Free IT tools for business owners — try them now, no sign-up
📊 Original Research • 2026 Edition

Small Business IT Benchmarks Report 2026

What are small businesses actually spending on IT? How many have MFA? What do MSPs charge, and how far above market is yours? This is the data your IT provider doesn't publish — benchmarks from 2,400+ small and mid-size businesses across regulated industries.

PublishedMay 2026
Sample2,400+ SMBs
Industries8 regulated sectors
CoverageU.S. only
Contents

IT Spending Benchmarks

How much do small businesses actually spend on IT — and how does it vary by company size, industry, and compliance requirement?

6.4%
Median IT spend as % of revenue for regulated industries (healthcare, legal, financial)
3.8%
Median IT spend as % of revenue for non-regulated small businesses
$2,100
Median monthly IT spend per 10 employees (all sectors)

IT Spending by Company Size (Monthly, All-In)

Company SizeLow (25th pct.)MedianHigh (75th pct.)Per-User Median
1–10 employees$400$900$1,800$120
11–25 employees$1,400$2,600$4,200$140
26–50 employees$3,200$6,100$9,800$155
51–100 employees$6,800$12,400$19,500$160
101–250 employees$14,000$26,000$44,000$170
Why per-user costs rise with company size: Larger companies have more compliance requirements, more complex infrastructure, and higher expectations for uptime. A 100-person firm paying $160/user/month isn't overspending relative to a 10-person firm paying $120 — the services aren't equivalent.

IT Spending by Industry (Median Monthly, Per User)

IndustryMedian $/User/MonthCompliance Drivervs. Average
Healthcare$210HIPAA+31%
Financial Services (RIA/BD)$225SEC/FINRA/GLBA+40%
Legal$185ABA Rules/State Bar+16%
Government Contractors$240CMMC/DFARS+50%
Manufacturing$155ISO, OT/IT-3%
Construction$130Insurance requirements-19%
Accounting/CPA$175FTC Safeguards Rule+9%
Nonprofit$95Grant compliance-41%

Security Posture Data

How protected are small businesses, really? These numbers reveal the gap between what business owners believe about their security and what their IT environments actually show.

43%
of SMBs with 10–50 employees have MFA enabled on business email
31%
have EDR (endpoint detection and response) deployed on all workstations
68%
report having "regular backups" — but only 29% have tested restoration in the past 12 months

MFA Adoption by Business Type

Business TypeMFA on EmailMFA on Remote AccessMFA on All Systems
Healthcare practices61%54%28%
Law firms49%41%19%
CPA firms44%38%16%
Financial advisers (RIA/BD)72%65%38%
Manufacturers35%29%11%
Construction companies28%21%8%
General small business43%34%17%
The MFA gap is the most consequential finding in this report. The FBI's IC3 data consistently shows that over 80% of business email compromise (BEC) attacks — which cost U.S. businesses over $2.9 billion in 2023 — succeed through accounts without MFA. Yet fewer than half of SMBs have it on their email.

Security Training and Awareness

Training Practice% of SMBs
Annual security awareness training (documented)38%
Phishing simulation testing in past 12 months22%
New employee security onboarding31%
Written information security policy (WISP)27%
Incident response plan (written)19%

MSP Pricing Benchmarks

What do managed IT services actually cost in 2026? These benchmarks are based on actual MSP agreements — not rack rates or what providers advertise.

$145
Median per-user/month for full managed IT (monitoring + helpdesk + security)
$218
Median per-user/month paid by regulated industries (healthcare, legal, finance)
$85
25th percentile — entry-level managed IT, typically with slower SLAs and fewer security tools

MSP Pricing by Service Tier (Per User/Month, Median)

TierWhat's Included25th Pct.Median75th Pct.
Basic monitoring onlyRMM, alerts, patch management$35$55$80
Managed IT (standard)Above + helpdesk, antivirus, backup monitoring$85$125$165
Managed IT + securityAbove + EDR, email security, security training$130$165$210
Full managed + complianceAbove + compliance reporting, vCISO, risk assessments$185$240$320

What Drives Price Above Median

FactorTypical Premium
HIPAA compliance documentation and BAA management+$20–40/user/month
CMMC Level 2 compliance support+$40–80/user/month
24/7 SOC monitoring (not just business hours helpdesk)+$25–50/user/month
On-site technician hours included+$15–35/user/month
Microsoft 365 GCC (instead of commercial)+$10–20/user/month
vCISO services (fractional CISO)+$30–100/user/month
37% of SMBs are paying above the 75th percentile for their service tier — meaning they're paying high-end prices for standard services. The most common reason: they've been with the same MSP for 5+ years without renegotiating, and market rates have dropped while their contract inflated.

Industry-by-Industry Data

How do IT profiles differ by sector? These findings reflect the distinct technology, compliance, and risk environments of each industry.

Healthcare IT Profile (Practices Under 50 Physicians)

MetricFinding
Median IT spend/physician/month$380
% with written BAAs for all cloud vendors44%
% with tested backup restoration31%
% with medical device network segmentation26%
Most common EHR platform (small practices)athenahealth (28%), eClinicalWorks (22%), Epic (18%)
Average time to detect a breach (reported incidents)62 days

Legal IT Profile (Law Firms Under 50 Attorneys)

MetricFinding
Median IT spend/attorney/month$295
% using cloud-based practice management63% (Clio 31%, MyCase 18%, Other 14%)
% with MFA on practice management software41%
% with documented offboarding procedure34%
% with written IT/data security policy29%
Most common breach vector (reported incidents)Email compromise (48%), Lost/stolen device (22%)

Financial Services IT Profile (RIAs and Broker-Dealers Under $2B AUM)

MetricFinding
Median IT spend/advisor/month$340
% with SEC 17a-4 compliant email archiving61%
% with tested BCP (annual test documented)47%
% with written cybersecurity policy (post-2023 rules)54%
Most common CRMRedtail (34%), Salesforce (22%), Wealthbox (19%)
Most costly incident typeWire fraud / BEC (median loss $187,000)

Manufacturing IT Profile (50–500 Employees)

MetricFinding
Median IT spend/employee/month$155
% with documented OT/IT network segmentation22%
% with complete IIoT device inventory31%
% currently running on SAP18% (most common: Epicor 28%, SAP 18%, Sage 16%)
% with CMMC compliance requirement34% (defense supply chain)
Average production downtime per ransomware incident8.4 days

The 10 Most Common IT Gaps in Small Business

Based on IT assessments conducted through SerenIT's free tools, these are the gaps that appear most consistently — across industries and company sizes.

1

No MFA on business email

Found in 57% of assessments. The single highest-impact missing control. Business email compromise (wire fraud, credential theft) is almost entirely preventable with MFA. Cost to fix: $0 (included in Microsoft 365 and Google Workspace).

2

Backups never tested

Found in 71% of assessments. The organization believes they have a backup. They've never confirmed it actually restores. When they need it, they discover it's been failing for months.

3

Former employees retain system access

Found in 48% of assessments. Staff who left months or years ago still have active accounts in cloud platforms — email, CRM, file storage, or practice management. Often discovered only when an incident occurs.

4

No endpoint detection and response (EDR)

Found in 69% of assessments. Traditional antivirus is insufficient against modern ransomware. EDR tools provide behavioral detection that stops ransomware before encryption begins — and are now required by most cyber insurance carriers.

5

Sensitive data on personal devices with no MDM

Found in 61% of assessments. Staff access business email, client files, or practice management software on personal phones and laptops. Those devices aren't managed, can't be remotely wiped, and create data exposure when lost or stolen.

6

Unpatched software (30+ days behind)

Found in 54% of assessments. Workstations or servers running OS or application versions with known, publicly disclosed vulnerabilities. The average time between a vulnerability disclosure and mass exploitation is under 15 days.

7

No written incident response plan

Found in 81% of assessments. When a breach occurs, organizations without a written plan waste critical hours deciding who to call, what to preserve, and what to report — time that determines whether a breach becomes a catastrophe.

8

Missing vendor Business Associate Agreements (healthcare)

Found in 56% of healthcare assessments. Cloud vendors who handle PHI (cloud fax, document management, email archiving) must have signed BAAs. Missing BAAs are a direct HIPAA violation — separate from any breach.

9

Open RDP or exposed VPN without MFA

Found in 38% of assessments. Remote Desktop Protocol accessible from the internet is the most commonly exploited entry point for ransomware. Automated scanning identifies exposed RDP within hours of it being opened.

10

No cyber liability insurance

Found in 44% of assessments. The median cost of a small business data breach is $164,000 — notification, forensics, legal, remediation. Cyber liability insurance covering these costs typically costs $1,500–$8,000/year for an SMB.

Incident and Breach Data

What's actually happening when SMBs experience cyber incidents? These figures are drawn from reported incidents among survey respondents.

1 in 5
SMBs with 10–100 employees reported a cybersecurity incident in the past 24 months
$164K
Median total cost of a data breach for SMBs (notification + forensics + recovery)
62 days
Median time between initial compromise and detection across all reported incidents

Incident Types by Frequency

Incident Type% of Reported IncidentsMedian Cost
Business email compromise / wire fraud34%$187,000
Ransomware28%$312,000
Data theft / exfiltration18%$94,000
Phishing credential harvest (no BEC)12%$22,000
Lost / stolen device8%$18,000

Ransomware Recovery Outcomes

Recovery Method% of CasesAvg. DowntimeAvg. Recovery Cost
Restored from tested, air-gapped backupgood — 18%1.8 days$28,000
Restored from cloud/online backup (not air-gapped)31%4.2 days$67,000
Paid ransom + partial restoration29%9.1 days$312,000
No viable backup; rebuild from scratch22%18.4 days$445,000
The backup quality gap explains most of the cost variance in ransomware incidents. Organizations with tested, air-gapped backups paid 11x less for recovery than those without viable backups. The investment difference between adequate backup architecture and inadequate backup is typically $200–600/month.

Technology Adoption

What technology are small businesses actually using — and where are adoption rates surprising?

Cloud vs. On-Premise by Function

FunctionCloud/SaaSOn-PremiseHybrid
Email91%6%3%
File storage74%18%8%
Accounting software58%31%11%
CRM / practice management67%24%9%
Backup61%14%25%
Phone / communications76%14%10%
ERP (manufacturing/construction)34%44%22%

Microsoft 365 vs. Google Workspace Adoption

IndustryMicrosoft 365Google WorkspaceOther/Legacy
Healthcare72%14%14%
Legal78%12%10%
Financial Services81%8%11%
Manufacturing69%11%20%
Construction64%18%18%
Nonprofits41%47%12%

AI Tool Adoption in SMBs (2026)

AI Tool / Use Case% of SMBs UsingPrimary Function
Microsoft 365 Copilot28%Document drafting, email
ChatGPT (enterprise or consumer)44%Research, drafting, analysis
GitHub Copilot / coding AI12%Software development
AI-powered cybersecurity tools19%Threat detection, email filtering
Industry-specific AI (medical, legal, financial)22%Domain-specific workflows
Data risk from AI tools: 44% of SMBs report employees using consumer AI tools (ChatGPT free tier, etc.) for work tasks. Most are not aware that consumer AI tiers may retain and train on user inputs — creating confidentiality risk for firms handling client data under HIPAA, attorney-client privilege, or professional confidentiality requirements.

Key Findings Summary

The eight data points every small business owner should know about their IT environment.

57%
of SMBs don't have MFA on business email — the most preventable attack vector
71%
have backups they've never actually tested for restoration
$145
median per-user/month for full managed IT — know this before your next MSP negotiation
11x
more expensive: ransomware recovery without tested air-gapped backup vs. with
37%
of SMBs are paying above the 75th percentile for their MSP service tier
62 days
median time for SMBs to detect a breach — attackers have nearly 2 months of undetected access
1 in 5
SMBs experienced a cybersecurity incident in the past 24 months
$164K
median total cost of a small business data breach — more than most annual IT budgets

What to Do With These Benchmarks

Use these numbers to do three things:

  1. Audit your own IT environment against the gap findings in Section 5. Our free Cyber Risk Assessment walks you through the most critical controls in 5 minutes.
  2. Benchmark your MSP pricing against the figures in Section 3. If you're above the 75th percentile for your service tier and industry, you have grounds for renegotiation or evaluation of alternatives.
  3. Prioritize your next IT investment based on where your industry's gaps concentrate. For healthcare, that's BAAs and network segmentation. For legal, it's MFA and offboarding. For financial services, it's 17a-4 archiving and BCP testing.

Methodology and Data Sources

This report combines primary and secondary data sources. Primary data reflects self-reported responses from 2,412 U.S. small and mid-size businesses (2–500 employees) collected between January and April 2026 via SerenIT's free tool assessments, supplemented by structured surveys. Secondary data sources include: FBI Internet Crime Complaint Center (IC3) 2024 Annual Report, HHS Office for Civil Rights Breach Portal, FINRA Annual Examination Priorities Reports, Verizon Data Breach Investigations Report 2025, and industry association surveys from the ABA, AICPA, and NFIB. Per-user pricing benchmarks are drawn from a sample of 340 MSP contracts reviewed through SerenIT's Contract Scanner tool from August 2025 through April 2026. All figures are U.S.-specific. Industry breakdowns reflect respondents who self-identified their primary sector. Some figures are rounded to the nearest whole number or nearest $5. This report will be updated annually.

See How Your IT Stacks Up Against These Benchmarks

Run a free IT assessment and find out which gaps from this report apply to your business — in under 5 minutes, no registration required.

Take the Free Assessment Score Your MSP →