At a Glance:
- Small businesses remain frequent targets for cybercriminals, with phishing, business email compromise, and ransomware among the most common threats.
- Artificial intelligence is making phishing scams more convincing and harder to detect.
- Multi-factor authentication, employee training, and strong access controls may help reduce risk.
- Download PNC's Small Business Owner’s Guide to Cybersecurity for a deeper look at today’s cyber threats and practical steps to help protect your financial data, employees, and operations.
Cybersecurity is now a core part of running any business – and cyberattacks are no longer limited to large corporations.
Today, even the smallest companies rely on email, online payments, cloud-based software, and connected devices to serve customers and manage operations. While these technologies create efficiency and opportunity, they also create openings for cybercriminals looking to steal money, access sensitive information, or disrupt business activities.
For small businesses, the impact of a cyber incident can extend far beyond technology. It may interrupt operations, strain customer relationships, delay payments, and consume valuable time and resources.
"One of the biggest misconceptions we see is that a business is too small to be a target," said Christian Winward, Chief Information Security Officer at PNC Bank. "Cybercriminals are often looking for vulnerabilities, and every organization has a responsibility to protect its people, data, and operations."
By combining employee education, strong security controls, and a well-defined response plan, small businesses may better position themselves to identify threats, reduce risk, and recover more quickly when an attack occurs.
Why Are Small Businesses Targeted by Cybercriminals?
For most cyberattacks, the endgame is simple: profit.
Cybercriminals often view small businesses as attractive targets because they may have fewer security resources than larger organizations but still possess valuable information, including employee records, customer data, payment information, and financial accounts.
As fraud tactics become more sophisticated, businesses are feeling the impact regardless of their size, location, or industry. In fact, 76% of organizations reported attempted or actual payments fraud in 2025, underscoring how widespread these threats have become[1].
In many cases, attackers are looking for opportunities to exploit common vulnerabilities such as weak passwords, outdated software, compromised credentials, or employees who unknowingly respond to fraudulent messages.
What Are Today's Most Common Cyber Threats?
While cyber threats continue to evolve, several attack methods remain particularly common among small businesses.
Phishing and Social Engineering
Phishing occurs when cybercriminals use emails, text messages, websites, or other communications to trick recipients into revealing sensitive information or clicking malicious links.
These attacks often appear to come from trusted sources, such as banks, vendors, coworkers, shipping providers, or government agencies.
Social engineering broadly describes attacks that work by manipulating people, rather than directly hacking into systems, to infiltrate an organization – making employee awareness one of the most important lines of defense. These scams trick recipients into revealing confidential information, such as passwords, or into sending criminals money.
Business Email Compromise
Business email compromise (BEC) occurs when criminals pose as executives, vendors, employees, or trusted partners to request payments, gift cards, sensitive information, or changes to payment instructions.
These scams often rely on realistic email addresses, convincing language, and urgent requests designed to pressure employees into acting quickly. BEC remains one of the most common forms of payments fraud affecting organizations today.
Ransomware
Ransomware is malicious software that encrypts files or systems and demands payment in exchange for restoring access. In some cases, attackers also threaten to publish or sell stolen information if a ransom is not paid.
A ransomware incident can result in operational downtime, lost productivity, financial losses, and reputational damage.
How Is Artificial Intelligence Changing Cybercrime?
Artificial intelligence is creating new opportunities for businesses, but cybercriminals are using it as well. The FBI warns that today’s cybercriminals are using generative AI to sharpen deception tactics and scale financial fraud schemes[2].
Attackers may use AI tools to generate realistic phishing emails, mimic writing styles, and create messages that are more personalized and convincing than traditional scams. Some criminals have even begun using voice-cloning technology to impersonate executives, colleagues, vendors, or family members.
What Steps Can Small Businesses Take to Strengthen Cybersecurity?
“The red flags that once made fraudulent messages easier to spot may not be as obvious today,” Winward said. “That's why businesses should establish verification procedures and encourage employees to pause and confirm unusual requests before taking action.”
When a request involves moving money, changing account information, sharing sensitive data, or granting system access, employees should verify the request through a separate, trusted communication channel.
No security measure can eliminate risk entirely, but businesses may significantly improve their defenses by implementing a layered approach.
Train Employees on Cybersecurity Awareness
Employees are often the first line of defense.
Provide regular training on recognizing phishing emails, suspicious links, fraudulent payment requests, and other cyber threats. Encourage employees to report unusual activity promptly rather than assuming someone else will investigate.
Require Multi-Factor Authentication
Multi-factor authentication (MFA) adds an additional layer of protection by requiring users to verify their identity through a second method beyond a password.
MFA should be enabled wherever possible, particularly for email, financial systems, payroll platforms, cloud applications, and remote access tools.
Keep Software and Systems Updated
Outdated software may create security gaps that attackers may exploit.
Regularly install security updates for operating systems, web browsers, applications, firewalls, and antivirus software. Automated updates may help ensure critical patches are not missed.
Limit Access to Sensitive Information
Not every employee needs access to every system.
Businesses should grant employees access only to the information and applications required to perform their jobs. Limiting access may help reduce potential damage if an account becomes compromised.
Secure Mobile Devices and Cloud Applications
With employees increasingly working remotely and using cloud-based platforms, securing access beyond the office is essential.
Require password protection on business devices, encrypt sensitive data when appropriate, and regularly review user permissions across cloud applications.
Back Up Critical Data
Regular backups may play an important role in business continuity.
Maintain backups of critical business information and test them periodically to ensure data can be recovered if systems are disrupted by ransomware, hardware failures, or other incidents.
Verify Payment and Account Change Requests
Establish procedures for independently verifying requests involving:
- Wire transfers
- ACH payments
- Vendor banking changes
- Payroll updates
- Sensitive customer information
Even when requests appear to come from a trusted source, employees should confirm them using a known phone number or another approved communication method.
What Banking Tools Can Help Businesses Prevent Payments Fraud?
Banks offer a range of built-in tools, from ACH filters that block unauthorized debits to real-time account alerts and customized access controls.
PNC Small Business customers receive access to online fraud mitigation tools such as PINACLE®, Positive Pay, ACH Debit Authorization, and Universal Payment Identification Code® (UPIC). These tools may help businesses monitor account activity, review checks and ACH transactions, control which debits post, and reduce the need to share account information.
Cybersecurity Is an Ongoing Business Priority
Cyber threats will continue to evolve, and businesses must evolve with them.
“Cybersecurity is a shared responsibility,” Winward said. “Preparation, awareness, and vigilance can go a long way toward protecting your business, your employees, your customers, and your operations.”
The goal is not to eliminate every threat, but to build habits and safeguards that make the business harder to target and better prepared to respond. Reviewing those protections regularly may help keep pace as technology and criminal tactics continue to change.
Learn More
Download PNC's Small Business Owner’s Guide to Cybersecurity for a deeper look at today’s cyber threats and practical steps to help protect your financial data, employees and operations.
You can also explore PNC’s Security & Privacy Center for additional fraud-prevention guidance.
Frequently Asked Questions About Small Business Cybersecurity:
What is the biggest cybersecurity risk for small businesses?
Phishing and social engineering are among the most common risks because they target employees with convincing messages designed to steal credentials, sensitive information, or money. Business email compromise can be especially damaging when criminals impersonate trusted executives, vendors, or partners.
What are the most important cybersecurity steps for a small business?
Start with a layered approach: train employees to recognize suspicious messages, require multi-factor authentication, keep software updated, limit access to sensitive information, back up critical data, and verify payment or account-change requests through a separate trusted channel.
How can a business reduce the risk of payments fraud?
Use documented approval procedures, independently confirm unusual payment or banking-change requests and consider banking tools that help monitor checks and ACH transactions, control authorized debits and alert users to account activity.
What should a small business do after discovering a cyber incident?
Act quickly by following the business’s incident response plan, containing affected systems, preserving relevant records and contacting appropriate technology, legal, insurance, and financial partners. If money may have been transferred fraudulently, contact the financial institution immediately.s remain frequent targets for cybercriminals, with phishing, business email compromise, and ransomware among the most common threats.