’ve seen EDR save firms by isolating a single laptop the moment it was infected, preventing the ransomware from spreading to the rest of the network.
Step 4: Build a "Human Firewall" Against AI Threats
I often hear, "My staff is too smart to click on a phishing link." Then I show them a deepfake audio clip of the CEO’s voice asking for an urgent wire transfer. In 2026, phishing isn't just about bad grammar and weird links. With Generative AI, attackers can craft perfect emails that sound exactly like your clients or colleagues.
Statistics show that 95% of cybersecurity incidents are still attributed to human error. But this isn't a failure of character; it's a failure of preparation. In my 26 years, I’ve found that the only thing that works is consistent, simulation-based training. If your employees only hear about security once a year during an onboarding video, they will fail when the real test comes.
I recommend quarterly phishing simulations. According to Cofense research, firms that use consistent simulations are 7x less likely to fall for the real thing. I once worked with a 12-person engineering firm where the admin assistant caught a sophisticated $200,000 wire fraud attempt simply because we had run a simulation of that exact scenario two weeks prior. That is a massive ROI on a simple training program.
Step 5: Resilience Over Just Resistance
Eventually, despite your best efforts, something will go wrong. The difference between a bad afternoon and a business-ending event is resilience. This means having a plan for when the walls are breached.
The gold standard in 2026 is the 3-2-1-1-0 backup strategy:
- 3 copies of your data.
- 2 different media types.
- 1 copy offsite.
- 1 copy that is Immutable (cannot be changed or deleted even with admin access).
- 0 errors after regular testing.
Ransomware actors now target your backups first. If they can delete your safety net, you have no choice but to pay. I’ve sat in rooms with CEOs who had "backups" only to find out they hadn't been checked in six months and were corrupted. We had to spend three weeks and $150,000 in professional recovery fees just to get back to 80% capacity. Don't be that person. Test your backups every single month.
Frequently Asked Questions
Why is a small firm targeted if they don't have millions in the bank?
Hackers don't always want your money directly. They want your clients' money. Professional service firms are "gateways." If an attacker gets into a law firm's email, they can send fraudulent invoices to all of that firm's clients. A $10,000 theft spread over 100 clients is $1 million for the hacker, and it’s often easier than hitting one big bank.
What is the FTC Safeguards Rule and does it apply to me?
As of late 2025 and into 2026, the FTC has expanded its reach. If your business touches consumer financial data—think tax preparers, accountants, mortgage brokers, or even some consultants—you are likely considered a "Financial Institution" under the law. This requires you to have a written security plan, a designated security lead, and mandatory breach reporting for any incident affecting 500 or more people.
How much should a small business spend on cybersecurity?
While 47% of very small firms spend $0, that is no longer a viable strategy. I typically see healthy firms allocating 10% to 15% of their total IT budget specifically to security. When you consider that the average breach recovery costs $120,000 for a small firm (excluding the $53k-per-hour downtime), spending $1,500 a month on proactive protection is just smart business math.
Can I just rely on my cyber insurance?
Insurance is a safety net, not a shield. In 2026, insurance carriers are much stricter. If you claim you have MFA and a written risk plan on your application but you actually don't, they will deny your claim after a breach. Furthermore, insurance won't get your reputation back after you have to tell every client their Social Security number is on the dark web.
Is AI making cybersecurity harder for small businesses?
It's a double-edged sword. Attackers use AI to write better phishing emails and find software holes faster. However, I use AI-powered defense tools that can spot those threats just as quickly. The gap is widening between firms that use modern, AI-backed security and those that are still relying on old, manual processes. The latter are the ones being left behind.
Final Words
Cybersecurity in 2026 is not a technical problem to be "solved" by your IT guy; it is a business risk to be managed by you, the leader. You don't need a multi-million dollar department, but you do need to stop assuming you're invisible. Start by identifying your data, fixing the most obvious holes (like MFA and patching), and training your team to be your best line of defense. If you aren't sure where you stand, reach out. In my 26 years of doing this, I've never seen a firm regret being too prepared. I have, however, seen plenty regret the opposite.
Related Articles in Cyber Risk Management
- 7 Proven Steps to Assessing Digital Vulnerabilities for SMBs
- Risk Assessment and Analysis: 7 Key critical Takeaways for Effective Security?
- 7 Powerful Reasons Cyber Risk Management is Critical for Your Business Success — Complete guide on Cyber Risk Management
- 5 Effective Cyber Risk Reduction Methods for Businesses
- Small Business Cyber Risk Assessment: 5 Shocking Truths
- Don't Overlook These 5 Cyber risk management best practices
- 5 Powerful Cyber Risk Monitoring Tools for SMBs
- Guide to implementing cyber risk strategies: 5 Simple Steps
- 5 Powerful Benefits of Cybersecurity Risk Analysis for Companies
- 5 Powerful Cyber Risk Mitigation Techniques SMBs Need
- Essential Cyber Insurance for Small Businesses: 2024 Guide
- 5 Proven Ways to Reduce Cyber Risk Impact on Business Operations
- 3 Proven Tips on How to Prioritize Cyber Risks
- 7 Powerful Affordable Cyber Risk Management Solutions for SMBs
- 5 Critical Key Cyber Risk Factors in Small Businesses to Tackle
- 5 Powerful Benefits of Risk-Based Cybersecurity Programs for SMBs
- 5 Powerful Reasons to Consider Cyber Insurance for Small Business Risks
- 5 Essential Steps for Reducing Cyber Liability for Small Business
- Cybersecurity Risk Management: 7 Key Strategies to Master Now
Watch: Think You’re Safe? SMB Cyber Threats You’re Ignoring
Kevin Mabry
Founder & CEO, Sentree Systems
Kevin Mabry is the founder and CEO of Sentree Systems, a cybersecurity company serving small professional service firms with under 100 employees. Since starting his business in 1999, Kevin has spent more than 26 years helping organizations protect sensitive information and make smarter technology and security decisions.
His work focuses on helping business owners protect client data, reduce cyber risk, and avoid the operational disruption caused by ransomware, account takeovers, phishing, and other preventable threats. Kevin is known for explaining cybersecurity in plain English without vendor hype, unnecessary jargon, or treating cybersecurity like generic IT support.
Is your business protected?
Get a free security assessment. We'll identify your biggest risks and give you a clear, plain-English action plan — no obligation.
Schedule Your Free Assessment