
Did you know that 8 controls block the vast majority of small business cyber attacks? Multi-factor authentication and the right cyber liability policy do most of the heavy lifting. Read below to explore why, and what the 2026 Canvas breach reveals about the risks every owner now faces.
The Canvas breach is a wake-up call for every business owner
On May 1, 2026, the education software giant Instructure disclosed that hackers from the group ShinyHunters had stolen roughly 3.65 terabytes of data from its Canvas learning platform. Recent reporting pegs the exposure at an estimated 275 million records across roughly 8,809 schools and universities, making it the largest education-sector cyber incident publicly disclosed to date. Six days later, attackers defaced the Canvas login page with a ransom demand right as students sat down for finals.
If you run a small or mid-size business, the Canvas story should land close to home. Cybercriminals no longer target only the Fortune 500. They hit dental offices, accounting firms, construction companies, retail shops, manufacturers, and nonprofits because those organizations hold valuable data and often run leaner security programs. The good news: most attacks succeed because of preventable mistakes, and the fixes do not require a Fortune 500 budget.
This guide walks through the cybersecurity risks that matter most for small businesses in 2026, the preemptive measures that close the gap before an attacker walks through it, and the cyber insurance details that decide whether a breach becomes a footnote or a closure event.
What are the biggest cybersecurity risks for small businesses in 2026?
Small businesses face a short list of threats that account for the majority of incidents.
-
Phishing and business email compromise. Attackers send convincing emails that trick employees into clicking malicious links, sharing credentials, or wiring money. The FBI’s Internet Crime Complaint Center recorded $2.77 billion in business email compromise losses in 2024 alone, against $16.6 billion in total reported cybercrime losses for the year.
-
Ransomware. Criminals encrypt your files and demand payment. Many groups now steal data first and threaten to leak it, the same playbook ShinyHunters ran against Canvas. Verizon’s 2025 Data Breach Investigations Report found that ransomware was present in 88% of breaches affecting small and mid-size businesses, more than double its share of breaches overall.
-
Vendor and supply chain breaches. When a software vendor, payroll provider, or cloud platform gets hacked, your data goes with it. The Canvas incident shows how one vendor breach cascades across thousands of customers in a single day.
-
Stolen or weak credentials. Reused passwords and missing multi-factor authentication remain a leading entry point for intrusions in the Verizon DBIR and CISA advisories year after year.
-
Insider mistakes. Misconfigured cloud storage, lost laptops, and accidentally shared spreadsheets cause a meaningful share of breaches every year.
-
AI-powered social engineering. Generative AI now produces fluent phishing emails, cloned voices, and deepfake video calls. Finance and operations teams increasingly report attempted wire fraud built on AI-generated audio of company executives.
How much does a cyber attack cost a small business in 2026?
The IBM Cost of a Data Breach Report 2025 puts the global average breach cost at $4.44 million, down from $4.88 million the year before, while the U.S. average climbed to a record $10.22 million. The Verizon 2025 DBIR reported a median ransom payment of roughly $115,000, a meaningful number for any small business.
The ransom itself usually accounts for only a fraction of the total. Business interruption, forensic investigation, customer notification, credit monitoring, regulatory defense, and the long tail of reputational damage often cost a small business several times more than the original demand. Many small companies struggle to fully recover from a serious incident, and some close their doors when cash flow stalls during weeks of downtime.
Industry-specific cyber risks small businesses should watch
Different industries draw different attackers and different regulatory penalties.
-
Healthcare and dental practices hold protected health information and face HIPAA civil monetary penalties that, in 2025, start at $145 per violation in the lowest tier and reach up to $2,190,294 per identical provision per calendar year (HHS, inflation-adjusted).
-
Law firms and CPAs hold client trust account information and tax data, both prime ransomware targets.
-
Construction and manufacturing lose revenue quickly when ransomware halts project management software or operational technology.
-
Retail and hospitality carry PCI exposure on every credit-card transaction and now operate under comprehensive consumer privacy laws in nearly 20 U.S. states, including California, Colorado, and Texas.
-
Professional services and consulting rely heavily on email and cloud document sharing, which makes them especially vulnerable to business email compromise.
Knowing the threat profile for your industry shapes both your security spending and your insurance limits.
8 pre-emptive cybersecurity measures every small business should take in 2026
You do not need a chief information security officer to dramatically lower your risk. Focus on the controls that block the most common attack paths.
1. Turn on multi-factor authentication everywhere
Microsoft has published research showing that multi-factor authentication blocks more than 99% of account compromise attacks. Enable it on email, banking, payroll, cloud storage, remote access, and any administrator account. Use an authenticator app or a hardware key instead of SMS wherever the application supports it, because attackers can intercept text messages through SIM-swap fraud.
2. Train your team to spot phishing and AI-driven scams
Run quarterly phishing simulations and short training videos that include AI-generated voice and video examples. Make sure employees know exactly how to report a suspicious email or voicemail, and reward the people who flag attempts. A single alert employee can stop a wire-transfer fraud attempt before money leaves the building.
3. Patch fast and remove unused software
CISA’s Known Exploited Vulnerabilities catalog shows that ransomware actors regularly exploit CVEs that already have patches available, often targeting internet-facing systems that organizations left unpatched. Set operating systems, browsers, and business apps to auto-update. Uninstall anything you do not actively use, especially old remote-access tools, abandoned plugins, and legacy file-sharing services that attackers scan for.
4. Back up your data and test the restore
Follow the 3-2-1 rule: three copies of your data, on two types of media, with one copy stored offline or in an immutable cloud bucket. Test a restore at least once a quarter. A working backup turns a ransomware event into an inconvenience instead of a catastrophe.
5. Vet your vendors and lock down your supply chain
Ask any vendor that touches your data three questions. Do you carry SOC 2 or ISO 27001 certification? Do you encrypt data at rest and in transit? Do you carry cyber insurance? Add those answers to your vendor file, revisit them annually, and require breach notification clauses in every contract. The Canvas breach shows what happens when a single vendor fails those checks.
6. Limit access with the principle of least privilege
Give each employee only the permissions the job requires. Remove access the day someone leaves. Audit shared drives, cloud apps, and database roles every quarter. Separate administrator accounts from daily-use accounts, and never let an admin account read email or browse the web.
7. Write an incident response plan you can actually use
A one-page playbook beats no plan at all. Document who calls the insurer, who notifies customers, who talks to law enforcement, who manages the press, and who restores systems. Include phone numbers for your IT provider, your cyber insurance carrier, and outside legal counsel. Print it. When systems go down, you cannot rely on the wiki.
8. Carry the right cyber insurance
Even strong defenses fail. A well-built cyber policy covers forensic investigation, ransom negotiation, customer notification, regulatory defense, business interruption, and legal costs. Many policies also fund proactive services like phishing training, dark web monitoring, and vulnerability scans before any incident occurs.
What does a strong cyber insurance policy include?
A modern cyber liability policy for a small business should include the following coverages without surprise sub-limits.
-
First-party coverage for ransomware payments, data restoration, business interruption, contingent business interruption from a vendor outage, and cyber extortion negotiation.
-
Third-party coverage for privacy liability, regulatory defense, PCI fines and assessments where insurable, media liability, and class-action defense.
-
Breach response services including a 24/7 incident hotline, forensics, legal counsel, notification, and credit monitoring for affected customers.
-
Social engineering and funds transfer fraud coverage with a limit that matches your real wire-transfer exposure.
-
Affirmative coverage for AI-driven attacks, including deepfake fraud, which some carriers still exclude.
If your current policy lacks any of these, you have a coverage gap that can cost you more than the premium savings.
How do I know if my current cyber coverage is enough?
Most business owners discover gaps only after a claim. Common problems include sub-limits that cap ransomware payouts at a fraction of the policy face value, exclusions for social engineering losses, missing coverage for regulatory penalties, and no contingent business interruption for vendor outages like the Canvas breach.
A coverage review with SandStone compares your cyber liability policy against your real-world exposure and benchmarks it against current market standards. Carriers also increasingly reward strong security controls with lower premiums, so a review often pays for itself.
Your 30-day cybersecurity action plan
You do not need to fix everything at once. Use this 30-day plan to make meaningful progress fast.
Week 1, lock the doors. Turn on multi-factor authentication for email, banking, and any admin accounts. Change default passwords on routers, firewalls, and printers.
Week 2, train your people. Send a phishing simulation, hold a 30-minute team training, and post your incident response phone list near every workstation.
Week 3, back up and patch. Verify your backups work by restoring a test file. Enable auto-updates on every device. Remove unused software.
Week 4, review insurance and vendors. Call SandStone Insurance Partners for a cyber coverage review. Send your top five vendors a short security questionnaire and file the answers.
Frequently asked questions about small business cybersecurity
Does my general liability policy cover a cyber attack?
No. Standard general liability policies exclude cyber events. You need a dedicated cyber liability policy to cover ransomware, data breaches, and regulatory defense costs.
Are small businesses really a target for hackers?
Yes. Verizon’s 2025 Data Breach Investigations Report found ransomware in 88% of breaches affecting small and mid-size businesses, compared to 44% across all breaches. Attackers consistently view smaller organizations as softer targets than large enterprises with full security teams.
How fast can a cyber attack take down my operations?
Modern ransomware can encrypt files across a network within hours of initial access. The downtime that follows varies widely by organization, but industry reporting routinely cites recovery timelines stretching from several days to several weeks, and some systems never fully come back.
What is the single most cost-effective cybersecurity control?
Multi-factor authentication, by a wide margin. Microsoft’s published research shows it blocks more than 99% of account compromise attacks, and most cloud platforms now include it at no extra cost.
How often should I review my cyber insurance policy?
Review your cyber insurance policy at least once a year and any time you change technology vendors, add a new product line, expand into a new state, or hire significantly more employees. Coverage that fit your business two years ago may leave dangerous gaps today.
How much cyber insurance does a small business need?
Industry data shows most small businesses carry cyber liability limits between ~$1 million and $5 million per occurrence, with $1 million as the most common starting point. The right number depends on your revenue, the type of data you hold, your contractual requirements with customers, and your industry. A coverage review pins down the right limit for your situation.
What should I do first if I think I have been hacked?
Disconnect affected devices from the network, preserve evidence, call your cyber insurance carrier’s 24/7 hotline, and avoid powering systems off until forensics arrive. Do not pay any ransom before talking to your insurer and legal counsel.
Protect your business before the next headline
The Canvas breach reminded every business owner that one vendor, one missed patch, or one phishing click can put hundreds of thousands of customers at risk. You can act today. Turn on multi-factor authentication, train your team, back up your data, vet your vendors, and make sure your cyber insurance actually covers the threats your business faces in 2026.
Schedule a free cyber coverage review with SandStone Insurance Partners
SandStone Insurance Partners specializes in helping small and mid-size businesses build cyber programs that match real-world risk. We review your existing policy, identify potential gaps, and place coverage with carriers who support you if and when the worst happens. One conversation can keep your business out of next year’s breach headlines and put real protection in place before the next attack hits your industry.
Contact SandStone Insurance Partners to get started and request your no-obligation cyber risk assessment.
Disclaimer: This blog provides general educational information about small business insurance and is not legal, financial, or insurance advice. Coverage availability, eligibility, sublimits, exclusions, and policy features vary by state, carrier, industry, and individual underwriting. For coverage recommendations specific to your business, contact a licensed agent from SandStone.


