The evidence · Updated August 2026
A question of IF has become a question of WHEN...
Attacks on business networks are up. The skill needed to run one has collapsed. The way in is now your firewall, not your staff. And the time it takes anyone to notice just got longer for the first time in five years.
Every number below is from a primary source and named on the page. Read it, then decide whether anyone is currently watching your network.
What it costs
A breach is now the most expensive thing that can happen to a small business
$11.5M
Average US breach cost
A record, two years running — up from $10.22M the year before. The global average also hit a record, rising 12%.
IBM / Ponemon, Cost of a Data Breach 2026
$20.9B
Reported US losses in one year
Up 26% in twelve months, and past $20 billion for the first time. That is only what victims bothered to report.
FBI IC3, 2025 Internet Crime Report
2,270
Attacks per business, per week
Up 70% since 2023 and still climbing. Not attacks on the internet — attacks per organization, every week.
Check Point Research, June 2026
32% → 48%
Breaches involving ransomware
Across three consecutive annual reports. Nearly half of all confirmed breaches now involve somebody holding your business hostage.
Verizon Data Breach Investigations Report, 2024–2026
And the number that should worry you most is the one going the wrong way:
“The mean time organizations took to identify and contain a breach rose to 247 days, a slight 2.5% uptick that reversed a five-year decline.” — IBM / Ponemon, Cost of a Data Breach 2026
247 days. Eight months between the break-in and anybody finding out. And that duration is not free: IBM measured breaches running past 200 days at $5.65 million against $4.32 million for the ones caught sooner. The clock is the bill.
Why now
Anyone can do this now. That is the whole change.
Attacking a business network used to take years of learning. That barrier is gone — and the clearest statement of it comes not from a security company with something to sell, but from an AI company auditing its own product.
“AI has lowered the barriers to sophisticated cybercrime. Criminals with few technical skills are using AI to conduct complex operations, such as developing ransomware, that would previously have required years of training.” — Anthropic, Threat Intelligence Report, August 2025
In that same report, Anthropic documented an actor with only basic coding skills who used AI to build ransomware and sell it on criminal forums for $400 to $1,200 a copy. The FBI logged 22,364 complaints referencing AI in 2025, with $893.3 million in reported losses.
FBI IC3, 2025 Internet Crime Report
“We’re too small to be worth the effort”
That was a reasonable bet when effort was the constraint. It is not one anymore.
Almost nothing that hits a small business is a targeted attack. It is automated scanning that sweeps the entire internet and stops wherever a door is open — and it does not know or care how big you are.
What it finds is almost never exotic. It is a firewall feature switched off. A guest Wi-Fi that was never actually separated from the computer running billing. A password still set to whatever it shipped with.
Nobody has to be after you specifically. They just have to find you before somebody on your side finds the setting.
And it is about to get worse. In November 2025 Anthropic disclosed an attack campaign in which AI performed 80–90% of the work, with humans stepping in at only four to six decision points across the entire operation. The World Economic Forum called it the first confirmed case of agentic AI reaching high-value targets. The number of people who can run a campaign like that is no longer limited by skill. It is limited by how many of them decide to.
The clock
They move in minutes. Most businesses find out in months.
22 seconds
From breaking in to handing your network off to the criminal who does the damage — down from more than eight hours in 2022.
Mandiant
29 minutes
Average time from the first compromised machine to the second — down from 48 minutes, and from 62 the year before that.
CrowdStrike Global Threat Report 2026
3 hours 24 minutes
Median time to reach the domain controller — the machine that holds the keys to everything else.
Sophos Active Adversary 2026
247 days
Average time to identify and contain the breach. Against minutes of attack, that is the entire fight in one comparison.
IBM Cost of a Data Breach 2026
Nobody wins that race by being faster than the attacker. You win it by not being the business that takes eight months to notice.
Where they get in
It stopped being your staff. It is your equipment.
For years the advice was to train people not to click things. The data moved on.
20% → 31%
Exploiting an internet-facing device
Your firewall, VPN or router is now the leading way attackers get their first foothold — ahead of stolen passwords at 13%.
Verizon DBIR 2026, n=19,905 breaches
15% → 48%
Breaches involving a third party
Tripled in two years. Your vendors’ remote access lands on your network — and almost nobody is watching what it does once it gets there.
Verizon DBIR 2026
38% → 26%
Known flaws actually getting fixed
Of the vulnerabilities the US government confirms are under active attack, the share organizations fully patched fell. The doors are being found faster than they are being closed.
Verizon DBIR 2026
Read those three together. The break-in point moved to the box in your closet. Half of breaches now arrive through somebody you gave access to. And the known holes are being patched more slowly than last year. Every one of those is on the network layer — which is exactly the layer nobody at a 30-person company is watching.
The part nobody checks
Your phone system is on the internet, and it is being knocked on right now
The riskiest device you own
VoIP systems ranked the riskiest connected device category of 2026, up from third the year before.
Forescout, Riskiest Connected Devices 2026
1.8 million attempts in 18 days
One internet-facing phone-system port recorded 1,869,521 login attempts against 29,433 extensions, plus 89,465 attempted fraudulent calls — in under three weeks. Toll fraud lands on your bill, not theirs.
CloudSEK SIP honeypot study, June 2026
Confirmed exploited by the US government
A business phone-system flaw was added to CISA’s Known Exploited Vulnerabilities catalog — the federal list of flaws confirmed to be under active attack. Seven more sit there for one major phone vendor, five of them tied to ransomware.
CISA KEV catalog
And here is why that is fixable today
99.8% of that attacking traffic came from datacenter and hosting providers, and 93.5% of the addresses were already on published abuse lists. This is machinery sweeping the internet, not a person choosing you.
Which means a correctly configured firewall in front of the phone system stops nearly all of it. That is not a product you need to buy. It is a setting somebody needs to have gotten right — and it is one of the first things we look at, because we do not think phones and network security are two separate purchases.
Not a big-city problem
When it happens, the phones go down with the network
These are not Fortune 500 headlines. They are ordinary organizations, and in every case the thing people actually noticed was that they could not make a call.
A county government
Shut down all government computers, networks and telephone lines in what it described as “a three-week, system-wide disruption.” Its own commissioner said they had “the same type of protections in place that most of corporate America has — and then some.”
Chelan County, WA — official release, June 2026
A major port and airport
“Maritime facilities phone systems are down as part of a system outage.” Baggage, check-in kiosks, ticketing, Wi-Fi and passenger displays all disrupted. They refused to pay.
Port of Seattle — official cyberattack notice
A school district
Cancelled classes across 14 schools for roughly 7,300 students after a server, network, internet and phone outage.
Franklin Pierce Schools, WA — June 2025
And if you think trade businesses are overlooked: of ransomware complaints from non-critical-sector businesses, legal services made up 18%, contracting 17%, and engineering and architecture 10%. FBI IC3, 2025
How we solve it
We can’t listen in 24/7 to a network. Andrew Igloo can.
No person can watch a network every second of every day. Nobody has ever been able to. Andrew Igloo is our AI IT Network Administrator — and he does exactly that, from The Igloo, correlating every layer at once, explaining what he finds in plain English, and putting a human on it the moment something matters.
Andrew sees the whole picture at once
“The internet is slow” touches five layers, and a technician checks them one at a time. Andrew reads all of it simultaneously and hands you a sentence: the circuit is healthy, one wired machine is saturating the upload, and three wireless devices are fighting a neighbour’s access point that moved onto your channel this week.
He translates, so you can decide
Every device on your network produces roughly 150 fields of data. Nobody reads that. Andrew turns wifi_tx_retries_percentage into “the tablets in the warehouse are fighting for airtime.” Same data. One version you can act on.
You can just ask him
“Why was the warehouse Wi-Fi bad Tuesday afternoon?” is a question you ask in plain English and get answered from the actual data — not a question you file a ticket about and wait two days for.
Three things Andrew catches that nobody else does
“Why was the internet down Tuesday?”
Somebody plugs a home router into a spare wall port. It starts handing out network addresses. Some machines lose the internet, the printers, the accounting server — not all of them, not consistently. It looks like a dozen unrelated faults, clears up by afternoon, and happens again next month.
We detect your network’s addressing changing and name the exact device — its hardware address, its vendor, when it appeared, and which machines took a bad lease.
“The backup internet was already dead.”
You pay every month for a second circuit so the business keeps running when the first fails. On a real audit in July 2026, one showed 0.0% availability for every one of the 11.5 days the gateway had been running. It had never raised a single alert. The network reported itself as redundant.
A dead backup is worse than no backup. No backup means you plan around it. A dead one means you stopped thinking about it.
“The camera was dead for three weeks.”
Cameras fail silently, recording light still on, in a corner nobody looks at. No user complains. The failure surfaces exactly once — the moment somebody backs into a vehicle or a package disappears, and the footage is not there.
Cameras are network devices. We see one stop responding in about two minutes and tell somebody, instead of you finding out three weeks later.
What Andrew watches, around the clock
Any device going offline, usually inside two minutes · your whole site dropping off · your public address changing · public-facing servers and VPN endpoints that stop answering · the specific port your business software listens on · new devices appearing on your network · changes to your network’s addressing and DNS · internet circuit health against independent targets · who is consuming your bandwidth · per-device wireless quality and interference · equipment heading toward its limits · your phones · your cameras — and the monitoring itself, because a monitor that has quietly stopped looking is indistinguishable from a clean result.
And Andrew does not sleep, which is why we do not bill you for somebody who does. The watching, correlating and triaging is software running at The Igloo. A human is on call and gets paged when it matters. That is how “all for less” works — it describes how we built the service, not a discount.
And here is what you get
The report. Every finding, the evidence behind it, and a fix.
Most providers want you on a call before they will tell you what you would receive. Here is the actual thing. Ranked critical to low, with the exact setting we read and what it means in one sentence.
EXAMPLE MILLWORK CO. · three sites · 25 managed devices
Executive summary
The network is functional and reasonably well built. It is also, in three specific places, wide open in ways nobody chose — an unauthorized device handing out network addresses on the shop floor, a management password stored in recoverable form and reused across all 25 devices, and the camera system published to the open internet from any address. None of the three needs new hardware. Two are settings changes. One needs a maintenance window.
Scorecard
| Domain | Grade | Note |
|---|---|---|
| Perimeter & firewall | D | Three inbound paths open to any source |
| Segmentation | F | Ten VLANs, three rules, nothing enforced between them |
| Identity & access | D | One shared credential, recoverable, no second factor |
| Resilience & backup | D | Config backup scheduled, retaining zero restore points |
| Video & physical | F | Camera recorder reachable from the open internet |
CRITICALC1 — Unauthorized device handing out network addresses
What we found. A device that is not the gateway is answering address requests on the shop-floor network. DHCP guard is not enabled on any VLAN, so nothing prevents it.
mac 02:1f:9c:44:6a:31 (locally administered) vendor (unregistered) first_seen 2026-04-11T07:52:19Z role_observed dhcp_server leases_issued 14 (of 61 clients on VLAN 40)
Why it matters. Fourteen of sixty-one machines on the shop floor took their network settings from an unmanaged device. Those machines lose the file server and the printers intermittently, in a way that looks like a dozen unrelated faults.
Fix. Remove the device, then enable DHCP guard with the legitimate servers allowlisted first. Minimum version: remove it today, schedule guard for the next window.
CRITICALC3 — Camera system and remote desktop published to the internet
What we found. Three inbound rules forward from any source address to internal machines, including the camera recorder.
rule 3 any -> 10.20.0.44:8000 (NVR web interface) src: any rule 7 any -> 10.20.0.12:3389 (remote desktop) src: any rule 9 any -> 10.20.0.44:554 (camera stream) src: any
Fix. Remove the rules and reach both over the existing VPN. Minimum version: restrict the source to known addresses today.
Re-audit, 48 days later
We run the identical collection again and publish what actually closed.
| ID | At issue | Now |
|---|---|---|
| C1 | Open | Closed — device removed, guard on 6 of 10 VLANs |
| C2 | Open | Partly — second factor on; rotation pending |
| C3 | Open | Closed — all three rules removed, access via VPN |
| H1 | Open | Unchanged — needs a maintenance window |
What to do about it
You cannot outrun 29 minutes. You can refuse to be the one who takes 247 days.
Three steps. The first one is free and takes a walkthrough and a 45-minute review.
Find out what you actually have
Not a verbal impression of a blinking box. We connect to your equipment, read its real configuration, and hand you a written report ranked critical to low. See a full sample report.
Close the doors standing open
Most of what turns up is a setting, not a purchase. A firewall feature off. A network never really separated. A camera recorder published to the open internet. That is the work.
Then never stop watching
Andrew Igloo, our AI IT Network Administrator, on your live network data around the clock — correlating every layer at once and telling a person the moment something matters. That is how 247 days becomes the same afternoon. Meet Andrew.
The uncomfortable part
Every organization on this page believed it was covered. The firewall was installed. The backup circuit was paid for. The cameras were recording. Nobody was checking whether any of it was actually true.
That gap is the one thing here you can close this month, and it does not take a bigger budget or new equipment. It takes somebody opening the closet, reading what is really configured, and then not looking away. That part is free to start.
Common questions
Straight answers
We're a small business. Are we really a target?
You are not a target. You are a result. Almost nothing that hits a business your size is aimed at you specifically — it is automated scanning that sweeps the entire internet and stops wherever a door is open. In one June 2026 study, a single internet-facing phone-system port recorded 1,869,521 login attempts in 18 days, and 99.8% of that traffic came from datacenter and hosting providers. Nobody chose that server. It was simply reachable. So was everything else on that block.
How do attackers actually get in now?
Through your equipment, not your people. Exploiting a vulnerability in an internet-facing device — a firewall, VPN or router — is now the leading initial access route at 31% of breaches, up from 20% the year before, ahead of stolen credentials at 13%. A further 48% of breaches involve a third party, which usually means vendor remote access landing on your network. Source: Verizon Data Breach Investigations Report 2026.
How fast does it move once someone is in?
Faster than any person can react. Handoff from the criminal who breaks in to the one who does the damage now takes about 22 seconds, down from more than eight hours in 2022 (Mandiant). Average time from the first compromised machine to the second is 29 minutes (CrowdStrike 2026). Median time to reach the domain controller is 3 hours 24 minutes (Sophos 2026). Meanwhile the average time to identify and contain a breach is 247 days (IBM 2026), which rose for the first time in five years.
What does a breach actually cost?
The average US data breach reached a record $11.5 million in 2026, up from $10.22 million the year before, and the global average hit a record $4.99 million (IBM / Ponemon). Duration drives it: breaches running past 200 days averaged $5.65 million against $4.32 million for the ones caught sooner. Reported US cybercrime losses passed $20.9 billion in a single year, up 26% (FBI IC3).
Does AI really make this worse?
It removed the last thing keeping unskilled people out. Anthropic's own threat intelligence reporting states that AI has lowered the barriers to sophisticated cybercrime, and that criminals with few technical skills are using AI to conduct complex operations, such as developing ransomware, that would previously have required years of training. The same report documents an actor with only basic coding skills selling AI-built ransomware for $400 to $1,200 a copy. The FBI logged 22,364 complaints referencing AI in 2025.
What would monitoring have changed?
The clock, which is the thing the cost is attached to. IBM measured breaches with lifecycles over 200 days at $5.65 million versus $4.32 million for shorter ones, and found organizations using security AI and automation extensively contained breaches 65 days faster. Continuous monitoring is what turns "we found out in eight months" into "we found out that afternoon" — and on a network where the break-in point is the edge equipment, that layer is where you have to be looking.
The infrastructure this is about
One local team for the layer these attacks actually target.
Find out what is actually on your network
Free, read-only, and nothing changes. A written report on your firewall, network, Wi-Fi, phones and cameras — ranked, evidenced, and yours whether you hire us or not.