Ninety percent of security leaders say they can recover from an attack. Twenty-eight percent of the ones who actually get hit by ransomware restore their data in full.
That gap is the whole problem with how small and mid-sized businesses talk about IT risk. The market runs on confident claims and thin evidence. Surveys ask people how secure they feel, and people answer the way they wish it were.
![]()
Think your IT is in good shape?
Take the free 3-minute readiness quiz
So for the second edition of our SMB Technology and Cyber Resilience Index, we did the opposite. We stopped asking how anyone feels and published what our own systems actually recorded across roughly 1,700 managed businesses in the second quarter. Including the numbers that do not flatter us.
The number that got worse on purpose
Here is the one I insisted we lead with.
Last edition, our endpoint patch compliance read 94 percent. This edition it reads 65.3 percent.
Patching did not fall apart in a quarter. We changed the ruler. The old number counted devices that were inside the patching policy window. The new number counts devices current on every applicable patch, at the moment of measurement. That is the standard an attacker actually tests, so that is the one we now report.
A better instrument changes the reading before it changes the reality. Most vendors would bury a number that moved the wrong way. We put it in the executive summary, because a benchmark that only prints the flattering measurement is worth nothing.
The gap that would not move
Two editions in, five percent of our clients have a documented recovery objective, and five percent have tested a restore in the last 90 days. The same five percent, six months apart.
I find that more useful than any of our good numbers. We identified it last time as the widest gap in the index. We recommended the fix. It did not move.
That tells you something the industry averages hide. Nothing about day to day IT operations produces recovery discipline on its own. No successful backup job asks to be tested. No quiet quarter forces anyone to write down how much data they can afford to lose. The gap only closes when testing becomes a scheduled, monitored obligation. Until it is, a backup nobody has restored is an assumption, not a control. Across the industry, only 28 percent of ransomware victims get all of their data back.
What actually held
Now the other side, because the point of measuring honestly is that the good numbers mean something too.
Over the quarter our client base absorbed 9.19 billion analyzed security events. Two hundred and fifteen became verified incidents. None of them became a ransomware detonation.
A typical managed client saw about 2.6 hours of unplanned downtime for the year, against a 14-hour industry average. Critical issues were resolved in an average of 8.5 hours.
The pattern across every pillar is the same, and it is the real finding. Where a discipline is instrumented, enforced, and monitored, backup automation, threat detection, response speed, the outcomes hold. Where it depends on someone remembering, recovery documentation, restore testing, MFA everywhere, it stalls. Resilience is an operating habit, not a product you buy.
The way in is a login now
One shift is worth pulling out on its own, because it changes what secure even means for a small business.
The attack does not start with a virus anymore. It starts with a stolen password. Seventy-nine percent of ransomware attacks now begin with a compromised identity. And in the finding that should end the “we are too small to be a target” conversation for good: where the victim’s size was known, 96 percent of ransomware victims were small and mid-sized businesses.
Most of our clients have multi-factor authentication turned on. That matters. But having MFA and having it everywhere are different things, and the space between them, the one VPN, the legacy app, the admin console left outside it, is exactly where this year’s breaches walked in. Adoption is not coverage.
Why we published numbers that make us look worse
Because I have never trusted a benchmark that only exists to sell something.
Every managed IT provider will tell you it reduces downtime and stops attacks. Almost none will show you the measurements, and none will show you a measurement that moved the wrong way. So the whole category reads as marketing, and a business owner trying to make a real decision has nothing solid to stand on.
We would rather hand that owner real operational evidence, including a patch number that dropped 29 points the moment we measured it honestly, and a recovery gap we have not closed yet. If our own data cannot survive being published in full, it was never a benchmark. It was a brochure.
If you take one thing from this
Ask your IT provider for the number, then ask what standard it is measured against.
“Ninety-something percent patched” means nothing until you know whether that counts every patch or only the ones inside a comfortable window. “We monitor your backups” means nothing until someone has actually restored one. The measurement is the whole story, and the standard behind it is the part nobody volunteers.
The full index, all five pillars and every source, is below.
Get the full Q2 2026 Index
The complete SMB Technology and Cyber Resilience Index, the five pillars, the methodology, and every cited source, is available as a free download.

