The phrase cyber poverty line is uncomfortable.

It can sound like the cybersecurity industry is calling a business poor, cheap, careless, or unsophisticated. That is not what the phrase should mean, and it is not how I use it.

A capable, profitable, well-run company can still operate below the cyber poverty line. The issue is not whether the owner can pay the bills. The issue is whether the organization has enough money, expertise, time, capability, and influence to consistently maintain a reasonable level of cybersecurity.

Many small businesses do not.

That is not an insult. It is an operating reality—and one worth seeing clearly before an attacker finds it for you.

What Is the Cyber Poverty Line?

Security strategist Wendy Nather introduced the idea in 2011 in Living Below the Security Poverty Line. The concept was later developed in a 2013 RSA Conference presentation with Andy Ellis.

The Atlantic Council’s explanation of the cyber poverty line describes organizations that struggle with security because of insufficient IT budget, expertise, capability, or influence. Those limitations can affect small businesses, schools, local governments, startups, nonprofits, healthcare organizations, and even large companies operating with thin margins or difficult legacy systems.

There is no universal dollar amount that separates the two sides of the line.

A ten-person accounting firm, a machine shop, a rural water utility, and a software company do not have the same systems, information, obligations, or exposure. Their minimum reasonable security posture will not cost the same, either.

The line is better understood as a capacity threshold. Below it, the organization cannot reliably operate the controls its real risks require. It may own some good technology, but important work is still happening inconsistently—or not at all.

That distinction matters because cybersecurity is not a one-time purchase. Someone has to enroll users in multi-factor authentication, remove old accounts, install updates, respond to alerts, test restores, review vendor access, maintain plans, and decide which risk should be addressed next.

A tool without the time and ownership to operate it does not move a business above the line.

Small Businesses Are Not Small to the Economy

According to the U.S. Small Business Administration’s 2026 small-business statistics, small businesses make up 99.9% of U.S. firms, employ 45.9% of private-sector workers, and produce 43.5% of gross domestic product.

Small businesses are not a fringe group. They are a large part of how the economy actually works.

They are also not miniature enterprises.

A business with 15 employees cannot take a large-company security program, divide it by 100, and expect it to fit. It may not have a chief information security officer, a security operations center, a risk team, an identity specialist, or even a full-time IT employee. The person handling technology may also be responsible for finance, operations, facilities, or office administration.

The U.S. government recognizes this gap. CISA notes that many small and medium-sized businesses do not have dedicated risk-management experts or functions. NIST publishes Cybersecurity Framework guidance specifically for businesses with modest or no cybersecurity plans, along with practical information about building a team through in-house staff, outside help, or a combination of both.

That guidance exists because the resource gap is real.

Yes, Smaller Companies Usually Spend Less

It should not be controversial to say that a small company generally spends fewer total dollars on cybersecurity products and talent than a national bank, hospital system, or Fortune 500 company.

The smaller company usually has fewer employees, fewer systems, less revenue, and a smaller total operating budget. It may need outside expertise but be unable to justify a full-time security hire. It may buy the security features included with its existing technology instead of a large collection of specialized products.

That is ordinary budget math, not a moral judgment.

Public data also shows how security capacity changes with organizational size. The United Kingdom’s 2025 Cyber Security Breaches Survey found that very few micro and small businesses had someone in a dedicated IT role looking after cybersecurity. It also found that 62% of small businesses used an external cybersecurity provider, compared with 50% of large businesses, and that formal cybersecurity policies became much more common as organizations grew: 30% of micro businesses, 59% of small businesses, 74% of medium businesses, and 87% of large businesses reported having one.

That is UK data, not a Minnesota benchmark, but the operating pattern is recognizable. Smaller organizations have less internal specialization and depend more heavily on generalists and outside providers.

The useful question is not, “Do you spend as much as a large company?”

Of course you do not.

The useful question is, “Are the resources you do have reducing the risks that matter most to this business?”

Day-to-Day Operations Usually Win

Small-business leadership has immediate problems to solve:

  • A customer needs an answer.
  • Payroll is due.
  • A machine is down.
  • A shipment is late.
  • A key employee called in sick.
  • The point-of-sale system stopped working.
  • A vendor increased its price.
  • A large customer wants paperwork by Friday.

Cybersecurity competes with all of that.

Most security risk is quiet until something goes wrong. A backup that has never been tested does not interrupt today’s work. An old administrator account does not complain. A weak Microsoft 365 configuration may sit unnoticed for years. Nobody hears an unmonitored security alert.

Revenue, customers, and operations naturally receive attention first because they are visible and urgent. Cybersecurity is postponed because the consequences are uncertain and usually somewhere in the future.

That prioritization is understandable. It is also how security debt accumulates.

The FBI’s 2025 Internet Crime Report recorded 24,768 business email compromise complaints and more than $3 billion in reported BEC losses. It also received more than 1,400 ransomware complaints from businesses and organizations outside critical-infrastructure sectors, including legal services, contractors, engineering firms, consultants, and manufacturers.

Those figures are not limited to small businesses, and reported complaints never describe every incident. They do show that the threats facing ordinary businesses are neither theoretical nor confined to giant corporations.

An attacker does not need a small company to have a security department. The attacker only needs a working path to email, money, data, or operations.

What Operating Below the Line Looks Like

The warning signs are usually ordinary:

  • Nobody can clearly explain who owns cybersecurity risk.
  • The business assumes the MSP handles something that is not actually in the contract.
  • Multi-factor authentication is enabled for some users but not enforced everywhere it matters.
  • Former employees, vendors, or old devices still have access.
  • Endpoint protection is installed, but nobody can say where the alerts go.
  • Patching happens, but important third-party applications or network devices are missed.
  • Backups report success, but a real restore has not been tested.
  • Sensitive files are stored wherever employees find convenient.
  • The incident response plan is missing, outdated, or unfamiliar to the people named in it.
  • Security products have been purchased, but nobody has time to configure or operate them well.

None of these observations means the business is irresponsible. They mean the organization has reached the limit of its available attention, expertise, or accountability.

That is the line.

This Is Not an Attack on MSPs

Managed service providers are one of the main ways small businesses add technical capacity. A good MSP keeps systems operating, supports employees, manages updates, maintains backups, deploys endpoint protection, and helps the business recover from daily technology problems.

That work matters.

But the words managed IT, managed security, risk management, and independent security review do not automatically mean the same thing. A provider cannot be accountable for services the business did not purchase, and a business should not assume every security responsibility is included because the agreement contains the word “security.”

The gap is often not bad intent. It is an unclear scope.

A practical review should clarify:

  • what the MSP manages
  • what the MSP monitors
  • what the business still owns
  • what another vendor handles
  • what nobody is currently doing

That clarity can strengthen the MSP relationship. It gives the provider a defined set of expectations and gives the business a better basis for deciding what to fund.

Crossing the Line Does Not Require an Enterprise Security Stack

The goal is not to make a 25-person company look like a global bank.

The goal is to establish a minimum viable security posture appropriate to the business. The FTC’s Cybersecurity for Small Business guidance and the NIST Cybersecurity Framework point toward familiar fundamentals:

  • know which systems, accounts, vendors, and data matter most
  • require strong multi-factor authentication
  • remove unnecessary access and administrator privileges
  • keep operating systems, applications, firewalls, and other devices updated
  • protect every supported endpoint and make someone responsible for alerts
  • maintain separate, recoverable backups and test them
  • train employees to recognize common fraud and phishing attempts
  • use a second channel to verify unusual payment or banking changes
  • document incident contacts, decisions, and responsibilities
  • periodically verify that providers and controls are doing what leadership expects

Some of these improvements cost money. Others require a configuration change, a conversation, a short test, or a decision that has been postponed.

The right order matters more than the length of the shopping list.

Buy a Few Hours of Clarity

A small business does not always need a six-month assessment, a penetration test, or a thick report full of findings it cannot act on.

Sometimes the sensible first step is to pay for a few focused hours with an independent security professional.

A limited review cannot prove that a business is secure, certify compliance, or uncover every technical weakness. It can still answer valuable questions:

  • What are we relying on today?
  • Which protections are already working?
  • Where are the most consequential gaps?
  • Are we getting the security capabilities already included in our licenses and contracts?
  • What does our MSP own, and what remains ours?
  • Which two or three improvements should happen first?
  • What can wait?
  • What do we probably not need to buy?

The output should be understandable: what is working, what needs attention now, what belongs in the next 90 days, and who should own each next step.

That kind of review will not turn a small business into a Fortune 500 security program. It should not try to.

It can help the business move above its own cyber poverty line by replacing assumptions with evidence and directing limited resources toward the risks most likely to cause real harm.


Sources


Not Sure Where Your Business Stands?

MN Risk & Cybersecurity Advisory offers focused, independent reviews for small and mid-sized businesses that want a practical view of what is working, where important gaps exist, and what to prioritize next.

Pay for a few hours. Let us look at the environment, the responsibilities, and the controls you already have. Then decide what—if anything—you need to buy or change.

Start a conversation about a cybersecurity review