Read the denominator first
- FBI IC3 figures describe reported complaints and losses, not every incident or a typical SMB loss.
- Verizon DBIR percentages describe its analyzed breach sample, not the probability your business will be breached.
- Use these signals to test exposed systems, recovery and payment controls; set budgets from your own assets and quotes.
- This page replaces older unsourced “industry average” and ROI claims with dated primary-source figures.
Last updated: September 25, 2026
Cybersecurity numbers are easy to misuse. A worldwide breach statistic cannot tell a ten-person firm what it will lose, and a complaint count does not measure how many businesses were attacked. The figures below are useful when their population and limits stay attached. They should help the owner choose a verification task, not become a promised risk-reduction percentage or a sales forecast.
Three current signals, with limits
| Primary source and period | Reported figure | What it does and does not mean | Practical check |
|---|---|---|---|
| FBI IC3 2025 report, complaints received in 2025 | 1,008,597 complaints and $20.877 billion in reported losses | US internet-crime complaints across crime types; not SMB-only incidence or a typical company loss | Confirm bank-change callbacks and the incident contact list |
| Verizon 2026 DBIR, analyzed breaches from Nov. 2024 to Oct. 2025 | 31% of breaches started with software vulnerabilities, as summarized by Verizon | Share of the DBIR's analyzed breach set; not the chance of compromise for your environment | Find exposed software and overdue high-risk updates |
| Verizon 2026 DBIR, same analyzed set | 48% of breaches involved ransomware, as summarized by Verizon | Involvement within the report's cases; not an SMB-specific annual attack rate | Test an isolated restore and ransomware response contact |
The Verizon report methodology draws from contributors such as law enforcement, forensic firms, insurers and Verizon's casework. Its analyzed population changes across years, so a year-over-year difference may reflect sources and definitions as well as threat change. IC3 totals depend on what victims report. Do not add the two datasets, divide their figures into an invented “average loss,” or apply either percentage to your own forecast.
Turn a statistic into a local measurement
For vulnerability exposure, count internet-facing systems, supported versus unsupported software and overdue priority updates. For ransomware resilience, record backup scope, last restore result, alert owner and time to reach a responder in a drill. For payment fraud, count bank-detail changes that received an independent callback and second approval. These measures can be checked against your own baseline after the assessment and 90-day roadmap.
| Local metric | Good evidence | What not to infer |
|---|---|---|
| MFA coverage | Enrollment export and exception review | An invoice proves coverage |
| Patch status | Device inventory with overdue items | Every vulnerability is exploitable or identical risk |
| Recovery readiness | Dated test of a critical workflow | A backup-job success equals business recovery |
| Outbound referral economics | Approved commissions and real clicks | A click equals a purchase |
How to use the numbers in a budget meeting
Start with the critical workflows, known gaps and the cost to operate a control. Request quotes for the exact plans and units needed; add setup, support and renewal. The budget worksheet accepts real amounts without industry multipliers. If data is unavailable, leave it unknown. The security checklist gives an owner and evidence field for the control work.
Editorial rule for statistics
Every numerical claim should keep its source, publication year, measured period, population, denominator and caveat. If those are missing, do not turn it into an SMB benchmark.
Sources checked September 25, 2026: FBI IC3 2025 Annual Report and Verizon 2026 DBIR. Their figures are third-party observations, not Valydex measurements or forecasts.