# The Security Poverty Line Is Real, and It's Breaking Supply Chains
The numbers don't add up, and that's the whole problem.
Global cybersecurity spending is closing in on $240 billion annually. Average breach costs hit record highs last year — IBM's most recent data puts the global mean at $4.88 million per incident. By any measure, the industry has never spent more money on defense. And yet small businesses — the companies that stock the shelves, process the payroll, and write the software that larger enterprises depend on every day — are being left completely behind.
This isn't a gap in awareness. It's a structural affordability crisis, and it's quietly eroding the security posture of entire industries from the inside out.
## The Math Doesn't Work for Small Business
A mid-size company running 50 endpoints, one IT generalist, and no dedicated security staff is looking at somewhere between $50,000 and $150,000 per year just to meet a defensible baseline: endpoint detection and response, a SIEM or managed detection service, identity and access management, and basic incident response retainers. That's before factoring in compliance requirements if they touch healthcare, finance, or government contracts.
For a business doing $2 million in annual revenue, that's not a budget line — that's an existential decision.
So most of them don't do it. They run Windows Defender and hope for the best. They reuse passwords across admin accounts. They skip MFA because it's annoying and nobody's made them care yet. And they remain connected — often deeply — to larger organizations that have spent millions assuming their vendors are secure.
That assumption is wrong, and the attack community knows it.
## Supply Chain is the Soft Underbelly
The pattern has been consistent for years now. Threat actors — whether financially motivated ransomware operators or nation-state APTs — figured out long ago that hitting a Fortune 500 directly is hard. Their security teams are funded, their detection is fast, and their incident response is practiced. But their HVAC contractor? Their regional managed service provider? Their small-batch software vendor? That's a different story.
The 2021 Kaseya VSA attack hit around 1,500 businesses through a single MSP software platform. SolarWinds compromised 18,000 organizations through one poisoned update. Change Healthcare's 2024 breach — arguably the worst healthcare supply chain attack ever — cascaded from a single point of failure that touched pharmacies, hospitals, and billing systems nationwide.
The common thread: the initial foothold was rarely in the most-secured environment. It was in the seam.
Small businesses are those seams. And right now, the seams are unpatchable, not because the companies lack knowledge but because they lack capital.
## Why the Insurance Market Made This Worse
For a brief window — roughly 2018 to 2021 — cyber insurance looked like the answer. SMBs that couldn't afford a SOC could at least buy coverage. The market was soft, underwriters were optimistic, and a $1 million policy was attainable.
Then the ransomware wave hit. Loss ratios exploded. Underwriters panicked.
What happened next was predictable in retrospect: premiums spiked, coverage narrowed, and exclusions multiplied. Today, getting a cyber insurance policy that actually covers a meaningful ransomware event requires demonstrating security controls — MFA, EDR, backup hygiene, incident response planning — that small businesses often can't afford to implement in the first place. It's a qualification barrier that functions as a de facto wealth test.
The businesses that most need a financial backstop can't get one. The businesses that least need it qualify easily. The market has optimized itself into irrelevance for the bottom half of the economy.
## What's Actually at Stake
This isn't abstract risk. It's operational. Defense contractors with classified supply chains are required to meet CMMC standards, but enforcement is still catching up to reality, and the SMB defense industrial base is notoriously under-resourced. Healthcare networks rely on hundreds of small software vendors, billing services, and regional labs — any one of which can be the pivot point for a systemwide compromise. Financial services firms aggregate customer data through mortgage brokers, insurance agents, and wealth advisors who operate on thin margins and thinner security budgets.
When regulators and larger enterprises push compliance requirements downstream without accompanying resources, they're not solving the problem. They're transferring liability. The risk remains; it just moves until it explodes somewhere unexpected.
## What Defenders Can Actually Do
If you're a small business, a few targeted moves matter more than broad spending:
Prioritize identity. Most breaches enter through compromised credentials. MFA on everything internet-facing — email, VPN, admin consoles — is non-negotiable and cheap. Microsoft Authenticator is free. There is no excuse for exposed admin accounts without it.
Know your crown jewels. You cannot protect everything on a limited budget. Identify what data would hurt most to lose or expose — customer PII, payment data, proprietary operations — and layer controls specifically around those systems rather than trying to secure the perimeter uniformly.
MSPs are a force multiplier, not a substitute for hygiene. A managed security provider can extend your capabilities dramatically, but vet them hard. The Kaseya attack was a reminder that your MSP's security posture is your security posture. Ask about their own MFA policies, their patch cadence, and their incident response obligations before you sign.
Tabletop now, not after the breach. A two-hour exercise with your key people — what do we do if ransomware locks our systems Friday night? — costs nothing and surfaces gaps that no tool can catch.
For larger enterprises and prime contractors: your supply chain security is only as strong as your weakest vendor. Supplier security questionnaires are a start, but they're self-reported and widely gamed. Contractual security requirements without support programs — training, subsidized tooling, shared threat intelligence — are theater.
---
## HackWire Analysis
The framing of this as an "affordability crisis" is accurate but undersells the structural problem. What we're really watching is a security bifurcation: a two-tier ecosystem where large enterprises are increasingly defensible and small businesses are functionally abandoned.
That bifurcation doesn't stay contained. It propagates upward through supply chains, creating attack surfaces that are essentially invisible to the organizations they threaten. A tier-one defense contractor can have a world-class SOC and still be compromised through a tier-four parts supplier running an unpatched server on a DSL connection.
The most alarming trend isn't the breach cost figure — it's the velocity at which the gap is widening. Enterprise security tooling has advanced rapidly: XDR, AI-assisted detection, automated response playbooks. None of that technology is accessible to a 20-person company. The tooling gap compounds the budget gap, and both are accelerating.
The policy conversation is finally starting to catch up. CISA's Secure by Design initiative is explicitly targeting vendors to reduce the burden pushed onto customers. The FTC has signaled renewed interest in holding software makers accountable for predictable vulnerabilities. But regulatory timelines move in years, and attackers move in hours.
The uncomfortable truth is that the security industry has made billions solving the problems of organizations that could afford to pay for solutions. The organizations that can't — the small manufacturers, regional healthcare providers, local government agencies — have been afterthoughts. That's a market failure with national security implications, and treating it like a marketing opportunity ("here's our SMB-tier package") is not going to close it.
— HackWire Editorial
---
## Related Coverage