The evidence · Updated
A question of IF has become a question of WHEN...
Attacks on business networks are up. The skill needed to run one has collapsed. The way in is now your firewall, not your staff. And the time it takes anyone to notice just got longer for the first time in five years.
Every number below is from a primary source and named on the page. Read it, then decide whether anyone is currently watching your network.
What it costs
A breach is now the most expensive thing that can happen to a small business
$11.5M
Average US breach cost
A record, two years running — up from $10.22M the year before. The global average also hit a record, rising 12%.
$20.9B
Reported US losses in one year
Up 26% in twelve months, and past $20 billion for the first time. That is only what victims bothered to report.
2,270
Attacks per business, per week
Up 17% on June 2025 and still climbing. Not attacks on the internet: attacks per organization, every week.
32% → 48%
Breaches involving ransomware
Across three consecutive annual reports. Nearly half of all confirmed breaches now involve somebody holding your business hostage.
And the number that should worry you most is the one going the wrong way:
“The mean time organizations took to identify and contain a breach rose to 247 days, a slight 2.5% uptick that reversed a five-year decline.” — IBM / Ponemon, Cost of a Data Breach 2026
247 days. Eight months between the break-in and anybody finding out. And that duration is not free: IBM measured breaches running past 200 days at $5.65 million against $4.32 million for the ones caught sooner. The clock is the bill.
Why now
Anyone can do this now. That is the whole change.
Attacking a business network used to take years of learning. That barrier is gone — and the clearest statement of it comes not from a security company with something to sell, but from an AI company auditing its own product.
“AI has lowered the barriers to sophisticated cybercrime. Criminals with few technical skills are using AI to conduct complex operations, such as developing ransomware, that would previously have required years of training.” — Anthropic, Threat Intelligence Report, August 2025
In that same report, Anthropic documented an actor with only basic coding skills who used AI to build ransomware and sell it on criminal forums for $400 to $1,200 a copy. The FBI logged 22,364 complaints referencing AI in 2025, with $893.3 million in reported losses.
“We’re too small to be worth the effort”
That was a reasonable bet when effort was the constraint. It is not one anymore.
Almost nothing that hits a small business is a targeted attack. It is automated scanning that sweeps the entire internet and stops wherever a door is open — and it does not know or care how big you are.
What it finds is almost never exotic. It is a firewall feature switched off. A guest Wi-Fi that was never actually separated from the computer running billing. A password still set to whatever it shipped with.
Nobody has to be after you specifically. They just have to find you before somebody on your side finds the setting.
And it is about to get worse. In November 2025 Anthropic disclosed an attack campaign in which AI performed 80–90% of the work, with humans stepping in at perhaps four to six critical decision points per campaign. The World Economic Forum called it the first confirmed case of agentic AI reaching high-value targets. Skill is becoming less of a limit on who can run a campaign like that. In Anthropic's words, less experienced and resourced groups “can now potentially perform large-scale attacks of this nature.”
The clock
They move in minutes. Most businesses find out in months.
22 seconds
From breaking in to handing your network off to the criminal who does the damage — down from more than eight hours in 2022.
29 minutes
Average time from the first compromised machine to the second — down from 48 minutes, and from 62 the year before that.
3 hours 24 minutes
Median time until attackers go after Active Directory, the system that holds the keys to everything else.
247 days
Average time to identify and contain the breach. Against minutes of attack, that is the entire fight in one comparison.
Nobody wins that race by being faster than the attacker. You win it by not being the business that takes eight months to notice.
Where they get in
It stopped being your staff. It is your equipment.
For years the advice was to train people not to click things. The data moved on.
20% → 31%
Exploiting an internet-facing device
Your firewall, VPN or router is now the leading way attackers get their first foothold — ahead of stolen passwords at 13%.
15% → 48%
Breaches involving a third party
Tripled in two years. Your vendors’ remote access lands on your network — and almost nobody is watching what it does once it gets there.
38% → 26%
Known flaws actually getting fixed
Of the vulnerabilities the US government confirms are under active attack, the share organizations fully patched fell. The doors are being found faster than they are being closed.
Read those three together. The break-in point moved to the box in your closet. Half of breaches now arrive through somebody you gave access to. And the known holes are being patched more slowly than last year. Every one of those is on the network layer — which is exactly the layer nobody at a 30-person company is watching.
The part nobody checks
Your phone system is on the internet, and it is being knocked on right now
The riskiest IoT device in your office
VoIP systems ranked the riskiest IoT device type of 2026, up from third the year before.
Nearly 1.9 million attempts in 18 days
One internet-facing phone-system port recorded 1,869,521 login attempts against 29,433 extensions, plus 89,465 attempted fraudulent calls — in under three weeks. Toll fraud lands on your bill, not theirs.
Confirmed exploited by the US government
A business phone-system flaw was added to CISA’s Known Exploited Vulnerabilities catalog — the federal list of flaws confirmed to be under active attack. Seven more sit there for one major phone vendor, five of them tied to ransomware.
And here is why that is fixable today
99.8% of that attacking traffic came from datacenter and hosting providers, and 93.5% of the addresses were already on published abuse lists. This is machinery sweeping the internet, not a person choosing you.
Which means a correctly configured firewall in front of the phone system stops nearly all of it. That is not a product you need to buy. It is a setting somebody needs to have gotten right — and it is one of the first things we look at, because we do not think phones and network security are two separate purchases.
Not a big-city problem
When it happens, the phones go down with the network
These are not Fortune 500 headlines. They are ordinary organizations, and in every case the thing people actually noticed was that they could not make a call.
A county government
Shut down its network in what it described as “a three-week, system-wide disruption.” Phones, desk computers and email were among the systems it then had to restore. Its own commissioner said they had “the same type of protections in place that most of corporate America has — and then some.”
A major port and airport
“Maritime facilities phone systems are down as part of a system outage.” Baggage, check-in kiosks, ticketing, Wi-Fi and passenger displays all disrupted. They refused to pay.
A school district
Cancelled classes across 14 schools for roughly 7,300 students after a server, network, internet and phone outage.
And if you think trade businesses are overlooked: of ransomware complaints from non-critical-sector businesses, legal services made up 18%, contracting 17%, and engineering and architecture 10%. FBI IC3, 2025
How we solve it
We can’t listen in 24/7 to a network. Andrew Igloo can.
No person can watch a network every second of every day. Nobody has ever been able to. Andrew Igloo is our AI IT Network Administrator — and he does exactly that, from The Igloo, correlating every layer at once, explaining what he finds in plain English, and putting a human on it the moment something matters.
Andrew sees the whole picture at once
“The internet is slow” touches five layers, and a technician checks them one at a time. Andrew reads all of it simultaneously and hands you a sentence: the circuit is healthy, one wired machine is saturating the upload, and three wireless devices are fighting a neighbour’s access point that moved onto your channel this week.
He translates, so you can decide
Every device on your network produces roughly 150 fields of data. Nobody reads that. Andrew turns wifi_tx_retries_percentage into “the tablets in the warehouse are fighting for airtime.” Same data. One version you can act on.
You can just ask him
“Why was the warehouse Wi-Fi bad Tuesday afternoon?” is a question you ask in plain English and get answered from the actual data — not a question you file a ticket about and wait two days for.
Three things Andrew catches that nobody else does
“Why was the internet down Tuesday?”
Somebody plugs a home router into a spare wall port. It starts handing out network addresses. Some machines lose the internet, the printers, the accounting server — not all of them, not consistently. It looks like a dozen unrelated faults, clears up by afternoon, and happens again next month.
We detect your network’s addressing changing and name the exact device — its hardware address, its vendor, when it appeared, and which machines took a bad lease.
“The backup internet was already dead.”
You pay every month for a second circuit so the business keeps running when the first fails. On a real audit in July 2026, one showed 0.0% availability for every one of the 11.5 days the gateway had been running. It had never raised a single alert. The network reported itself as redundant.
A dead backup is worse than no backup. No backup means you plan around it. A dead one means you stopped thinking about it.
“The camera was dead for three weeks.”
Cameras fail silently, recording light still on, in a corner nobody looks at. No user complains. The failure surfaces exactly once — the moment somebody backs into a vehicle or a package disappears, and the footage is not there.
Cameras are network devices. We see one stop responding in about two minutes and tell somebody, instead of you finding out three weeks later.
What Andrew watches, around the clock
Any device going offline, usually inside two minutes · your whole site dropping off · your public address changing · public-facing servers and VPN endpoints that stop answering · the specific port your business software listens on · new devices appearing on your network · changes to your network’s addressing and DNS · internet circuit health against independent targets · who is consuming your bandwidth · per-device wireless quality and interference · equipment heading toward its limits · your phones · your cameras — and the monitoring itself, because a monitor that has quietly stopped looking is indistinguishable from a clean result.
And Andrew does not sleep, which is why we do not bill you for somebody who does. The watching, correlating and triaging is software running at The Igloo. A human is on call and gets paged when it matters. That is how “all for less” works — it describes how we built the service, not a discount.
And here is what you get
The report. Every finding, the evidence behind it, and a fix.
Most providers want you on a call before they will tell you what you would receive. Here is the actual thing. Ranked critical to low, with the exact setting we read and what it means in one sentence.
EXAMPLE MILLWORK CO. · three sites · 25 managed devices
Executive summary
The network is functional and reasonably well built. It is also, in three specific places, wide open in ways nobody chose — an unauthorized device handing out network addresses on the shop floor, a management password stored in recoverable form and reused across all 25 devices, and the camera system published to the open internet from any address. None of the three needs new hardware. Two are settings changes. One needs a maintenance window.
Scorecard
| Domain | Grade | Note |
|---|---|---|
| Perimeter & firewall | D | Three inbound paths open to any source |
| Segmentation | F | Ten VLANs, three rules, nothing enforced between them |
| Identity & access | D | One shared credential, recoverable, no second factor |
| Resilience & backup | D | Config backup scheduled, retaining zero restore points |
| Video & physical | F | Camera recorder reachable from the open internet |
CRITICALC1 — Unauthorized device handing out network addresses
What we found. A device that is not the gateway is answering address requests on the shop-floor network. DHCP guard is not enabled on any VLAN, so nothing prevents it.
mac 02:1f:9c:44:6a:31 (locally administered) vendor (unregistered) first_seen 2026-04-11T07:52:19Z role_observed dhcp_server leases_issued 14 (of 61 clients on VLAN 40)
Why it matters. Fourteen of sixty-one machines on the shop floor took their network settings from an unmanaged device. Those machines lose the file server and the printers intermittently, in a way that looks like a dozen unrelated faults.
Fix. Remove the device, then enable DHCP guard with the legitimate servers allowlisted first. Minimum version: remove it today, schedule guard for the next window.
CRITICALC3 — Camera system and remote desktop published to the internet
What we found. Three inbound rules forward from any source address to internal machines, including the camera recorder.
rule 3 any -> 10.20.0.44:8000 (NVR web interface) src: any rule 7 any -> 10.20.0.12:3389 (remote desktop) src: any rule 9 any -> 10.20.0.44:554 (camera stream) src: any
Fix. Remove the rules and reach both over the existing VPN. Minimum version: restrict the source to known addresses today.
Re-audit, 48 days later
We run the identical collection again and publish what actually closed.
| ID | At issue | Now |
|---|---|---|
| C1 | Open | Closed — device removed, guard on 6 of 10 VLANs |
| C2 | Open | Partly — second factor on; rotation pending |
| C3 | Open | Closed — all three rules removed, access via VPN |
| H1 | Open | Unchanged — needs a maintenance window |
What to do about it
You cannot outrun 29 minutes. You can refuse to be the one who takes 247 days.
Three steps. The first one is free and takes a walkthrough and a 45-minute review.
Find out what you actually have
Not a verbal impression of a blinking box. We connect to your equipment, read its real configuration, and hand you a written report ranked critical to low. See a full sample report.
Close the doors standing open
Most of what turns up is a setting, not a purchase. A firewall feature off. A network never really separated. A camera recorder published to the open internet. That is the work.
Then never stop watching
Andrew Igloo, our AI IT Network Administrator, on your live network data around the clock — correlating every layer at once and telling a person the moment something matters. That is how 247 days becomes the same afternoon. Meet Andrew.
The uncomfortable part
Every organization on this page believed it was covered. The firewall was installed. The backup circuit was paid for. The cameras were recording. Nobody was checking whether any of it was actually true.
That gap is the one thing here you can close this month, and it does not take a bigger budget or new equipment. It takes somebody opening the closet, reading what is really configured, and then not looking away. That part is free to start.
Common questions
What do small businesses ask about network threats in 2026?
We're a small business. Are we really a target?
No, and you get attacked anyway. Almost everything that hits a business your size comes from automated scanning that sweeps the whole internet and stops wherever a door is open. In one June 2026 study, a single internet-facing phone-system port recorded 1,869,521 login attempts in 18 days, and 99.8% of that traffic came from datacenter and hosting providers. Nobody chose that server. It was reachable, and so was everything else on that block.
How do attackers actually get in now?
Through your equipment more often than through your people. Exploiting a vulnerability in an internet-facing device (a firewall, VPN or router) is now the leading initial access route at 31% of breaches, up from 20% the year before, ahead of stolen credentials at 13%. Another 48% of breaches involve a third party, which usually means vendor remote access landing on your network. Sources: Verizon Data Breach Investigations Reports 2025 and 2026.
How fast does it move once someone is in?
Faster than a person can respond. The handoff from the criminal who breaks in to the one who does the damage now takes about 22 seconds, down from more than eight hours in 2022 (Mandiant). From the first compromised machine to the second averages 29 minutes (CrowdStrike 2026), and the median time to reach the domain controller is 3 hours 24 minutes (Sophos 2026). Meanwhile the average time to identify and contain a breach is 247 days (IBM 2026), which rose for the first time in five years.
What does a breach actually cost?
The average US data breach cost a record $11.5 million in 2026, up from $10.22 million the year before, and the global average was a record $4.99 million (IBM / Ponemon). How long it runs drives the number: breaches going past 200 days averaged $5.65 million, against $4.32 million for the ones caught sooner. Reported US cybercrime losses passed $20.9 billion in a single year, up 26% (FBI IC3).
Does AI really make this worse?
Yes. It widened the pool of people who can run a serious attack. Anthropic's threat intelligence reporting states that AI has lowered the barriers to sophisticated cybercrime, and that criminals with few technical skills are using AI to conduct complex operations, such as developing ransomware, that would previously have required years of training. The same report documents an actor with only basic coding skills selling AI-built ransomware for $400 to $1,200 a copy. The FBI logged 22,364 complaints referencing AI in 2025.
What would monitoring have changed?
The clock, because the cost of a breach is attached to how long it runs. IBM measured breaches with lifecycles over 200 days at $5.65 million versus $4.32 million for shorter ones, and found organizations using security AI and automation extensively contained breaches 65 days faster. Continuous monitoring is what turns "we found out in eight months" into "we found out that afternoon." On a network where the break-in point is the edge equipment, that layer is where you have to be looking.
Sources
- IBM and Ponemon Institute, Cost of a Data Breach Report 2026 (2026)
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report (2026)
- Check Point Research, A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide (2026)
- Verizon, 2026 Data Breach Investigations Report, with the 2024 and 2025 editions (2026)
- Anthropic, Threat Intelligence Report: August 2025 (2025)
- Anthropic, Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign (2025)
- World Economic Forum, Global Cybersecurity Outlook 2026 (2026)
- Mandiant (Google Cloud), M-Trends 2026 (2026)
- CrowdStrike, 2026 Global Threat Report (2026)
- Sophos X-Ops, Nowhere, Man: The 2026 Active Adversary Report (2026)
- Forescout Research, Vedere Labs, The Riskiest Devices of 2026 (2026)
- CloudSEK, The 5060 Siege: Industrialized Attacks Against the SIP Telephony Ecosystem (2026)
- Cybersecurity and Infrastructure Security Agency, Known Exploited Vulnerabilities Catalog (2026)
- Chelan County, Washington, County Continues to Make Progress in Restoring Systems (2026)
- Port of Seattle, Port Cyberattack Archive (2024)
- Comparitech, Ransomware Gang Gives Franklin Pierce Schools 10 Days to Pay $400K Ransom (2025)
The infrastructure this is about
One local team for the layer these attacks actually target.
Find out what is actually on your network
Free, read-only, and nothing changes. A written report on your firewall, network, Wi-Fi, phones and cameras — ranked, evidenced, and yours whether you hire us or not.