The National Cybersecurity Alliance, working with CISA, surveyed 1,000 small business leaders across 10 industries. The results describe a false sense of security that’s remarkably consistent across small businesses of every size and industry.
The study found that 86% of small businesses feel confident about their cybersecurity. Yet about half reported a confirmed or suspected incident in the past 12 months.
Those two numbers don’t add up, and the survey explains why.
Having a Tool Isn’t the Same as Using It
Based on the study, small businesses aren’t ignoring security. It found that they’re buying the tools and not fully deploying them.
87% of respondents have MFA, but only 51% require it on all key accounts. That means nearly half the businesses with MFA installed have left some accounts unprotected.
Additionally, 88% have data backups, and only 61% have ever tested them. An untested backup is theoretical protection. It feels like insurance, but you don’t know whether it pays out until you need it, and a ransomware attack is a bad time to find out your backup hasn’t been running correctly for three months.
Finally, 87% use AI tools, yet 46% have formal guidelines governing that use. And according to separate NCA research, nearly a third of employees using AI at work have shared sensitive company information with an AI tool without their employer knowing. If your employees use AI tools you haven’t reviewed, you have no visibility into what data goes into them or where it goes afterward.
The survey consistently found that small businesses have good intentions when purchasing and installing certain products, but they aren’t using them fully.
Good Intentions Only Go So Far
Organizations that have experienced a breach report stronger security practices than those that haven’t. This includes broader MFA enforcement, tested backups, documented incident response plans, and more frequent risk reviews. The survey found this consistently across breach victims versus non-victims. In other words, getting hit is a wake-up call for most small businesses.
That’s a hard way to learn. The confidence that comes from having MFA deployed, backups running, and AI tools available creates the impression that security is handled, but that’s part of the problem. Nobody audits what they believe is already working.
“There’s a meaningful difference between having security tools and using them effectively,” said Lisa Plaggemier, Executive Director of the National Cybersecurity Alliance. “Whether it’s testing backups, enforcing multi-factor authentication across every account, or establishing clear policies for AI, resilience comes from consistently putting those practices into action.”
Not sure whether your security controls hold up when someone’s trying to get through them? That’s exactly what a penetration test is designed to find out, before an attacker does. Let’s talk about what that looks like for your environment.
The Self-Audit Nobody Does
Here’s a short version of what the survey is really asking. Take five minutes to answer these questions honestly.
MFA: Do you have MFA turned on? On which accounts specifically? Your business email, your banking platform, your accounting software, your cloud storage, your VPN or remote access tools? Are all of them covered, or just most of them? “Most of them” is where the breach happens.
Backups: Do you have backups running? When did someone last verify they completed successfully? Has anyone ever done a test restore to confirm the backup works? If the answer to either of the last two is “I’m not sure,” the backup is theoretical.
AI tools: Do you know which AI tools your employees are using for work? Do you have any policy, even a simple one, about what data they’re allowed to put into those tools? Have you considered whether any of those tools retain the data your employees feed them? If 46% of businesses with AI tools have no guidelines, there’s a reasonable chance yours is in that group.
Incident response: If something went wrong today, like ransomware, a phishing attack, or a compromised email account, does your team know what to do in the first hour? Who to call, in what order, and what not to do before forensics gets involved? A plan that exists only in someone’s head isn’t a plan.
Risk reviews: When did you last sit down and look at your security posture? Not troubleshoot a problem, not renew a software subscription, review what controls you have, whether they’re working, and what’s changed in your environment since the last time you looked?
Most small businesses can’t answer all five of those questions with confidence. It’s the findings of a survey of 1,000 businesses conducted by the people whose entire job is tracking this. The tools are there. The consistent follow-through isn’t.
The AI Piece Deserves Its Own Conversation
The AI governance gap in the survey (87% adoption, 46% with any formal guidelines) is the one that’s moving the fastest and getting the least attention.
AI adoption in small businesses has outpaced governance by a significant margin, and the risk isn’t abstract. Employees using AI tools to draft client proposals, summarize documents, or process data feed real business information into platforms with varying data retention practices, privacy commitments, and security controls. Consumer-tier AI tools in particular often have terms that give the provider broad rights to use inputs for model training. Most employees don’t know this.
The fix isn’t banning AI tools. That won’t work, and the productivity benefits are real. The fix is knowing which tools your employees are using, having a clear policy about what data is and isn’t appropriate to put into them, choosing enterprise-tier tools with stronger contractual data protections where sensitive information is involved, and training employees on the difference between approved tools and consumer tools they found on their own.
One in five breached organizations in IBM’s 2025 Cost of a Data Breach Report had experienced an incident involving shadow AI, which is employees using AI tools the organization never approved or reviewed. Those incidents added roughly $670,000 to the average breach cost. 97% of those organizations had no access controls for AI tools in place at all. The gap between “we use AI” and “we have rules about how we use AI” comes with a price tag.
The tools are there. The follow-through is missing, and that’s what MainNerve has helped organizations close for over 20 years. If you want an honest look at where your security posture stands, we’re glad to help. Reach us at mainnerve.com/contact-us or call 833-847-3280.
What to Do With This
The NCA survey isn’t describing a group of businesses that don’t care about security. It describes businesses that made the investment, felt covered, and stopped short of the follow-through that makes the investment work.
The distance between “we have MFA” and “we require MFA on every account that matters” is one policy decision and an afternoon of configuration. The distance between “we have backups” and “we have tested backups” is one scheduled restore test and a note in the calendar to do it again next quarter. The distance between “we use AI” and “we have a policy about AI” is one short conversation with your team and a one-page document that tells them what’s approved and what isn’t.
None of this requires a security team, and none of it requires a significant budget. You just need to stop treating “we have the tool” as the finish line when it’s really just the starting point.