Operate more efficiently, reduce complexity, improve EBITDA, and much more with the purpose-built platform for MSPs.
Protect and defend what matters most to your clients and stakeholders with ConnectWise's best-in-class cybersecurity and BCDR solutions.
Leverage generative AI and RPA workflows to simplify and streamline the most time-consuming parts of IT.
Join fellow IT pros at ConnectWise industry & customer events!
Check out our online learning platform, designed to help IT service providers get the most out of ConnectWise products and services.
Search our resource center for the latest MSP ebooks, white papers, infographics, webinars and more!
Join hundreds of thousands of IT professionals benefiting from and contributing to a legacy of industry leadership when you become a part of the ConnectWise community.
Join hundreds of thousands of IT professionals benefiting from and contributing to a legacy of industry leadership when you become a part of the ConnectWise community.
7/8/2025 | 7 Minute Read
Topics:
Cybercrime is big business. Threat actors are now AI-powered and highly organized. If cybercrime were a nation, it would have the third-largest GDP in the world, trailing behind only the United States and China. The stakes have never been higher for small and midsized businesses (SMBs).
In this blog, we unpack the latest SMB cybersecurity statistics and explore what they mean for MSPs who want to lead in this critical moment.
Cybercriminals are leveraging AI to automate and scale their attacks, making them harder to detect. According to The State of SMB Cybersecurity Report, 83% of SMBs state that AI/genAI increases the cybersecurity threat level for their organization, yet many remain underprepared. SMBs and MSPs alike must understand how AI is intensifying familiar attack methods to better defend against them.
The top threats using supercharged by AI include:
Phishing remains one of the most common and dangerous entry points for attackers. AI now enables cybercriminals to create highly realistic emails, messages, and websites that often impersonate trusted vendors or contacts. Whether it’s a spoofed login page or a well-written message from a “CEO,” phishing is designed to trick users into surrendering credentials, sharing confidential data, or providing access to systems.
BEC attacks are highly targeted attempts to impersonate a trusted individual or organization to trick employees into taking an action that results in financial loss or sharing confidential information. These AI-enhanced scams often take the form of an “urgent” request via convincing emails with accurate tone, language, and timing, making scams hard to spot.
From spyware and trojans to rootkits and keyloggers, malware is designed to infiltrate systems, steal data, monitor activity, or give attackers remote control over business networks.
Ransomware was once thought to primarily target large enterprises. But threat actors are increasingly focusing on SMBs because attackers perceive that SMBs have less cybersecurity protection and lack the robust backup and recovery capabilities of larger organizations.
These statistics reveal a clear pattern: cyberattacks are rising in volume, severity, and financial impact. According to Vanson Bourne research, 61% of SMBs worry that a serious cybersecurity attack could be enough to put them out of business.
The stakes are high. Phishing, BEC, and other social engineering attacks rely heavily on human error. Without proper training, employees can easily become the weakest link in an otherwise secure system. And as AI-generated phishing and deepfake scams grow more realistic, it’s becoming even harder for untrained users to distinguish between legitimate and malicious content.
Comprehensive cybersecurity awareness training can significantly reduce risk by helping employees:
In addition, according to the State of SMB Cybersecurity Report, only 51% of SMBs have implemented security policies and practices for AI/genAI. This gap suggests that many organizations are not educating their employees on how AI tools can be exploited or how they may inadvertently misuse applications that could lead to confidential data leakage.
MSPs differentiate themselves by offering security awareness training that helps SMB clients create a strong “human firewall.” These programs lower the likelihood of successful attacks and reinforce a security culture that protects the business from the inside out.
Based on the results of The State of SMB Cybersecurity Report, 58% of SMBs spent more on cybersecurity in 2024 than originally anticipated.
Why? Many surveyed SMBs underestimated the complexity, speed, and scale of modern cyberthreats.
From protecting remote endpoints to securing AI-driven systems, SMBs are now racing to close critical security gaps before attackers exploit them.

Figure 1: SMB cybersecurity investment areas from March 2024 through March 2025
As SMBs scale their cybersecurity efforts, they’re turning to MSPs for help. However, expectations are also rising:
In other words, SMBs are ready to pay for protection, but they expect performance and accountability in return.
These stats reveal a clear mandate for MSPs:
Holidays, weekends, and late nights are prime windows for cyberattacks, as they’re times when SMBs are least prepared. MSPs that offer always-on defense and proactive education will not only meet expectations, but they’ll become indispensable.
As the threat landscape continues to evolve, SMBs are feeling the pressure to strengthen their cybersecurity defenses. The State of SMB Cybersecurity Report reveals how SMBs are evolving their security strategies and expectations of MSPs.
With this in mind, ConnectWise is committed to equipping MSPs with the solutions, expertise, and support to meet those needs and lead in this new era. Together, we can help SMBs protect their businesses.
Equip your team with the tools, training, and support to deliver unmatched cybersecurity outcomes for your clients and position your business as a leader in the next era of managed services. Connect with a cybersecurity expert today to explore how ConnectWise can power your cybersecurity and growth strategy.