It is the single most common thing we hear in a first conversation: “We're probably too small for anyone to bother with us.” It feels reasonable. It is also, almost word for word, the assumption that precedes most of the incidents we get called in to clean up.

The misunderstanding is about how attacks actually happen. People picture a hacker choosing a target, studying it, and going after it. That does happen — to banks and governments. It is not what happens to a fifteen-person firm. What happens to a fifteen-person firm is automated.

Most attacks never picked you

The overwhelming majority of breaches at small and mid-sized businesses begin with a machine, not a person. Bots scan enormous ranges of the internet looking for one thing: a door left open. A server missing a patch. A login with no second factor. A password that showed up in a previous leak. They are not reading your company name. They are checking, at scale, whether the lock turns.

Being small doesn't make you invisible to that. It usually makes you more exposed, because the same small size is often the reason the basics were never put in place. No one whose full-time job is security. No one testing the backups. A firewall someone configured years ago and nobody has looked at since.

The cost isn't scaled to your size

Here's the part that makes the myth expensive. The attacker's effort scales with their automation. Your loss scales with your dependence on the systems that go down. A ransomware event doesn't ask how many employees you have before it encrypts your files. For a small business, a week of downtime, lost records, and a scramble to rebuild can be existential in a way it simply isn't for a company with a recovery team on staff.

So the equation is backwards from how it feels. The businesses most likely to think they're not worth attacking are frequently the ones least able to absorb it when they are.

What actually changes the odds

The good news is that because most of this is automated and opportunistic, the same unglamorous fundamentals that protect a large enterprise work just as well for a small one. Multi-factor authentication on everything that matters. Systems kept patched. Backups that are tested, not just scheduled. Monitoring that notices the unusual login at 2 a.m. None of it is exotic. It just has to actually be in place, and stay in place.

That's the whole of our argument, really: you don't need to be a likely target to be a reachable one, and you don't need to be a large company to be protected like one. The standard is the same. The only question is whether someone is holding you to it.