The smallest businesses are falling the furthest behind on cybersecurity, according to a new report from Crowdstrike, with very few having the budget, tools or in-house expertise to stop modern threats.
Crowdstrike’s 2025 State of SMB Cybersecurity Report found that despite 93% of small and medium-sized businesses (SMBs) considering themselves knowledgeable about cybersecurity risks, and 83% having a security plan in place, just 36% are investing in new tools, and even fewer (11%) have adopted AI-powered defences.
The situation is worse among SMBs with fewer than fifty employees, with only 47% reporting having a security plan in place, although Crowdstrike pointed out that businesses with security plans were as likely to fall victim to cyber incidents (25%) as those without (24%), suggesting many plans are underdeveloped or not effectively implemented.
The research, based on a survey of 291 SMB business leaders, shows that cost concerns are a major driver of security decisions, with 67% of SMBs prioritising affordability when selecting a cybersecurity solution, versus 57% more focused on protection against advanced threats.
Cost pressures are forcing these companies to make difficult choices that they know could impact their security, with only 6.5% believing their current cybersecurity budget is truly sufficient, and more than half allocating less than 1% of their annual budget to cybersecurity.
SMB’s security plans also might be suffering from an overload of choices. Half (50%) of SMB leaders feel overwhelmed by the number of cybersecurity tools on the market, and nearly 70% said that they rely on third-party guidance to inform buying decisions.
Firewalls (91%), MFA tools (89%), and traditional antivirus software (70%) are by far the most used cybersecurity tools of SMBs, with just 11% currently using AI-powered security.
SMB leaders are all too aware of the danger in continuing to rely on these legacy tools as a core part of their defence.
Among the top three emerging threats most worrying for SMBs are AI-powered cyber-attacks (48%), deepfake and social engineering scams (48%) and cloud security risks (37%), highlighting a dangerous disconnect between the tools these businesses depend on and the evolving threat landscape.
That is having a noticeable impact on the success of SMB’s security strategies, with the smallest firms often being hit the hardest.
Recommended reading
- SMBs Increasingly Targeted by Cybercriminals in 2024
- Samsung: Bad Tech Costing UK SMEs £300K Every Year
- Majority of Scottish SMEs Expect AI to Boost Productivity
Among SMBs with under 25 employees who experienced a cyber incident in the past year, 29% reported ransomware, compared to 19% among medium-sized firms – a worrying number when three-quarters of micro businesses said that a cyber-attack would either likely or definitely put them out of business.
“SMBs are increasingly aware of the cyber risks they face, but remain vulnerable to modern threats,” said Lisa Campbell, vice president of SMB at CrowdStrike.
“Many know they need stronger protection but are held back by limited time, resources and expertise. They need solutions that are affordable and effective, without adding complexity – so they can turn awareness into action.”





