Don't wait for a cyberattack: What previously breached businesses do differently

Cristina POPOV

September 11, 2026

Don't wait for a cyberattack: What previously breached businesses do differently

A cyberattack has a way of turning cybersecurity from something you know you should think about into something you can't afford to ignore.

According to the 2026 Small Business Cybersecurity Awareness & Practices Survey, businesses that have experienced a breach report stronger cybersecurity preparedness than those that haven't, particularly when it comes to planning for an incident. The survey included 1,000 US business leaders and decision-makers from companies with between 2 and 1,000 employees across 10 industries.

The findings raise a question for small business owners: Why wait for a cyberattack to start preparing for one?

Key takeaways:

  • Businesses that have experienced a breach report stronger cybersecurity preparedness than those that haven't.
  • The biggest differences appear in incident response planning, MFA adoption, backup testing and how regularly leaders review cybersecurity risks.
  • Businesses don't have to experience a cyberattack themselves to adopt the security practices that are more common among those that have.

What businesses do differently after experiencing a cyber breach

The 2026 survey shows a clear difference between businesses that have already experienced a breach and those that haven't. And it shows up in several areas of cybersecurity.

Incident response: Nearly three-quarters (74.9%) of previously breached businesses have a documented incident response plan that employees follow, compared with 51.5% of businesses that haven't been breached. Perhaps more telling, 30.3% of businesses with no previous breach have no response plan at all, compared with just 5.9% of those that have already been through one.

Multi-factor authentication: The same pattern appears with MFA. 58.4% of previously breached businesses use MFA across most or all key accounts, compared with 44.8% of those that haven't been breached. And while 13.8% of businesses with no previous breach don't use MFA at all, that drops to 5.9% among those that have experienced one.

Backup testing: Previously breached businesses are also more likely to know whether their backups actually work. 70.3% say they have tested their backups, compared with 53.8% of businesses that haven't experienced a breach. That's an important distinction: having a backup is useful, but only if you can restore your data when you actually need it.

Cybersecurity reviews: Previously breached businesses also tend to check their cybersecurity risks more often. Nearly a third (31.5%) review them every month, compared with 19.8% of businesses that haven't experienced a breach. At the other end, 17% of businesses with no previous breach review cybersecurity rarely or never, compared with just 4.8%of those that have already experienced one.

You don't need to experience an attack to protect your business

So what can you do differently now? Start with the same areas where the survey shows the clearest gaps between previously breached and non-breached businesses.

1. Have an incident response plan before you need one

Start by deciding what happens if something goes wrong: Who needs to be contacted? Who is responsible for making decisions? Which systems and data need to be protected first? Where are your backups? How will you communicate if your usual email or other systems aren't available?

Make sure employees know how to report a suspicious email, compromised account, lost device or other security incident, and who they should contact: an external IT provider, cybersecurity company, insurer or other specialist.

Related: Can your small business be hacked without you knowing?

2. Use MFA on the accounts that matter most

Stronger account security can help prevent an attacker from getting in in the first place.

Enable MFA wherever it's available, with particular attention to accounts that could give an attacker access to other parts of your business. That includes business email, Microsoft or Google administrator accounts, cloud storage, banking and payment services, accounting software, social media, and systems containing sensitive customer or employee information.

Related: Your business uses MFA. But are you using it on the right accounts?

3. Back up your data and test whether you can restore it

Even with good security in place, you still need to be prepared to recover if an incident disrupts your business.

Identify the data your business couldn't easily operate without and make sure it's backed up regularly. Depending on your business, that might include customer records, financial documents, contracts, project files or other essential information.

Then test your backups occasionally rather than assuming they're working. Try restoring a file, check that the most important folders are actually included, and make sure you know how to access your backups if your usual device or account is compromised.

Related: You Back Up Your Business Data. But Could You Actually Restore It?

4. Review your cybersecurity regularly

A simple monthly check is a good place to start. Ask what's changed since your last review: Have you added a new payment platform, employee laptop or cloud service? Are there old accounts or access permissions you no longer need? Are MFA and backups still working as expected?

Make these checks part of running your business, rather than something you start thinking about only after an attack.

And if you don't have dedicated IT staff, the right security tools can make protecting your business easier.

Bitdefender Ultimate Small Business Security is designed for small businesses that may not have dedicated IT staff. It helps protect business devices, accounts and employees against malware, ransomware, phishing, scams and other online threats, while giving business owners visibility over security from one dashboard.

Try Bitdefender Ultimate Small Business Security free for 30 days. No credit card required.

You may also want to read:

FAQs

Does a small business really need an incident response plan?

Yes. Even a very small business can benefit from a simple incident response plan. You don't need a large IT department or a lengthy document. Knowing who to contact, what to protect first and how to keep operating can save valuable time during a cyberattack.

What should a small business do first after a cyberattack?

The first steps depend on the type of attack, but generally you should contain the incident, prevent further unauthorized access, preserve relevant information about what happened and contact the appropriate IT or cybersecurity support. Avoid making major changes or deleting information until you understand the incident, as this could make investigation more difficult.

How can a small business prepare for a cyberattack?

Start by identifying the devices, accounts and data your business relies on most. Use strong, unique passwords and multi-factor authentication, keep software updated, protect business devices, back up important data, train employees to recognize scams and phishing, and create an incident response plan so everyone knows what to do if something goes wrong.

tags


Author


Cristina POPOV

Cristina Popov is a Denmark-based content creator and small business owner who has been writing for Bitdefender since 2017, making cybersecurity feel more human and less overwhelming.

View all posts

You might also like

Bookmarks


loader