Skip to content

Data

The small-business guide to customer data you can actually use

What you are required to protect, what you should protect anyway, and how to start without a security team.

Most small business owners think of customer data as an asset. It is. It is also a liability sitting on your servers, in your inbox, and in whatever spreadsheet your team uses to track clients. The moment you collect a name, an email, a card number, or a health detail, you have taken on a duty to protect it. The question is whether you are doing that on purpose or by accident.

Here is the uncomfortable part. Attackers have figured out that small businesses are the soft target. Roughly 43% of all cyberattacks now aim at small businesses, in large part because their defenses are thin and predictable (ElectroIQ, 2025). The cost when one lands is not small either. A typical incident runs from $120,000 to well over $1 million, and 60% of small businesses that are breached close within six months (Total Assure, 2025).

You do not have to be a target worth a fortune. You just have to be easier to reach than the business next door.

43% of cyberattacks target small businesses
60% of breached small businesses close within 6 months
$120k+ typical cost of a single incident

What you are actually required to protect

This is where most owners are surprised. Data protection is no longer just a best practice. It is law in a growing share of the country. As of the end of 2025, 20 U.S. states have comprehensive consumer privacy laws on the books, with new ones taking effect in 2025 across Iowa, Delaware, Nebraska, New Hampshire, Tennessee, Minnesota, and Maryland (White & Case, 2025).

The common assumption is that these rules are for the big companies. Not anymore. Nebraska's law has no small-business exemption at all, no minimum revenue and no minimum number of customers (Cookie-Script, 2025-2026). And if you serve customers in California, the updated CPRA now carries stricter requirements for vendor contracts and consent, and has ended the temporary exemptions that small operators leaned on (Cookie-Script, 2025-2026).

At a minimum, most of these laws expect you to: post a real privacy notice, let customers access and delete their data, and maintain reasonable security measures. The phrase "reasonable security measures" is doing a lot of work, and it is exactly where unprepared businesses get exposed.

What you should protect anyway

Set the law aside for a second. Even where you are not legally required to act, two facts make protection worth it on its own. Ransomware was a factor in 44% of all breaches in 2025, up sharply from the year before, and 88% of small-business breaches involved ransomware (Total Assure, 2025). And the damage outlives the incident: 29% of businesses that suffer a breach lose customers permanently (Total Assure, 2025).

An ounce of prevention is worth a pound of cure.

Benjamin Franklin

The reputational hit is the part that never shows up on the invoice. Customers hand you their information on trust. Lose it once and you do not just pay to clean up the breach. You pay to win back the people who left.

Share of breaches involving ransomware · 2024 to 2025

32%
2024
44%
2025
88%
Small-biz breaches

How to start without a security team

You do not need a CISO to close the most common gaps. You need to know where your data lives, who can touch it, and what would happen if it disappeared. Three moves cover most of the exposure:

First, map your data. Write down every place customer information is stored and every tool that touches it. Most owners cannot do this from memory, which is itself the warning sign.

Second, control access and back up everything. The majority of damaging incidents start with one compromised login or one un-backed-up system. Multi-factor authentication and reliable backups are unglamorous and they stop a remarkable amount of harm.

Third, get your privacy notice and data practices reviewed against the states you actually operate in. This is the piece that turns "we think we are fine" into "we are documented and defensible."

The businesses that survive the next five years will not be the ones that never got targeted. They will be the ones who decided, before anything went wrong, to treat the data they hold as something worth protecting.

Sources ElectroIQ · Total Assure · White & Case · Cookie-Script

Written by

Danelle Kinzie

Danelle has spent two decades in employee and group benefits, leading teams of 200+ and helping owners bring enterprise-grade protection within reach.

Talk to Danelle
All articles