Desk live·
ForensicPost
Breaches/Small business/File 25-0611b

19% of Small and Medium Businesses Face Bankruptcy After a Cyberattack

Survey research reports that roughly 19% of small and medium businesses face bankruptcy following a cyberattack. Nothing else in this corpus has that consequence.

Constructed geometry · not a chart of case data
TargetSmall and medium businesses
ActorMultiple
S. Rosler12 min readConfidence: medium2 sources reviewed

Industry research reports that around 19% of small and medium businesses face bankruptcy following a successful cyberattack, with separate survey work finding nearly one in five would be forced to close.

The Corpus Has No Comparable Outcome

Jaguar Land Rover lost five weeks of production and £196 million, at 25-0902, and continued. Nevada lost sixty agencies for 28 days, at 25-0922, and continued. Co-op lost every member record, at 25-0501, and continued.

Large organisations absorb these incidents. That is what the cost figures at 25-0808 and 25-0616 describe — expensive, survivable events, priced into a balance sheet.

For a fifth of small firms the same event is terminal. It is a different category of harm that the corpus has been measuring on a scale built for the other one.

Which Means Deterrence Works Differently At The Small End

This desk filed at 25-1121 that a maximum penalty is an order of magnitude below what a serious incident costs a large company, and that the regulator is not the most expensive consequence — the failure is.

At the small end that is even more true, and it removes the argument for penalties entirely. A firm that would go bankrupt from the incident cannot be additionally deterred by a fine, and fining a business that has just been destroyed serves no purpose anybody would defend.

And It Explains The Compliance Gap

The corpus filed at 25-1223 that an obligation without capacity produces non-compliance rather than security, and at 25-1211 that budget cuts overtook talent scarcity as the reported cause of staffing shortfalls.

A firm facing closure from a $50,000 loss, per 25-0612b, is not making a considered trade-off about security investment. It has no version of the decision available.

Graded medium: these are self-reported survey findings about a hypothetical, not observed closure rates. Whether firms that say they would close actually do is not established anywhere this desk could find.

This is an analysis file

Built on published survey research, listed below. Findings are self-reported responses to hypothetical scenarios, not observed outcomes. Corrections: corrections@forensicpost.com.

Sources
  1. SMB cybersecurity survey statistics and threatsVikingCloud
  2. Must-know small business cybersecurity statisticsBD Emerson
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary