A survey found that 52 percent of small businesses rely on untrained staff or the business owner to manage cybersecurity without professional support. The gap between what these businesses believe is in place and what actually works is where expensive breaches begin.

Almost every small business has someone like this. You may not have hired them for the role, and their job title almost certainly doesn’t mention it, but somewhere in your company there is  probably a person who has become, by default, your IT department. Maybe it’s your office manager. Maybe it’s the bookkeeper who set up the QuickBooks integration and then got asked to handle “the computer stuff” because she seemed to have a knack for it. Maybe it’s you.

This person keeps things running. They configured the Wi-Fi, and they’re the one who calls the internet provider when something goes down. They may have even installed antivirus software on everyone’s machines and set up a basic backup. They didn’t volunteer for this. They just happened to be the most technically comfortable person in a building full of people who weren’t.

I want to be clear about something: this person is not the problem. The problem is what happens when a business builds its entire cybersecurity posture on the foundation of one person’s good intentions and self-taught knowledge. That foundation has predictable gaps, and in 2026, those gaps are getting expensive.

A Majority Problem, Not an Edge Case

If your company fits the description above, you’re in the majority. The Guardz 2025 SMB Cybersecurity Report, based on a survey of 800 small business owners, found that 52 percent of SMBs rely on an untrained internal staff member or the business owner to manage critical security functions, without support from cybersecurity professionals or managed service providers. In a third of cases, the business owner personally handles security alerts and incident resolution. An additional 13 percent rely on completely untrained employees.

These are not businesses that don’t care about cybersecurity. Eighty percent of the same respondents said they believe the need for cybersecurity in their industry has increased over the past year. They know the threat landscape is getting worse. They just haven’t changed who is responsible for dealing with it.

CrowdStrike’s 2025 State of SMB Cybersecurity Report found the same pattern from a different angle: 93 percent of SMB decision-makers describe themselves as knowledgeable about cybersecurity risks, and 83 percent say they have a plan in place. But only 36 percent are investing in new security tools, and only 11 percent have adopted any form of advanced threat detection. Knowledge and action appear to be running on separate tracks.

The Confidence Problem

Here’s what makes the accidental IT person such a difficult risk to address: the arrangement feels like it’s working. The business hasn’t been breached. The systems are running. There is no visible reason to change anything, and in a small business where every dollar and every hour is already committed, “no visible reason to change” is a powerful defense for the status quo.

But data suggests that this confidence may be misplaced. Coalition’s 2025 small business cybersecurity study found that 79 percent of SMBs experienced at least one cyberattack in the past five years, but 64 percent still don’t believe they are an attractive target for attackers. That is a gap between experience and self-perception. The numbers suggest that even businesses that have already been attacked still don’t believe they’re the kind of business that gets attacked.

A non-specialist can build a security posture that looks complete from the inside—firewall, antivirus, and so on.  But a professional assessment will find unpatched systems, misconfigured cloud permissions, no network segmentation, no tested recovery process, no logging, no monitoring, and no formal incident response plan. The Guardz survey found that only 34 percent of SMBs have an incident response plan developed with professional cybersecurity expertise. That means two-thirds of small businesses will be improvising when something goes wrong.

Why Small Businesses Are Disproportionately Targeted

The accidental IT problem would be less urgent if small businesses were less interesting to attackers. They aren’t. Research from Barracuda Networks found that employees at companies with fewer than 100 staff face 350 percent more social engineering attacks than their counterparts at larger organizations. Attackers understand the math: small businesses hold valuable data, process real financial transactions, and have meaningfully weaker defenses. The ROI on attacking a 30-person professional services firm is often better than attacking a 3,000-person enterprise with a full security operations center.

And the attack doesn’t need to be sophisticated. Over and over, we see phishing breaches at SMBs that trace back to a single untrained employee. One person, one email, one click. In a business where the person responsible for security is the same person configuring the printers, the odds that an effective security awareness program is in place are not strong.

The average eCrime breakout time, the window between initial access and lateral movement through a network, fell to 48 minutes in 2024 according to CrowdStrike’s Global Threat Report. The fastest observed was 51 seconds. A small business with no monitoring, no segmentation, and no dedicated security staff doesn’t have 48 minutes to respond. It has zero minutes, because nobody is watching.

What to Do About It

I’m not going to suggest that every 25-person company should hire a full-time chief information security officer. That isn’t realistic, and pretending doesn’t help anyone. What I will suggest is that there are concrete, affordable steps between “the office manager handles it” and “we have an enterprise security team,” and most small businesses haven’t explored them.

Separate the day-to-day from the strategic. The person who resets passwords and troubleshoots the printer can keep doing that. What they should not be doing is making decisions about firewall rules, cloud security configurations, data retention policies, or incident response procedures. Those decisions require expertise that most self-taught IT generalists don’t have, and the consequences of getting them wrong are disproportionate to the apparent complexity of the task. A misconfigured cloud permission looks like a checkbox. The breach it enables does not.

Implement a managed security baseline. The economics of managed security services have changed dramatically over the past five years. For a few hundred dollars per user annually, a managed service provider or managed security service provider can deliver monitoring, endpoint protection, patch management, and incident response capabilities that would be impossible to replicate with an internal non-specialist. ConnectWise’s State of SMB Cybersecurity research found that roughly nine in ten SMBs would consider a new IT service provider if it offered the right cybersecurity solution. The appetite is there. What’s missing, for most businesses, is the push to act before something forces the decision.

Test what you think you have. If your accidental IT person has built a backup system, test it. If they’ve configured a firewall, have someone review the rules. If they say email is secured, ask them to explain exactly what that means and whether it includes DMARC enforcement, phishing filtering, and compromised credential monitoring. Many of the confidence gaps identified in the research above stem from assumptions that were never verified. Verification is cheap. Recovery from a breach enabled by an untested assumption is not.

Create an incident response plan before you need one. This is the item that most consistently separates businesses that survive a breach from businesses that don’t. It doesn’t need to be a fifty-page document. It needs to answer a short list of questions: Who do we call first? Who has authority to shut systems down? Where are our backups, and when did we last confirm they work? What are our legal notification obligations? Who talks to customers? Having these answers written down and accessible before an incident occurs is the difference between a structured response and a room full of people making phone calls at random.

Get an outside assessment. The single most valuable thing a small business can do is bring in someone who doesn’t work there to look at what’s actually in place. The accidental IT person has been building for years, and they’ve been doing it without a second opinion. They don’t know what they don’t know, and the only way to find out is to have someone with professional security experience walk through the environment, review the configurations, and identify the gaps. This doesn’t need to be a six-month engagement. A focused security assessment takes days, not months, and the output is a prioritized list of what to fix first.

An Essential Conversation

The hardest part of addressing this problem won’t be the technical work. It’ll be the discussion you’ll need to have with the person who has been handling IT. They’ve been doing it for years, often without recognition, usually without additional compensation, and frequently under the assumption that they were doing a good job. In most cases, they were doing a good job relative to what they knew. The issue isn’t their performance. It’s the scope of what they were asked to cover with the training they were given.

That conversation needs to happen with respect, with specificity, and with a clear acknowledgment that the gap is an organizational failure, not a personal one. The business owner who let the office manager become the IT department made a resource decision, and it’s the business owner’s responsibility to recognize when that decision has been outgrown by the threat environment.

CrowdStrike’s research tells us that 93 percent of small businesses believe they understand cybersecurity. The Guardz survey tells us that more than half are relying on someone untrained to manage it. Both of those things can’t be true at the same time. In most of the businesses I work with, resolving that contradiction starts with a single honest question: who is actually responsible for our security, and are they equipped for what that means in 2026?  The answer, more often than anyone would like to admit, is someone who never applied for the job.

Leave a Reply

Your email address will not be published. Required fields are marked *