In the complex and everchanging world of cybersecurity, SMBs have come a long way. In 2026, they are using more advanced security solutions, training employees regularly, adopting cyber insurance, and resolving incidents much faster.

All of these improvements translate into higher confidence: As many as 26% of SMBs describe themselves as very confident in their cyber resilience, 49% are slightly confident, and only 4% lack confidence in this area, according to the ESET SMB Cyber Readiness Index 2026, which surveyed 4,400 SMBs across 13 countries.

However, the data reveals an alarming discrepancy between perceived and actual cyber resilience as well as between perceived threats and the real risks stemming from AI.

Amid the ongoing hype around AI, the theme of perception vs. reality was also a recurring topic at the 2026 ESET World conference (May 18–21 in Berlin), where speakers detailed real AI threats and how organizations can prepare for them.

Key points of the article:

  • SMBs report high confidence in their cyber resilience, i.e., their ability to protect themselves against cyberattacks and withstand breaches.
  • In parallel, ESET data shows that many SMBs have limited understanding of cybersecurity, including the tools protecting them and AI’s effects on the threat landscape.
  • SMBs are most concerned about AIpowered malware, while in reality, AI mainly lowers the barrier for cybercriminals to launch sophisticated attacks.

Perception: SMBs can take a hit … like champs

SMBs’ confidence in their cybersecurity and cyber resilience is consistently reflected across the ESET SMB Cyber Readiness Index 2026 findings. Respondents believe their cybersecurity can prevent cyberattacks (18% strongly agree, 50% agree, only 7% disagree or strongly disagree).

What is the difference between cybersecurity and cyber resilience?

Cybersecurity focuses on protecting systems, networks, and data from cyberattacks, unauthorized access, and breaches.

Cyber resilience is the ability of an organization to prepare for, withstand, respond to, and recover from cyber incidents.

confidence 

Image 1. North American countries lead in confidence.

The highest reported confidence in cyber resilience came from organizations holding cyber insurance that included specific security control requirements (37% of all respondents), as nearly 88% of them reported being very or slightly confident.

Similarly, businesses that experienced multiple incidents (14% of all respondents) show high confidence in their ability to handle them, with 81% reporting being very or slightly confident.

The confidence is partly explained by multiple measurable improvements in SMBs’ cybersecurity. See this comparison between the 2026 SMB survey and ESET data from 2022.

  • In 2022, almost a third of SMBs (32%) said they were using threat detection and response solutions like EDR/XDR/MDR. In 2026 the number of businesses utilizing detection and response services rose to 42%.
  • In the 2022 report, only 21% of SMBs managed to investigate incidents in less than 2 weeks. In 2026, it is 41%.
  • Four years ago, 49% of SMBs included budget limitations in the top three cybersecurity challenges. Now, budget limitations are only considered main obstacles among 24% of the businesses surveyed.
  • In 2022, 84% of SMBs said that lack of cyber awareness among employees significantly increased the risk of a cyberattack in next 12 months. In 2026, only 27% consider lack of employee training and awareness as one of the biggest security challenges, and 70% stated that they invest in higher tiers of cybersecurity awareness training. 

Seeing these numbers, there should be no surprise that the percentage of SMBs stating that they are “very confident” about their cyber resilience rose from only 10% in 2022 to 26% in 2026.

Reality: Many SMBs still struggle to grasp the basics

At ESET, we are happy to see SMBs becoming increasingly aware of the importance of cybersecurity and that the old myth about “being too small to be targeted” is finally in the rearview mirror.

However, as revealed by ESET Vice President of Enterprise, SMB & MSP Michal Jankech at the ESET World conference, we conducted a second, contextual follow-up survey specifically among smaller SMBs2 to better understand the  picture in more depth. The responses indicate that many of them do not understand core cybersecurity principles at all, which raises some questions about the previous positive findings.

First, we asked businesses how confident they feel when dealing with security topics and how they would rate their overall understanding of those topics. As many as 83% reported being moderately to extremely confident, while 89% indicated a moderate to full understanding of cybersecurity.

Then, we went deeper and found a conflict in the responses: Despite their previous confidence, only 30–34% said they understood basic cybersecurity terms like EDR/MDR/XDR, and the results were even worse in open-text answers (EDR 30%, XDR 16%, MDR 17%). Further, 68% of respondents declared that keeping up with cybersecurity trends was challenging, and 55% considered the cybersecurity market confusing.

When asked about the cybersecurity measures they use, the results were shocking: Only 42% said they use endpoint protection, which is limited to absolutely essential (basic) protection natively built into both Windows and macOS.

Further, 74% of respondents stated that they exclusively use antivirus, a foundational element of endpoint security (although using it as a standalone protection layer is ill-advised). On top of that, 20% said they don’t use either antivirus or endpoint protection.

Of course, it’s hard to believe that only 42% of businesses surveyed use endpoint protection or that 20% use neither endpoint protection nor antivirus. What these numbers suggest is that smaller businesses do not understand the terminology of solutions protecting them.

 survey 2 cybersec measuresImage 2. The second survey shows that around half of smaller SMBs still lack basic security measures. *The result may indicate that cybersecurity terminology is confusing for SMBs.

When it comes to other cybersecurity measures, only 40% declared using a VPN, just 43% have an employee security training program, and only 46% enforce multi-factor authentication, also according to the second survey.

“They feel confident, but their countermeasures fall far behind,” Jankech said.

Interestingly, when asked about employee training directly, 36% said they train staff regularly and 45% occasionally, which again conflicts with the previous figure of 43% of businesses having an employee security training program.

Perception: AI-powered malware is the biggest threat

This conflict between perception and reality is also visible when it comes to AI. There is no doubt that AI is revolutionizing the entire IT industry, and malware operators are no exception. After encountering stories of AIpowered malware appearing in the wild, many businesses have likely grown increasingly worried.

However, as the Cyber Readiness Index shows, this fear is a doubleedged sword. On the one hand, businesses are more cybersecurityaware than ever. On the other hand, they are focusing their attention on threats that are far less prevalent than they believe.

“Businesses fear things they hear about more than those they actually fall victim to,” Jankech said.

According to the ESET SMB Cyber Readiness Index 2026 (Survey 1), AI-powered malware is the threat causing the most concern (31%), followed by ransomware, phishing, and identity/credential theft.

 most concerning threats Image 3. AI-powered malware tops the list of most concerning threats despite being very rare.

Reality: The biggest threats are still the same 

However, despite AI-powered malware making headlines over the past two years, it is important to note that encountering such threats in real-world environments remains extremely rare. In fact, the ESET Managed Detection and Response (MDR) dataset contains zero incidents in which generative AI played a significant “active” role (i.e., direct use of AI to generate malware and scripts).

There are a few exceptions, such as the February 2026 discovery by ESET Research of PromptSpy, the first known Android malware to abuse generative AI during execution, and the ESET discovery in August 2025 of PromptLock, the first documented case of AIdriven ransomware. However, PromptLock was merely a proof of concept developed as part of an academic study, not a threat seen in realworld attacks.

The “real” threats businesses face on daily basis are not new, but they are evolving rapidly:

Phishing

Based on ESET telemetry, we can confidently say that phishing continues to be the most prevalent threat. It isn’t necessarily sophisticated – it doesn’t require advanced technical skills – but it is frequently the entry point attackers use to bypass business defenses, steal data, or deliver malware. Phishing can greatly benefit from AI in preparing phishing emails or other communications used to lure victims – but these attacks aren’t actively powered by AI.

all threats from H1 2026 threat report

Image 4. As seen in the latest ESET Threat Report, phishing is still the most prevalent threat.

The telemetry data is also backed by the Cyber Readiness Index showing that phishing (26%) and unpatched security vulnerabilities (23%) are the most common incident causes/reported causes, each affecting approximately one-quarter of SMBs.

reaons of cyber incidents

Image 5. This ESET SMB Cyber Readiness Index 2026 chart shows the real reasons behind the security incidents. 

Ransomware

The ransomware threat continues to grow too, as malware operators increasingly target smaller businesses using more sophisticated yet easily accessible tools.

ESET analysis of data leak sites indicates a 50% year-on-year increase in these attacks, and our telemetry shows a 13% rise in detections between the first and the second halves of 2025.

At the ESET World conference, ESET Director of Threat Research Jean-Ian Boutin showed that the number of ransomware attacks continues to grow in 2026.

“If the trend continues, we can see that the number of attacks in 2026 will be higher than in 2025,” Boutin said.

 ransomware statisticsImage 6. Ransomware is on course to exceed itself in ESET telemetry for 2026.

The success of ransomware is now often driven by EDR killers, a fundamental part of modern ransomware intrusions that shut down the cybersecurity solution of the targeted company before malware execution. ESET detects a total of almost 90 EDR killers actively used in the wild by nearly all ransomware gangs, both small and large.

Malicious websites

Malicious websites underpin many modern attack campaigns, from largescale consumer scams to highly targeted spearphishing operations. ESET telemetry showed a sharp spike in malicious website activity in the second half of 2025, further confirming that attackers increasingly rely on webbased lures to compromise their victims.

URL block trend H1 26 threat report

Image 7. ESET telemetry highlighting malicious website activity.

Initial access for attackers: Credential abuse and vulnerabilities

When data breaches are not caused by human error or intentional misuse (such as insider attacks), they typically begin with the exploitation of vulnerabilities (unpatched or outdated software), phishing, or credential abuse (e.g., stolen passwords), according to the 2026 Verizon Data Breach Investigations Report (DBIR 2026). These remain the primary entry points attackers use to establish initial access in compromised environments.

Third-party-related breaches

DBIR 2026 also found that thirdparty involvement plays an increasingly important role in breaches (rising from 15% in 2024 to 30% in 2025 to 48% in 2026). This highlights the growing risk posed by supplychain dependencies, service providers, and external partners with access to internal systems or sensitive data.

Reality: How AI threatens your business

Yes, AI-powered malware exists, but in most cases, AI is (just) a tool that makes it easier and faster for cybercriminals to create and operate malicious campaigns. Think of it as if attackers suddenly gained access to a full team of coders, graphic designers, translators, and content writers – all working instantaneously and for just a few bucks.

This leads to higher volumes of more convincing phishing messages and a rapid increase in new malware variants circulating in the wild.

At ESET WORLD 2026, featured speaker Allie Mellen, an analyst at the Forrester research and advisory firm, summed up the emerging threats driven by AI, noting that attackers will use it to defeat their constraints and become more effective than ever before:

Having to understand the operating system they are deploying on to build the right malware: That’s no longer necessary, as attackers can build malware specific to an OS with a single prompt.

Manual reconnaissance, including finding vulnerable targets in an organization, crafting the right phishing emails, and identifying vulnerable assets: Now they can obtain all of that information through a few simple prompts.

Domain knowledge: Now they can learn whatever they need about networking, computing, or even AI on the fly.

Exploit creation: Traditionally, attackers created malware with a specific exploit and a specific payload for a specific operating system. Now, a simple invocation of AI can dynamically generate exploits, payloads, or anything attackers need based on what they observe in the target environment.

Avoiding attribution: Attackers no longer need to spend hours researching and extracting indicators of compromise (IOCs), code comments, and functions. Now they can ask AI to build malware based on a specific threat actor without the need for manual research.

Manual malware deployment: Instead of manually operating malware in real time, attackers can use AI tools to perform multiple tasks autonomously. For example, AI tools can perform reconnaissance, identify exploitable vulnerabilities, build exploits based on those vulnerabilities, escalate privileges once inside, steal information, and deploy malicious payloads.

Supporting this, the IBM Cost of a Data Breach Report 2025 found that 1 in 6 breaches involved AIdriven attacks, typically cases in which generative AI was used to perfect and scale phishing and other social engineering campaigns. IBM previously showed that generative AI reduced the time needed to craft a convincing phishing email from 16 hours to only five minutes.

The same report highlighted another emerging threat vector: legitimate AI tools used carelessly by employees. On average, 13% of organizations reported breaches involving their own AI models or applications, and in 97% of those cases, the affected organizations lacked proper AI access controls.

This aligns with the ESET SMB Cyber Readiness Index 2026 finding that only 69% of U.S. SMBs restrict the use of AI applications, despite 76% of surveyed businesses admitting that utilization of AI applications introduces additional security risks.

How to prepare for the AI-driven threat landscape

SMBs are now at a crossroads: They are spending more on cybersecurity and relying on powerful new tools, believing these tools can protect them. At the same time, they lack an understanding of what these tools are and how to use them to full effect.

Meanwhile, the world is changing so rapidly that SMBs feel lost in cybersecurity jargon, the threat landscape, and emerging AI capabilities.

So, what’s the right path? As ESET’s Michal Jankech says: Fix the basics and learn. There are high-quality guidelines published by reputable organizations like the Cybersecurity and Infrastructure Security Agency (CISA) that can be followed. Many SMBs already have the right tools; they just don’t use them.

“Talk to your vendors and understand what functionalities are available to you,” Jankech said.

Frequently Asked Questions (FAQs)

Why are SMBs confident in their cybersecurity despite ongoing risks?

SMBs have improved their cybersecurity posture in recent years by adopting advanced security tools, investing in employee training, and implementing cyber insurance. These improvements have likely increased confidence levels, with a majority believing they can prevent or withstand cyberattacks.

What is the gap between perception and reality in SMB cybersecurity?

While many SMBs report high confidence and claim a strong understanding of cybersecurity, deeper analysis shows they often lack knowledge of basic concepts and tools such as EDR or endpoint protection. This gap suggests that perceived preparedness is frequently higher than actual capability.

Are AI-powered malware attacks a major real-world threat today?

No, AI-powered malware remains very rare in real-world environments. Although widely discussed in the media and a top concern among SMBs, most cyberattacks today still rely on traditional methods rather than true AI-driven malware.

What are the most common cyber threats SMBs face today?

The most prevalent threats remain phishing, ransomware, unpatched vulnerabilities, credential theft, and malicious websites. These attacks can often be simple but remain highly effective and are responsible for the majority of real security incidents.

How does AI actually impact the cybersecurity threat landscape?

AI primarily acts as a force multiplier for attackers, enabling them to scale phishing campaigns, automate tasks, and create more convincing content. Rather than creating entirely new threats, AI lowers the barrier to entry and increases the speed and volume of existing attack methods.

 

[1] Note there are some differences between the 2022 and 2026 reports: The 2022 survey was made on smaller sample size (1,212 businesses from 25 to 500 employees) but includes higher number of countries (14), including Poland and Finland. The 2026 report represents answers from 4,400 SMBs with 25 to 1,000 employees, and does not include Poland and Finland but surveys Japanese businesses instead. Additionally, some questions and available options differ.   

[2] In the second follow-up survey, sample size was 2,500 SMBs with up to 250 devices from the U.S., UK, Germany, Italy, and Japan.