Microsoft's most recent Digital Defense Report has a number in it that should change how small firms think about security: more than 97% of identity attacks are password attacks.
Not zero-days. Not nation-state wizardry. Someone using a password that already leaked somewhere else.
That's why a 12-person advisory firm in Palm Beach is not "too small to target." You're close to the opposite — sensitive client data, a tight security budget, and nobody on call at 9pm on a Friday. Microsoft's report describes attackers using small businesses as a low-effort pivot into the larger organizations they connect to.
The stakes aren't abstract. It's a week without access to client records during a market swing. It's every hour your team spends rebuilding instead of billing. It's the call where you explain to a client why their account statements were sitting in someone else's inbox. That call costs more than any tool on the market.
Here's the part I like: Microsoft says phishing-resistant multifactor authentication blocks over 99% of identity-based attacks. For a firm already paying for Microsoft 365, that's a configuration change and an afternoon, not a new line item.
Small doesn't mean invisible. It usually just means unprotected.
Worth a look before your next cyber renewal.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email