Skip to content
As of September 2026

The numbers behind the risk.

All statistics from our funding page in detail – with source, sample and context. So you can judge for yourself how big the risk is for your company.

Small companies are the focus.

Attackers increasingly rely on many small, simple attacks instead of a few big ones. This mostly hits companies that lack the time and know-how for their own IT security.

80%

of reported attacks, e.g. with ransomware, targeted small and medium-sized companies.

950

police reports of ransomware attacks in the reporting period.

72%

of them with a data leak – the data was not only encrypted but also stolen.

Based on reported attacks. Not every incident is reported to the police.

BSI, The State of IT Security in Germany 2025 · reporting period July 2024 – June 2025 · report data: Federal Criminal Police Office (BKA)

What an attack costs.

A successful attack means downtime, effort and, in the worst case, the end of the business.

€25,000

is the average damage caused by a successful attack.

41.7 h

of downtime on average after an attack – 31.6 h worldwide.

33%

of attacked SMEs saw their solvency or existence significantly endangered.

Prevention costs less than an emergency.

  • Average damage of an attack€25,000
  • Your own share with the Starter package (max.)€4,000

HDI and Hiscox are insurers. In the HDI study, the average damage has dropped significantly compared with earlier studies (at least €68,000). A comparison does not replace an individual risk assessment.

Why attacks succeed.

Companies that suffered damage from cyberattacks name these causes. Most of them are covered by our three building blocks.

  • Insufficient detection of security incidentsSoftware & hardware59%
  • MisconfigurationsCurrent-state analysis57%
  • Insufficient identity and access managementCurrent-state analysis55%
  • Technical vulnerabilitiesCurrent-state analysis50%
  • Outdated hardware or softwareSoftware & hardware43%
  • Insufficient security awareness among employeesHuman factor18%
  • Attack via suppliers or service providers8%

Bitkom Research, Wirtschaftsschutz 2026 · base: 580 companies with damage from cyberattacks · multiple answers possible

The most common way in: the inbox.

This is how attacked small and medium-sized companies were targeted in the last 12 months. This is exactly where the “human factor” building block comes in.

  • Phishing64%
  • Emails with malware47%
  • Accidental malware download30%

HDI KMU-Cyberstudie 2026 (Sirius Campus for HDI) · around 1,100 decision-makers from SMEs plus self-employed and freelancers · multiple answers possible

Almost every company is affected.

Share of companies affected by data theft, industrial espionage or sabotage in the last 12 months – analogue and digital.

Affected companies 2021 – 2026

AffectedProbably affected
Affected companies 2021 – 2026
AffectedProbably affected
202188%12%
202284%9%
202372%8%
202481%10%
202587%10%
202667%29%
58%

suffered damage from cyberattacks in the last 12 months.

43%

consider themselves very well prepared for cyberattacks. In 2025 it was 50%.

Notably, in 2026 far more companies can only suspect an attack but not prove it – 29% instead of 10% the year before.

Bitkom Research, Wirtschaftsschutz 2026 · 1,003 companies with 10+ employees, surveyed April – June 2026

New gaps every day.

Software is constantly being developed – and with it, new vulnerabilities appear. If you don’t update regularly, you stay vulnerable.

119

new vulnerabilities became known per day on average – worldwide, across all kinds of IT systems.

„For example, known vulnerabilities in perimeter systems are far too often patched too late or not at all.“

— BSI, situation report 2025 (translated)

Around 24% more than the previous year – according to the BSI partly due to a changed reporting policy.

Source: BSI situation report 2025

And your company?

Find out in a few minutes whether you can use the funding – and save up to 50% of your costs.