What a New SMB Cybersecurity Report Found
CrowdStrike’s 2025 State of SMB Cybersecurity Report set out to measure the gap between how prepared small and mid-size businesses think they are and how prepared their budgets actually make them. The numbers land on two very different sides of that line. Ninety-three percent of SMBs consider themselves knowledgeable about cybersecurity risks, and 83% say they have a cybersecurity plan in place. On paper, that looks like a confident, well-prepared population of businesses.
Then the report asks about money, and the confidence evaporates. Only 36% of SMBs are actually investing in new security tools, and just 11% have adopted AI-powered defenses, the kind of tooling increasingly needed to keep pace with automated attacks. Most strikingly, only 6.5% of SMBs believe their current cybersecurity budget is actually sufficient. That’s not a company here or there feeling stretched. That’s the overwhelming majority of small and mid-size businesses in the survey knowing, in plain terms, that what they’re spending doesn’t match what they need.
The smallest and often fastest-growing businesses come out worst. Among SMBs with fewer than 50 employees, more than half allocate less than 1% of their annual budget to cybersecurity, and only 47% have a security plan at all, well below the 83% average across the broader SMB population. When it comes to actually choosing tools, 67% of SMBs prioritize affordability over protection against advanced threats, which only 57% ranked as a top priority. That’s a rational response to a real budget constraint, and also exactly the kind of tradeoff that leaves gaps.
Those gaps show up as incidents. Among SMBs with fewer than 25 employees that experienced a security incident, 29% involved ransomware, compared with 19% among larger SMBs. Smaller, leaner organizations, the ones most likely to be adding headcount, opening new locations, and growing revenue without a matching IT buildout, are getting hit by the most disruptive category of attack at a higher rate than their larger peers.
Why This Matters If You’re Not a Big Company
None of this is a story about companies that ignore security. It’s a story about companies that plan for it on paper and then can’t fund it in practice, which describes a lot of growing small and mid-size businesses. You hire five people this quarter, open a second office, add a new line of business, and your revenue climbs. Nobody sits down and asks whether the IT budget needs to climb along with it, because IT spending doesn’t announce itself as urgent the way payroll or rent does. It just quietly falls further behind the size of the company it’s supposed to protect.
That’s exactly the pattern the CrowdStrike numbers describe: a company with a real plan and real awareness, but a budget that was set for a smaller, simpler version of itself. Every new employee is another endpoint, another set of credentials, another person who can click the wrong link. Every new location is another network to secure. If the budget doesn’t grow with the business, the business is effectively getting less secure every quarter, even while everyone involved believes they’re doing the right things.
What Growing Businesses Should Do Instead
The fix isn’t a bigger budget for its own sake, it’s a budget that’s tied to something that actually changes as the company changes, like headcount, locations, or revenue, and gets reviewed at the same cadence as those numbers. A company that reviews its IT and security spending only when something breaks is, by definition, always reviewing it too late. Tying that review to a regular planning cycle, quarterly for fast-growing companies, at minimum annually for everyone else, keeps the budget from quietly falling behind the business it supports.
It also helps to separate “do we have a plan” from “can we actually execute the plan,” since the CrowdStrike data shows those two things diverging badly. A written policy that nobody funded isn’t protection. If affordability is genuinely the deciding factor in every tool purchase, that’s worth saying out loud to whoever owns the budget, rather than letting it stay an unstated assumption that shapes every decision by default.
Security Checklist for Your Business
Tie your IT budget to growth metrics. Set a rule, like a percentage of revenue or a per-employee amount, and revisit it every time headcount, locations, or revenue changes materially.
Separate having a plan from funding a plan. A written security plan with no budget behind it protects nothing; check that the two actually match before you count on either.
Prioritize protection alongside affordability, not affordability alone, when comparing tools, especially the smallest, fastest-scaling businesses where budgets are tightest.
Review spending on a schedule, not a trigger. Waiting for an incident to reassess IT investment means the reassessment always comes after the damage is done.
The uncomfortable finding in this report isn’t that small businesses lack a plan. It’s that almost none of them believe their budget can actually support the one they have. MSP Today’s trusted tech partner is JK Computer Solutions. If you want a second set of eyes on your setup, get in touch.
Source: CrowdStrike, “CrowdStrike Unveils State of SMB Cybersecurity Report: High Awareness, Lagging Protection”.



