For the first time in the 19 years Verizon has published its Data Breach Investigations Report, exploiting a software vulnerability has overtaken stolen credentials as the number one way attackers get in. The 2026 edition puts vulnerability exploitation behind 31 percent of breaches, and the reason isn’t that criminals got smarter. Only 26 percent of known exploited vulnerabilities were remediated during 2025, down from 38 percent the year before, while AI has compressed the gap between a flaw becoming public and being weaponized from months to hours.
That single finding should reorder how a small business spends its security budget, because the thing breaking in is increasingly not the thing antivirus was built to catch. Ransomware now appears in 48 percent of all breaches, up from 44 percent, and Verizon’s SMB-specific data has put ransomware in 88 percent of small business breaches against 39 percent for large enterprises. Here’s what the independent testing actually shows, what the tiers really cost, and which of it you’re already paying for without knowing.
Buy in the order attackers actually get in, not the order vendors sell
The 2026 DBIR found the human element involved in 62 percent of breaches, with social engineering accounting for 16 percent on its own. Third-party compromise appeared in 48 percent of breaches, a 60 percent jump year over year, meaning your vendor’s security failure is now roughly as likely to hurt you as your own. Attackers have also moved to phones, where simulated voice and SMS lures produced a median click rate of 2 percent against 1.4 percent for email, about 40 percent higher.
Put that together and the priority order is patching, multi-factor authentication, backups, email and identity filtering, and then endpoint software. Endpoint protection is the layer everyone shops for and it’s the fourth or fifth most valuable thing you can spend on. There’s evidence the boring items work, too. Median ransom payments fell to $139,875 and 69 percent of victims refused to pay, which the report treats as measurable progress driven by better backups and faster recovery rather than better detection.
One detail from this year’s report is worth repeating because it says something about how fast the ground is moving. The DBIR notes that AI-assisted text in malicious emails has roughly doubled, and joked that its phishing detection guidance is shifting from asking whether a message contains many typos to asking whether it contains the em dash. Employee training built around spotting bad grammar is training for a threat that no longer exists.
You probably already own more security than you’ve switched on
Microsoft 365 Business Premium runs around $22 per user per month and bundles Microsoft Defender for Business, Intune for device management, Entra ID Premium P1 for conditional access, and Defender for Office 365 Plan 1 for email filtering. Defender for Business covers up to 300 users with five devices each, and it’s genuine endpoint detection and response with automated investigation and vulnerability management, not a stripped consumer antivirus. Bought standalone it runs roughly $3 per user per month, so inside the Business Premium bundle the incremental cost of your endpoint security is effectively zero.
Most small businesses on that license are paying for EDR, mobile device management and conditional access and using approximately none of it. Before you evaluate a single third-party product, enforce MFA on every account or move to passkeys where you can, turn on automatic patching for operating systems and third-party applications, block legacy authentication protocols in conditional access, and confirm your backups restore rather than merely run. All of that is included and all of it addresses the vectors the DBIR just ranked at the top.
Worth noting on timing, since it changes the math for some buyers. From July 1, 2026, Microsoft 365 Business Standard picks up Defender for Office 365 Plan 1 and several Intune capabilities alongside a $3 per user per month price increase. If you’re on Standard and were planning to buy email security separately, check what your renewal now includes before you sign anything else.
What the independent labs measured in 2026, and what those numbers don’t tell you
AV-Comparatives ran its Business Security Test from March to June 2026 across 16 vendors, covering Avast, Bitdefender, Cisco, CrowdStrike, Elastic, ESET, G Data, K7, Kaspersky, ManageEngine, Microsoft, Norton, SenseOn, Sophos, Trellix and VIPRE. Kaspersky, Bitdefender and Elastic tied at the top with a 99.8 percent protection rate across 400 real-world test cases, and Elastic recorded a perfect 100 percent in malware detection. ESET and Kaspersky showed the lowest impact on system speed. Fifteen products earned the Approved Enterprise Product award, which requires at least 90 percent protection in malware testing with zero false positives against business software.
Consistency over time is more useful than a single result. Across three years of these tests from March 2023 through November 2025, Bitdefender averaged 0.5 compromised systems per test against a competitor average of 4, which translates directly into fewer reimages and fewer investigation hours.
Two caveats keep those numbers honest. AV-Comparatives invites each vendor to configure its own product for the test, often at aggressive settings that are not the defaults you’ll get out of the box, so published protection rates describe a tuned deployment rather than an installed one. More importantly, the composite protection score doesn’t weight phishing heavily, and a credential-harvesting page that steals a session token before any file touches disk is the dominant small business entry point. A product can post a 99.9 percent malware score and still leave you exposed to the attack you’re most likely to face.
Real 2026 pricing, and why the sticker is rarely the price
Bitdefender’s GravityZone Small Business Security starts around $227 a year covering up to 100 devices and three servers, with GravityZone Business Security landing in the $4 to $7 per endpoint per month range and the Premium tier at roughly $6 to $9. ESET PROTECT runs about $3 to $5 for Entry, $5 to $8 for Advanced and $7 to $10 for Complete. Sophos Intercept X Advanced sits around $5 to $8, rising to $10 to $15 with its managed response service attached.
CrowdStrike publishes cleaner numbers than most, which makes it useful for budgeting even if you don’t buy it. Falcon Go lists at $59.99 per device per year or $7.99 per month, Falcon Pro at $99.99 per device per year, and Falcon Enterprise at $184.99. Read the tier definitions carefully, because Falcon Go is next-generation antivirus with device control and mobile protection rather than full EDR, and it’s capped at 100 endpoints. SentinelOne’s Core, Control and Complete tiers run roughly $5 to $7, $7 to $9 and $9 to $12 per endpoint per month.
None of those are what a small business actually pays. Channel and reseller discounts of 20 to 30 percent are well documented, competing quotes reliably produce movement, and renewal pricing after a promotional first year frequently multiplies. If a vendor won’t publish pricing at all, that’s a signal about how the negotiation will go rather than a mark against the product. Get quotes from at least two vendors in the same tier and ask specifically what year two costs.
The question that actually decides your shortlist is who reads the alerts at 2am
Endpoint detection and response is a detection product. It generates alerts, and alerts are only worth what the person reading them does next. A small business with no dedicated security staff that buys the most sophisticated platform available has usually purchased an extremely detailed recording of its own breach. That’s the real dividing line in this category, and it matters more than any protection percentage.
Match the tool to your staffing honestly. CrowdStrike rewards an environment where somebody actively hunts and investigates. Bitdefender is the simplest of the dedicated platforms for a generalist IT person to operate. SentinelOne’s automated response and ransomware rollback reduce how much human investigation a given alert needs, which is why it suits shops without a security analyst. Managed detection and response, where somebody else’s security operations center watches your alerts around the clock, adds roughly $5 to $20 per endpoint per month, or comes bundled in products like Huntress at around $8.99 per endpoint per month.
Check your cyber insurance application before you finalize any of this. Carriers increasingly make MFA and deployed EDR a condition of coverage rather than a discount, and buying a product that doesn’t satisfy the questionnaire you’ll answer in six months is an expensive way to learn the requirement. Read the questionnaire first and let it shape the shortlist.
The protection scores at the top of the independent tests are separated by fractions of a percent, and the genuine differences between the leading products are smaller than the marketing suggests. What isn’t small is the gap between a business that patches promptly, enforces MFA and tests its restores and one that bought excellent endpoint software instead of doing those things, which is why the most valuable security purchase most small businesses can make in 2026 is usually the license they already own and never configured.

