HomeBlog5 Essential Steps for Reducing Cyber Liability for Small Business
All PostsCyber Risk Management

5 Essential Steps for Reducing Cyber Liability for Small Business

Kevin MabryJuly 19, 2026
cybersecurity for small businessdata breach preventionsmall business risk managementcyber liabilityIT security for professional servicesbusiness email compromise
5 Essential Steps for Reducing Cyber Liability for Small Business

Small businesses are prime targets for cyberattacks in 2026. Founder Kevin Mabry shares 5 practical, jargon-free steps to protect your firm from modern threats.

The 2026 Reality for Small Business Owners: You Are the Target

I started helping professional service firms secure their data in 1999. Back then, "cybersecurity" usually meant making sure your dial-up connection didn't stay open too long and checking a floppy disk for viruses. Over the last 26 years, I’ve watched the landscape shift from bored teenagers looking for a thrill to highly organized, AI-powered criminal syndicates that operate with the efficiency of a Fortune 500 company.

If you run an accounting firm, a law practice, or a consultancy with under 100 employees, you’ve likely spent the last year hearing about "AI this" and "Deepfake that." It sounds like science fiction, but the reality is much more grounded. Today, on July 19, 2026, the risk isn't just about a computer getting a "virus." It’s about your client’s sensitive data being auctioned off, your bank account being drained via a fraudulent wire transfer, and your firm’s reputation—the one you spent decades building—vanishing in a single afternoon.

Being a small firm does not make you invisible to attackers. In many cases, it makes you easier to target because criminals expect fewer safeguards, limited monitoring, and employees who have never been shown what to watch for. According to the 2026 Verizon Data Breach Investigations Report, small and mid-sized businesses (SMBs) experienced approximately 4 times more confirmed data breaches than large organizations over the past year. Attackers aren't avoiding you because of your size; they are seeking you out because of it.

Key Takeaways for 2026:

  • The "Invisible Target" Myth is Dead: 43% of all cyberattacks now target small businesses, and 80% of firms with under 50 employees suffered at least one incident in 2025.
  • AI Has Changed the Game: AI-powered phishing attacks rose 340% in the last year, with open rates as high as 78% because the emails are indistinguishable from real client requests.
  • Financial Stakes are Existential: The average data breach cost for firms under 500 employees has climbed to $3.31 million, and 40% of small firms say an attack costing $100,000 would put them out of business.
  • Compliance is No Longer Optional: The SEC’s amended Regulation S-P now mandates that even small financial institutions have written incident response plans and meet strict notification deadlines as of June 2026.
  • Insurance Requires Proof, Not Promises: To get a cyber liability policy today, you must prove you have Multi-Factor Authentication (MFA), Endpoint Detection and Response (EDR), and tested backups in place.

Step 1: Conduct a Plain-English Risk Assessment

In my 26 years of doing this, I’ve found that most business owners are overwhelmed because they think they need to protect "everything." You don't. You need to protect what matters. I once sat down with the managing partner of a 12-person architectural firm who was terrified of hackers. When I asked where their most sensitive client blueprints were stored, he pointed to a server in the closet, a Dropbox account three different employees used, and a couple of personal laptops. They were trying to secure a whole building while leaving the back windows wide open.

A real assessment isn't a technical scan; it’s a business inventory. You need to identify your Crown Jewels. For most professional service firms, this is your client data, your financial accounts, and your ability to communicate (email).

Start by mapping out where your data lives:

  • Local Devices: Laptops, desktops, and that old server in the breakroom.
  • Cloud Services: M365, Google Workspace, QuickBooks Online, and specialized practice management software.
  • Shadow IT: This is the big one in 2026. It’s the "free" PDF converter an employee downloaded or the personal Evernote account they use to take client notes.

Once you know where the data is, you can quantify the risk. I use a simple formula: Cost of Downtime per Hour x Hours to Recover = Real Liability. According to VikingCloud research, downtime now costs the average small business $53,000 per hour. If it takes you two days to get back online after a ransomware hit, that’s over $800,000 in lost productivity and opportunity before you even pay a single fine.

Step 2: Fortify Your Perimeter (Beyond Basic Antivirus)

If you are still relying on a basic antivirus program that you bought five years ago, you are essentially bringing a knife to a drone fight. Modern threats don't "infect" files like they used to; they use legitimate tools already on your computer to steal data. This is why vulnerability exploitation—finding a hole in your software—has overtaken stolen passwords as the #1 way hackers get in, according to the 2026 Verizon DBIR.

For a small firm, three technical controls are non-negotiable in 2026:

1. Multi-Factor Authentication (MFA) That Actually Works

I cannot stress this enough: MFA is the single most effective way to prevent account takeovers. However, in 2026, hackers can bypass simple SMS (text message) codes. I recently worked with a boutique law firm where an attorney was "fatigued" by MFA prompts and clicked "Approve" on his phone for a login he didn't initiate. Within ten minutes, the attacker had set up a mail forwarding rule to steal every invoice sent to clients. Recommendation: Use app-based push notifications or physical security keys (like YubiKeys) for your most sensitive accounts.

2. EDR vs. Traditional Antivirus

Traditional antivirus looks for "bad files." Endpoint Detection and Response (EDR) looks for "bad behavior." If an admin account suddenly tries to export your entire client database at 3 AM, EDR spots the anomaly and kills the connection. It’s like having a security guard who knows everyone’s face instead of just a lock on the door. The ROI here is massive—firms using AI-driven security monitoring saw average savings of $1.9 million in breach costs compared to those that didn't, per IBM's 2025 data.

3. Tested, Immutable Backups

Ransomware in 2026 is smarter. It spends days or weeks inside your network specifically looking for your backups so it can encrypt them first. If your backup is just an external drive plugged into your server, it’s useless. You need immutable backups—data that cannot be changed or deleted for a set period, even by an admin. I tell my clients: "A backup isn't a backup until you've successfully restored a file from it." I’ve seen too many owners realize their "backup system" had been failing for six months only after they needed it.

Step 3: Turn Your Team Into a Human Firewall

We’ve all seen the boring 45-minute security training videos. They don't work. The human element is involved in 62% of breaches because attackers have mastered the art of psychological manipulation. In 2026, the biggest threat is AI-Enabled Phishing. Criminals can now use a 10-second clip of your voice from a LinkedIn video to create a deepfake audio message.

Imagine your office manager receiving a voice note from "you" asking them to urgently pay a vendor invoice. The voice sounds like you, the email looks right, and the pressure is high. This is how $2.77 billion was lost to Business Email Compromise (BEC) recently, according to the FBI.

Training needs to be habitual, not annual. I recommend:

  • Monthly Phishing Simulations: Send fake "tests" to your team. If they click, they get a 2-minute "teachable moment" immediately. Consistent training improves phishing resistance by 7x.
  • The "Safe Word" Protocol: I advised a 5-person accounting firm to implement a simple rule: Any wire transfer or change in payment details must be verified via a second channel (like a phone call to a known number) using a pre-agreed verbal confirmation. It costs zero dollars and prevents six-figure losses.
  • Reporting Culture: Encourage your team to speak up. I’d rather my team report ten "false alarms" than stay silent about one real threat because they were afraid of getting in trouble for clicking a link.

Step 4: Develop an Incident Response Plan (IRP)

When a breach happens, the first 60 minutes are the "Golden Hour." If you spend that hour panicking, you’ve already lost. A written Incident Response Plan is now a requirement for many small firms under the SEC’s amended Regulation S-P, which hit its compliance deadline for small organizations on June 3, 2026. This regulation requires you to notify affected individuals within 30 days of discovering a breach. You cannot meet that deadline if you don't know who to call first.

I once got a call at 6 AM from a client whose main admin account had been hijacked. Because we had a written plan, we knew exactly which logs to pull, which insurance carrier to notify, and how to isolate the affected systems without shutting down the entire business. Without that plan, they would have been blind for days.

Your IRP doesn't need to be 50 pages. It needs to answer three questions:

  1. Who is in charge? (Hint: It should be one person with the authority to make decisions, not a committee).
  2. Who are our external partners? (Your IT provider, your cyber insurance carrier, and your legal counsel).
  3. How do we communicate? (If your email is down, how do you talk to your staff? Signal? Text?)

Having a plan is like having a fire extinguisher. You hope you never use it, but you don't want to be reading the instructions while the room is on fire.

Step 5: Navigate the 2026 Cyber Insurance Market

Cyber insurance is no longer a simple "add-on" to your general liability policy. In 2026, it is a full-scale qualification process. Carriers are tired of paying out for preventable ransomware attacks. As of this year, if you cannot prove you have MFA on all remote access and EDR on every machine, most carriers will simply decline to quote you.

But here is the good news: Lockton data shows that for firms with strong controls, premiums are finally stabilizing. By investing in the steps I’ve outlined above, you aren't just "buying security"—you are qualifying for better insurance rates and higher coverage limits.

When choosing a policy, look for these three things:

FeatureWhy It Matters
First-Party CoverageCovers your costs: forensics, data restoration, and lost income during downtime.
Third-Party LiabilityCovers legal costs: if a client sues you because their data was exposed.
Extortion/RansomwareCovers the negotiation and (if necessary) payment of a ransom, though 69% of victims now refuse to pay.

Remember, insurance is the safety net, not the floor. If you fall, you want the net to be there, but your goal should be to never leave the tightrope in the first place.

Frequently Asked Questions

Is my business too small to need a written cybersecurity policy?

No. In fact, as of June 2026, many small financial and professional service firms are legally required to have one under SEC Regulation S-P. Beyond the law, a policy sets the standard for your employees. If you don't have a written rule about not using personal laptops for client work, you can't be surprised when a breach happens because of a family member’s malware-infected gaming site.

How much should a small firm spend on cybersecurity?

I get asked this every week. While every firm is different, a good benchmark is 10-15% of your total IT budget. However, I prefer to look at the "Security ROI." Spending $500 a month on a managed EDR service is much cheaper than the $1.24 million average cost to resolve a major security incident in 2026. Security is a business expense, not a "tech cost."

Can't I just move everything to the cloud and be safe?

The cloud is generally more secure than a server in your closet, but it is not a "get out of jail free" card. You are still responsible for Identity Management. If your employee has a weak password and no MFA on their Microsoft 365 account, a hacker can walk right into your cloud environment. The cloud secures the infrastructure; you are still responsible for securing the access.

What is the very first thing I should do today?

Turn on Multi-Factor Authentication (MFA) on your email and your primary bank accounts. It is the single highest-impact, lowest-cost action you can take. If you do nothing else this month, do that. It stops approximately 99% of bulk automated attacks overnight.

Conclusion

Reducing your cyber liability isn't about achieving "perfect" security. In my 26 years, I’ve never seen a firm that was 100% unhackable. It’s about being a "hard target." Hackers are like burglars in a neighborhood; they are looking for the house with the door unlocked and the lights off. By following these five steps—assessing your risk, fortifying your tech, training your team, planning for the worst, and securing the right insurance—you are locking the doors and turning on the floodlights.

Cybersecurity shouldn't be a source of constant anxiety. It should be a foundation that allows you to serve your clients with confidence. Take it one step at a time, start with the fundamentals, and don't be afraid to ask for help from someone who speaks your language, not just "IT-speak." Your business, your reputation, and your peace of mind are worth the effort.

Watch: How Stolen Passwords Let Hackers Take Over Your Business

41 viewsDec 9, 2025Watch on YouTube →
KM

Kevin Mabry

Founder & CEO, Sentree Systems

Kevin Mabry is the founder and CEO of Sentree Systems, a cybersecurity company serving small professional service firms with under 100 employees. Since starting his business in 1999, Kevin has spent more than 26 years helping organizations protect sensitive information and make smarter technology and security decisions.

His work focuses on helping business owners protect client data, reduce cyber risk, and avoid the operational disruption caused by ransomware, account takeovers, phishing, and other preventable threats. Kevin is known for explaining cybersecurity in plain English without vendor hype, unnecessary jargon, or treating cybersecurity like generic IT support.

Take Action

Is your business protected?

Get a free security assessment. We'll identify your biggest risks and give you a clear, plain-English action plan — no obligation.

Schedule Your Free Assessment