Best Cybersecurity Trends in 2023 for a Positive Future

Explore 2023-2026 cybersecurity trends for small businesses. Learn about vulnerability exploitation, rising breach costs, and AI-driven phishing protection.
In 2026, small businesses are not fighting “small” cyber risks. They are facing enterprise-grade attacks with small-business budgets. That gap is where most damage happens. IBM reported that the average cost of a data breach in the United States hit a record $10.22 million in 2025, while the global average was $4.44 million in 2026. Those numbers include large organizations, but for small firms the real-world hit is still painful: most small business breaches now land somewhere between $120,000 and $1.24 million. For a firm with 8, 20, or 60 employees, that is not an accounting problem. It is a survival problem.
I have spent more than 26 years helping small professional service firms protect sensitive information and make better security decisions. One thing I have learned since 1999 is this: owners usually do not fail because they ignored a “big new trend.” They get hurt because basic controls were never put in place, never tested, or never enforced. The trends matter, but only if they change what you do on Monday morning.
The title of this post says 2023, and that matters because many of the themes people talked about then have now fully matured. AI is no longer a future issue. Ransomware is no longer just file encryption. Phishing is no longer easy to spot. And attackers are no longer relying mainly on stolen passwords. According to the Verizon 2026 Data Breach Investigations Report, vulnerability exploitation now accounts for 31% of breach entry points, overtaking stolen credentials at 13% for the first time in 19 years. If you want a positive future, the good news is that the path is still practical: patch faster, reduce exposure, train your people, and prepare before the bad day arrives.
Key Takeaways
- Attackers are changing how they get in. Vulnerability exploitation is now the top breach entry vector at 31%, ahead of stolen credentials at 13% (Source: Verizon 2026 DBIR).
- People still matter. Even with more technical attacks, the human element is involved in 62% of breaches through error, social engineering, or misuse (Source: Verizon 2026 DBIR).
- Ransomware is hitting small firms especially hard. Ransomware appeared in 48% of all analyzed breaches, and 88% of SMB breaches had a ransomware component (Sources: Verizon 2026 DBIR and SMB 2025/2026 data summary).
- AI cuts both ways. AI-driven phishing now accounts for about 86% of phishing attacks, but AI-assisted defense can reduce breach costs by an average of $1.9 million per incident (Sources: KnowBe4 2026, IBM 2026).
- Small firms remain under-protected. About 65% of SMBs still have not implemented multi-factor authentication, and 47% of businesses under 50 employees allocate $0 specifically to cybersecurity.
- Insurance and clients are forcing the issue. Many small firms saw cyber insurance premiums rise by 200% or more, and weak controls are now causing coverage denials.
- The positive future is still available. The firms that do best are not the ones with the fanciest tools. They are the ones that close obvious gaps, limit access, back up data, and rehearse their response.
The Best Cybersecurity Trends in 2023 That Still Shape a Positive Future in 2026
Trend 1: Attackers shifted from stealing passwords to exploiting weaknesses
One of the biggest changes I have seen in the past few years is where attackers spend their time. For a long time, stolen passwords dominated the conversation. That still matters, but Verizon’s 2026 DBIR shows a clear shift: vulnerability exploitation is now the number one initial access vector at 31%. Stolen credentials dropped to 13%.
In plain English, that means attackers are increasingly getting in through unpatched software, exposed remote access tools, insecure firewalls, old VPN appliances, internet-facing apps, and overlooked third-party software. They are not always “hacking” in some Hollywood sense. Often, they are simply finding systems that have known holes and no one has closed them.
I saw this firsthand with a 14-person law office I advised. They assumed their biggest risk was email phishing, so they bought email filtering and did a basic training class once a year. But their remote access appliance had not been updated in months. An attacker got in quietly, created persistence, and sat there long enough to collect email histories and client files. Nobody noticed for weeks. That story is more common now than many owners realize.
Why edge devices became the quiet doorway
Attackers have increasingly focused on edge devices such as VPNs, firewalls, remote desktop gateways, and internet-connected office devices. These systems sit at the edge of your network, which makes them attractive targets. If they are exposed to the internet and not patched promptly, they become an easy door.
This is especially dangerous for small firms because updates often depend on one overworked IT person, an outside consultant who only comes in when called, or nobody at all. I have walked into firms where a firewall had not been reviewed in 18 months, default administrative accounts still existed, and remote access was open to anyone with a username and password. Those firms were not reckless. They were busy. Attackers count on that.
What a positive response looks like
The positive side of this trend is that it is one of the most fixable problems in cybersecurity. A disciplined patching process, vendor alert monitoring, asset inventory, and MFA on remote access can close a large part of this risk without massive spending.
Here is the reality I share with owners: if you spend $4,000 to $12,000 per year on basic patch management, vulnerability scanning, and managed oversight, and that prevents even one breach that would cost $120,000, the return is obvious. Even using the low end, avoiding a $120,000 incident on a $8,000 annual investment is a 1,400% return. You do not need perfect security to get strong value. You need fewer obvious openings.
Human Error Is Still the Fuel Behind Most Breaches
Technology changed, but people are still involved in 62% of breaches
Business owners sometimes hear about AI, zero-days, or cloud attacks and assume the human side matters less now. It does not. Verizon says the human element remains a factor in 62% of breaches. That includes social engineering, simple mistakes, sending information to the wrong person, reusing passwords, approving fake login prompts, and misuse of data.
In my experience, overwhelmed employees rarely make reckless decisions on purpose. They make rushed decisions. A fake Microsoft 365 prompt at 4:47 p.m. on a Friday gets a different result than the same prompt during a calm training session. That is why awareness training has to reflect real work conditions, not just check a compliance box.
Phishing became more believable because AI made it cheaper to personalize
KnowBe4 reported in 2026 that about 86% of phishing attacks are now AI-driven. That means better grammar, more specific context, more convincing sender profiles, and in some cases even deepfake voice messages. The old advice to “look for spelling mistakes” is no longer enough.
I worked with a 22-person accounting firm that received a fake message appearing to come from a long-time client. The tone matched the client. The timing matched quarter-end filing pressure. The message referenced an actual employee by name and asked for a secure upload review. It was not a mass email blast. It was a tailored lure. One click led to a fake sign-in page, and from there the attacker tried to access multiple mailboxes. The good news is that MFA stopped the account takeover. Without it, that incident would have become a breach.
Training works when it is continuous
Here is one of the most encouraging numbers in this entire discussion. KnowBe4 found that the baseline percentage of employees likely to click a malicious link sits at 33.2% before training. With continuous security awareness training over 12 months, that can drop to 4.2%.
That is the kind of trend I like because it gives small firms leverage. You do not need a six-figure budget to improve human defenses. You need repetition, realistic examples, short lessons, and leadership that treats security as part of the job instead of an annual interruption.
I have seen a 9-person consulting firm reduce failed phishing tests from 28% to 3% in under a year. We did not shame anyone. We trained them monthly in plain English, reviewed a few real examples, and made reporting suspicious messages easy. Progress came from consistency, not complexity.
Ransomware Is No Longer Just Encryption
The attack model became “pay us or we hurt your business in three ways”
Ransomware used to be discussed mainly as locked files. That is outdated. Today, many ransomware groups use a multi-extortion model: they encrypt your systems, steal your data, and threaten to leak it publicly. Some now add a third layer by directly contacting your clients, partners, or staff to increase pressure. That is why the term “triple-threat” is not an exaggeration.
According to Verizon’s 2026 DBIR, ransomware was involved in 48% of analyzed breaches, up from 44% in the previous cycle. For SMBs, the pain is even more concentrated. Recent small business data shows 88% of SMB breaches in 2025/2026 involved a ransomware component, versus 39% for large organizations.
Why the difference? Small firms often have weaker backups, slower detection, less segregation between systems, and fewer response resources. Attackers see that and aim where the payoff is easier.
Downtime is often more expensive than the ransom
When owners think about ransomware, they often focus only on the ransom demand. In many cases, that is not even the biggest cost. The larger hit usually comes from downtime, recovery labor, legal review, client notification, lost billable hours, reputation damage, and insurance issues.
IBM reports the average time to identify and contain a breach is now 241 days, with 181 days to identify and 60 days to contain. Small firms may detect faster if the disruption is obvious, but they often recover slower because they do not have spare staff or spare systems.
I remember an engineering firm with about 35 employees that lost access to project files and email after a ransomware event. Their ransom note demanded less than the cost of one week of operational downtime. But the total impact ended up far larger than the note: two weeks of interrupted work, outside forensics, client communications, emergency system rebuilds, and delayed invoices. The direct and indirect losses crossed $300,000. They had backups, but they had never tested recovery speed. That detail mattered.
Backups only help if they are isolated and tested
This is where I still see too many small firms make assumptions. They tell me, “We have backups, so we’re covered.” Maybe. Maybe not. If backups are connected to the same environment, use the same credentials, or have never been restored in a real test, they may fail when you need them most.
A positive future requires recovery readiness, not just backup existence. That means offline or immutable backups, defined recovery priorities, documented restore steps, and practice. A tested backup system is a business continuity tool. An untested one is just hope with a monthly invoice.
AI Is Helping Defenders, but Shadow AI Is Creating New Exposure
AI can lower costs when used well
Not every trend is bad news. IBM’s 2026 data shows that AI-driven automation helped organizations save an average of $1.9 million per breach incident. For larger companies, that often comes from faster detection and more efficient response. Small firms can benefit too, especially through managed tools that improve alert triage, email protection, endpoint monitoring, and anomaly detection.
I want to be careful here. Small businesses do not need to chase every AI-labeled product on the market. Many are just old tools with new marketing. What matters is outcome: does the tool help you detect suspicious activity earlier, reduce noise, or respond faster? If yes, it may be worth considering. If not, skip the hype.
Shadow AI is a real data leak problem
The more urgent AI issue for many small firms is not buying AI. It is controlling employee use of AI. Current 2026 data shows that 67% of employees are using non-corporate AI accounts on work devices. That creates “Shadow AI” exposure, where employees paste client information, financial details, contract language, health information, legal drafts, or internal strategy into public tools outside company control.
For professional service firms, that should get your attention immediately. If your business depends on trust, confidentiality, and privileged or sensitive information, then uncontrolled AI use is not just an IT topic. It is a client obligation issue.
I recently spoke with a small advisory firm that discovered staff were using personal AI accounts to summarize meeting notes and draft client responses. Nobody had bad intent. They were trying to save time. But they were also uploading confidential data into systems the firm did not manage, monitor, or contractually control. We fixed it with a simple policy, approved tools, data handling rules, and staff education. The problem was not the technology. The problem was the absence of guardrails.
Simple AI rules beat vague warnings
If you want a workable response, do not tell employees “never use AI.” That is unrealistic and usually ineffective. Give them a short list of clear rules instead:
- Do not paste client names, financial records, legal matter details, health information, or internal credentials into public AI tools.
- Use only firm-approved AI accounts and platforms.
- Assume anything entered into an unapproved tool could leave your control.
- Require review of AI-generated output before it goes to a client.
- Log which tools are approved and who owns the account relationship.
That kind of policy is practical. It protects the firm without pretending people will stop using productivity tools altogether.
Cyber Insurance, Regulation, and Client Pressure Are Reshaping Security Decisions
Insurance carriers now expect basic proof, not promises
Over the past few years, I have watched cyber insurance move from a simple add-on to a much stricter underwriting process. Recent data shows that 63% of small firms saw cyber insurance premiums increase by 200% or more in the last year, and many were denied coverage due to missing basic controls such as MFA or a documented incident response plan.
This change is frustrating for owners, but it has one upside: it forces practical conversations. Carriers are asking questions many firms should have already answered. Do you use MFA? Do you back up data? Do you test restores? Do you have endpoint protection? Do you have a response plan? If the answer is no, the risk is not theoretical.
New rules will keep spreading downstream
Even if your firm is not directly regulated, your clients may be. That matters. New developments such as the DOJ Bulk Data Rule from 2025 and the FTC COPPA amendments from June 2025 show how federal expectations around data handling are tightening. The Small Business Cybersecurity Assistance Evaluation Act of 202
Related Articles in Small Business Cybersecurity Basics
- Why Small Indiana Law Firms Are Top Targets for Cyberattacks
- Why Classifying Information is Essential for Small Business Cybersecurity
- What is an Advanced Persistent Threat (APT)? Protecting Your Small Firm
- Disaster-Proofing Your Firm: Why Business Continuity Planning is Critical
- Small Business Cyber Security: Protecting Your Firm with the NIST Framework
- Protecting Your Firm: The Real Cost of Data Collection and Security
- Cybersecurity Awareness: Why Your Small Firm is a Prime Target
- Why Active Threat Hunting is Critical for Small Professional Service Firms
- 3 Critical Cybersecurity Performance Goals Your Team Missed
- Unlock Success: 5 Tips for Employee Cybersecurity Training
- Cybersecurity Fundamentals: 5 Power Moves for Unbreakable Digital Armor
- Scams: The latest in 2022 Holiday's
- Cyber Security Audit: 5 Powerful Ways to Boost Protection
- Cyber Resilience In The Face Of Increase Threats
- Digital Transformation: Why cyber security is critical
- Tiers of Cyber Security: 3 Critical Levels for Full Protection
- 5 Powerful Steps for Security in Depth Success
- Preventing Cyber Threats in Small Business: 5 Essential Tips
- 7 Essential Best Practices for Indiana Small Business Cyber Security
- 5 Shocking Questions to Ask Before Hiring a Cybersecurity Provider
- Cyber security Tips: 10 Powerful Ways to Secure Your Business — Complete guide on Small Business Cybersecurity Basics
- 7 Essential Employee Cybersecurity Training Tips That Work
- 5 Essential Cybersecurity Solutions for Small Businesses
- 10 essential cyber hygiene best practices
- Ultimate Multi-Factor Authentication for SMBs: 5 Critical Steps
- 5 Reasons Why Cyber security is important to small business
- Boost Your Security with Implementing Multi-Factor Authentication: 5 steps
- Ultimate Best Practices for Data Backup and Recovery: 5 Key Takeaways
- Why MFA Is the Single Most Important Security Control
- 7 Critical Steps for Conducting a Cybersecurity Audit
Watch: The $25K Mistake You’re Making: Stop Breaches Now
Kevin Mabry
Founder & CEO, Sentree Systems
Kevin Mabry is the founder and CEO of Sentree Systems, a cybersecurity company serving small professional service firms with under 100 employees. Since starting his business in 1999, Kevin has spent more than 26 years helping organizations protect sensitive information and make smarter technology and security decisions.
His work focuses on helping business owners protect client data, reduce cyber risk, and avoid the operational disruption caused by ransomware, account takeovers, phishing, and other preventable threats. Kevin is known for explaining cybersecurity in plain English without vendor hype, unnecessary jargon, or treating cybersecurity like generic IT support.
Is your business protected?
Get a free security assessment. We'll identify your biggest risks and give you a clear, plain-English action plan — no obligation.
Schedule Your Free Assessment