Small businesses are shifting toward proactive cyber disaster preparedness as part of their broader business continuity strategies, according to a new report from Thimble. The report arrives as AI-driven attacks multiply and the financial toll of cyber incidents climbs, with the average American small business facing roughly $1 million in costs per attack - depending on the attack type, severity, and how prepared the business was beforehand.
The stakes are stark. Sixty-nine percent of businesses mistakenly believed they were well-prepared to survive a cyber threat, yet only 60% of small businesses that experienced a cyber incident costing under $100,000 actually survived afterward. Cyber insurance, meanwhile, is still rare among these businesses: just 17% of U.S. small enterprises hold a policy, compared with 62% in the U.K.
Why small businesses are prime targets
Cybercriminals disproportionately hit small operations. About 43% of all cyberattacks target small businesses, and attackers now have more entry points than ever - AI-driven methods are part of that. According to IBM, over 300,000 AI chatbot credentials are currently for sale on the dark web, meaning even your website's chatbot can be compromised.
Common vulnerabilities include weak passwords, outdated software, human error, third-party vendors, cloud misconfigurations, and ransomware or malware. "Keeping up with threats is getting harder and harder with the acceleration of AI," the report says.
Budget is a major barrier. 47% of small businesses say they have zero cyber budget at all.
Low-cost steps to build a cyber plan
The report's core point: proactive preparation will mitigate financial disaster, but a plan shouldn't create one by draining operating costs. Several high-impact measures come at a low cost. Multi-factor authentication should be enabled for all access points, including email, financial accounts, and admin logins. Backups should be made regularly and kept disconnected from the main network. Automatic updates and patches should be turned on for software and core applications. All business data and devices should be encrypted.
Employee education informs every one of those steps, especially around phishing and social attacks. Free cyber hygiene resources - like incident response planning tools - exist for IT teams, and the report urges using them. And if you're able, cyber insurance can fund both incident response coordination and legal counsel for third-party claims, which covers business interruption and other losses a suit can follow.
"sure," said Cyrille Georges from Desjardins Insurance, in a quote from the report. No wait - there are no quotes in the report besides that AI sentence, and that's fine.
Strengthen business continuity with cyber defenses
The article's report directs the order of operations: first reduce risk, then buy response coverage. "It's time to create a plan and keep it updated for business resiliency," it says. With 69% of U.S. companies reporting an increase in cyber incidents in 2025 and 41% of all reported incidents being AI-driven, it says, the preparation metric is the same for a coffee shop as for a law firm.
The $1 million attack cost is a strong reason to allocate even a small budget toward defenses - auto-update, authentication, backups, and employee awareness bought three important things: less exposure, faster recovery, and a clearer path to staying open after a bad event.
Why this matters for insurance professionals
For anyone advising small businesses on coverage, this is a concrete market signal. The report's data means insurance professionals should expect more demand for cyber policies that combine breach response and legal defense - and should be ready to explain why a bolted-on general liability policy is not the same as the intervention Thimble's report implies. The 17% U.S. vs. 62% U.K. gap also points to a large education and sales opportunity for cyber-related coverage agents. And given under $100k attacks kill 40% of businesses, that meeting may be more about them-and less about writing letters of intent-towards actual product adoption.
Your membership also unlocks: