1,000 Business Owners Said They Felt Secure. Turns Out, Feelings Aren’t Facts.

If you feel good about your cybersecurity, you're not alone. A new survey of 1,000 small and mid-sized business leaders in the US found that 86.3 percent report medium to very high confidence in their ability to manage cyber risk. We hear the same thing from the construction, oil and gas, financial services, and not-for-profit clients we support here in Calgary. Feeling secure and being secure aren't the same thing, though, and the data shows a real difference between the two. No jargon, no spin, just the numbers.

Feeling Safe and Being Safe Are Two Different Things

Cyber risk isn't going away. 72.3 percent of business leaders report their risk increased or stayed the same over the past year, and only 17.9 percent have seen it go down. At the same time, 58.8 percent say they're highly confident they could recover quickly from a full day or more of downtime. For a construction firm juggling job sites or an oil and gas supplier running lean, that kind of downtime isn't an inconvenience. It's lost work and unhappy clients. Confidence without a tested plan behind it tends to fall apart at the worst possible time.

Half of Businesses Can't Say They Had a Clean Year

According to the National Cybersecurity Alliance's small business survey, 50.5 percent of SMBs reported a confirmed or suspected security incident in the past year, and another 5.6 percent weren't sure either way. Combined, 56.1 percent of businesses can't say with confidence they had a clean year. That uncertainty is usually a sign that nobody's watching closely enough. Without proper monitoring, most businesses wouldn't know they'd been hit until well after the damage was done. The risk varies by industry too. Technology and telecom businesses reported the highest rate at 76.4 percent, followed by financial services at 67.1 percent, healthcare at 58.2 percent, and manufacturing at 58.1 percent, sectors we see plenty of right here in Alberta.

The picture in Canada points the same way. The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026 names ransomware the top cybercrime threat facing Canada, which makes the gap between feeling secure and being secure just as real for Calgary businesses.

Owning a Security Tool Isn't the Same as Running It Right

Having a security tool and using it properly are two different things, and that's where most incidents happen. 86.8 percent of businesses have multi-factor authentication in place, but only 51.1 percent require it on every key account. More than a third, 35.7 percent, only require it for some accounts, which leaves exactly the kind of opening attackers look for. Backups follow the same pattern. 88.4 percent of businesses have them, but only 61.4 percent have verified they restore. Roughly a quarter of the market is trusting backups nobody's tested, which is a rough way to find out your data's gone for good.

Leadership review habits tell the same story. Only 23.7 percent of businesses review cybersecurity as a business risk monthly, the cadence best suited to a threat landscape that changes fast. Another 32.1 percent review it quarterly, and nearly 38 percent review it only sometimes, rarely, or never.

Everyone's Using AI. Almost Nobody Has Rules for It.

AI use among small businesses has hit 87.3 percent, driven mostly by the desire to save time and automate routine work, cited by 49.1 percent of businesses. Policy hasn't caught up. Only 45.6 percent of businesses have formal guidelines for how staff should use AI tools, which means most employees are making calls about client data and business records with nothing to guide them. The Cybersecurity and Infrastructure Security Agency and the National Cybersecurity Alliance both flag this as one of the fastest-growing risk areas for small businesses right now, precisely because AI is so easy to start using without a policy in place first.

Four Things Worth Doing This Quarter

  • Put an AI acceptable use policy in writing. Spell out what should never go into a public AI tool, including client data, financial records, and proprietary information, and name which tools your team is cleared to use.
  • Choose business-grade AI platforms over free consumer versions. Paid, business-tier tools generally come with stronger data protections and admin controls.
  • Keep a human in the loop. Require review of AI-generated work before it goes external, whether that's a client email, a quote, or code.
  • Train your team in short, regular sessions. Fifteen to thirty minutes covering safe data handling and AI-related phishing goes a long way, and it's the resource business leaders say they want most.

No Jargon, No Guesswork: A Clear Answer on Where You Stand

Every stat in this report describes a business that thought it had things covered. If you can't say for certain whether your MFA covers every account, whether your backups restore, or what your team's typing into AI tools, that's worth a conversation this week, not next quarter.

At Sure Systems, we've spent over 25 years cutting through IT complexity for businesses across Calgary and the surrounding area. No jargon, no confusion, no promises we can't keep. Get in touch with our team and find out exactly where you stand before an attacker does.

FAQ

Why do so many business owners feel confident about cybersecurity even though risk is rising?

Confidence usually comes from having tools in place, like MFA or backups, without confirming they're configured, enforced, or tested properly. Feeling prepared and being prepared aren't the same thing.

Is having multi-factor authentication enough to protect my business?

Not on its own. 86.8 percent of businesses have MFA, but only 51.1 percent require it on every key account. Partial enforcement leaves accounts exposed, and attackers specifically look for the accounts MFA doesn't cover.

Do smaller businesses need a written AI policy?

Yes. 87.3 percent of small businesses already use AI tools, but only 45.6 percent have guidelines for how staff should use them. A short written policy covering what data can and can't go into an AI tool closes one of the fastest-growing risk areas for small businesses.

What's the first step toward closing the difference between confidence and readiness?

Start with what you already have. Confirm MFA is required on every key account, test your backups instead of assuming they work, and put cybersecurity on the agenda for a monthly leadership review instead of a quarterly or occasional one.

Source: 2026 Small Business Cybersecurity Awareness & Practices Survey, National Cybersecurity Alliance in partnership with CISA (US-based data; cited as a directional benchmark for Calgary-area businesses).

Scroll to Top