The numbers behind the risk.
All statistics from our funding page in detail – with source, sample and context. So you can judge for yourself how big the risk is for your company.
Small companies are the focus.
Attackers increasingly rely on many small, simple attacks instead of a few big ones. This mostly hits companies that lack the time and know-how for their own IT security.
of reported attacks, e.g. with ransomware, targeted small and medium-sized companies.
police reports of ransomware attacks in the reporting period.
of them with a data leak – the data was not only encrypted but also stolen.
Based on reported attacks. Not every incident is reported to the police.
What an attack costs.
A successful attack means downtime, effort and, in the worst case, the end of the business.
is the average damage caused by a successful attack.
of downtime on average after an attack – 31.6 h worldwide.
of attacked SMEs saw their solvency or existence significantly endangered.
Prevention costs less than an emergency.
- Average damage of an attack€25,000
- Your own share with the Starter package (max.)€4,000
HDI and Hiscox are insurers. In the HDI study, the average damage has dropped significantly compared with earlier studies (at least €68,000). A comparison does not replace an individual risk assessment.
Why attacks succeed.
Companies that suffered damage from cyberattacks name these causes. Most of them are covered by our three building blocks.
- Insufficient detection of security incidentsSoftware & hardware59%
- MisconfigurationsCurrent-state analysis57%
- Insufficient identity and access managementCurrent-state analysis55%
- Technical vulnerabilitiesCurrent-state analysis50%
- Outdated hardware or softwareSoftware & hardware43%
- Insufficient security awareness among employeesHuman factor18%
- Attack via suppliers or service providers8%
The most common way in: the inbox.
This is how attacked small and medium-sized companies were targeted in the last 12 months. This is exactly where the “human factor” building block comes in.
- Phishing64%
- Emails with malware47%
- Accidental malware download30%
Almost every company is affected.
Share of companies affected by data theft, industrial espionage or sabotage in the last 12 months – analogue and digital.
Affected companies 2021 – 2026
| Affected | Probably affected | |
|---|---|---|
| 2021 | 88% | 12% |
| 2022 | 84% | 9% |
| 2023 | 72% | 8% |
| 2024 | 81% | 10% |
| 2025 | 87% | 10% |
| 2026 | 67% | 29% |
suffered damage from cyberattacks in the last 12 months.
consider themselves very well prepared for cyberattacks. In 2025 it was 50%.
Notably, in 2026 far more companies can only suspect an attack but not prove it – 29% instead of 10% the year before.
New gaps every day.
Software is constantly being developed – and with it, new vulnerabilities appear. If you don’t update regularly, you stay vulnerable.
new vulnerabilities became known per day on average – worldwide, across all kinds of IT systems.
„For example, known vulnerabilities in perimeter systems are far too often patched too late or not at all.“
Around 24% more than the previous year – according to the BSI partly due to a changed reporting policy.
Sources & methodology
We only use current studies and always name the publisher, sample and period.
All information without guarantee. Research as of 29 Sep 2026. Percentages are taken over rounded.
And your company?
Find out in a few minutes whether you can use the funding – and save up to 50% of your costs.