A law firm in Century City gets a call from a client asking why their contract was posted on a public forum. A medical billing office in Glendale finds out its patient records were listed for sale before its own IT team noticed anything wrong. These are not rare stories anymore. They are the kind of calls small business owners across Los Angeles are increasingly likely to get.
Attackers are not waiting for a mistake anymore. According to IBM’s 2026 Cost of a Data Breach Report, one in four malicious breaches in 2026 involved AI in some form, a 56% jump from the year before, and those AI-enabled breaches cost organizations an average of $6 million, about $1 million more than the overall global average of $4.99 million. Attacks that used to take weeks to plan can now be built in hours. For a small business without a dedicated security team, that speed gap is the whole problem.
This guide walks through what’s actually changed in 2026, what it costs when a breach happens, which Los Angeles industries carry the most exposure, and what a reasonable defense looks like for a business that isn’t running its own security operations center.

Why 2026 Looks Different from Past Years
Every year brings new breach statistics, but 2026 marks a real shift in how attacks start. According to Verizon’s 2026 Data Breach Investigations Report, which analyzed more than 22,000 confirmed breaches worldwide, the exploitation of unpatched software vulnerabilities has overtaken stolen passwords as the leading way attackers get in, involved in roughly 31% of breaches. Verizon also found that only 26% of critical vulnerabilities were fully remediated by organizations in 2025, down from 38% the year before.
That combination matters for small businesses specifically. Larger companies typically have patch management schedules and dedicated IT staff watching for new vulnerabilities. A small business running its own patching on an ad hoc basis is exactly the kind of target this trend describes.
A few other patterns stand out in the 2026 data:
- The human element (phishing, social engineering, stolen credentials, and simple mistakes) was present in 62% of breaches, according to Verizon, up slightly from the year before.
- Third-party and vendor-related breaches jumped 60% year over year and now factor into 48% of all breaches, a reminder that a business’s exposure isn’t limited to its own systems.
- IBM’s research found that reported ransomware incidents rose from 34% to 39% of breaches, with attackers increasingly using AI to scale and automate the attack itself.
None of this means small businesses need enterprise-level security budgets. It means the basics, patching, monitoring, and vendor oversight, matter more than they used to, because attackers are now moving fast enough to punish the businesses that skip them.
What a Breach Actually Costs
Breach cost figures get thrown around a lot, and it’s worth being precise about what they mean. IBM’s 2026 report puts the global average cost of a data breach at $4.99 million, and notes that breach costs in the United States run well above that average, at $10.22 million, more than double the global figure. Those numbers come primarily from mid-size and large organizations across 17 countries, so they shouldn’t be read as “what a 20-person business in Los Angeles will pay.” But they do show the direction costs are moving, and a few of the underlying cost drivers apply just as much to a small business as a large one:
- Detection takes time. Breaches involving stolen credentials took an average of 292 days to resolve, according to IBM, and only about a third of breaches were caught by internal security staff in the first place. A small business without any monitoring in place is likely to find out from a customer, a vendor, or a dark web alert, not from its own systems.
- Multi-environment data is harder to contain. IBM found that breaches involving data spread across multiple storage environments (a mix of cloud apps, local servers, and third-party platforms, which describes most small businesses) took longer to contain and cost more to fix.
- Automation changes the math. Organizations that made serious use of AI and automation in their security operations saw average cost reductions of roughly $1.76 million to $2 million compared to those that didn’t, according to IBM’s research. That’s not a small business number on its own, but the underlying point holds at any size: the businesses that catch a threat early spend far less putting out the fire.
The practical takeaway isn’t the exact dollar figure. It’s that the gap between “we caught this in a day” and “we found out three months later from a client” is where most of the cost lives.
Which Los Angeles Industries Carry the Most Risk
Not every business faces the same exposure. A few sectors that are heavily represented in the Los Angeles business community show up consistently in national breach data:
| Industry | Why It’s a Target |
|---|---|
| Healthcare and medical billing | Patient records combine financial, medical, and identity data in one file, making them valuable on the dark web. IBM’s research has repeatedly found healthcare breaches carry the highest average cost of any industry, largely due to regulatory penalties and the length of time breaches go undetected. |
| Legal and professional services | Law firms and accounting firms hold sensitive client data and are frequent targets of business email compromise, where an attacker impersonates a partner or client to redirect a payment. |
| Financial services | High-value transactions and regulatory obligations make finance firms a consistent second-place industry in breach cost data. |
| Entertainment and media | Los Angeles’s entertainment industry handles unreleased content, contracts, and celebrity personal data, all of which have resale value to attackers. |
If your business falls into one of these categories, the risk isn’t hypothetical. It’s a matter of when your name shows up in an attacker’s target list, not if.
Where Small Businesses Are Exposed That They Don’t Expect
A few blind spots come up again and again with small and mid-size businesses:
Vendor and supply chain access. With third-party involvement in 48% of breaches according to Verizon, a business can do everything right internally and still get breached through a payroll vendor, a cloud app, or an outsourced IT provider with weak access controls. Ask your vendors what security controls they actually have in place, not just what’s in their marketing materials.
Credentials that are already circulating. Employees reuse passwords across work and personal accounts more often than most owners assume. Once one of those accounts is compromised anywhere, including on a site that has nothing to do with your business, that same password is often tried against work logins. Dark web monitoring exists specifically to catch this before it turns into a real breach.
No one watching after hours. A phishing email that lands at 7 p.m. on a Friday has a much longer runway to do damage if nobody notices it until Monday morning. Attackers know this, which is part of why off-hours activity has become more common.
Unpatched software running quietly in the background. With vulnerability exploitation now the top entry point in Verizon’s data, the software your business hasn’t updated in a while, an old plugin, an outdated server operating system, a forgotten VPN appliance, is a live risk, not just a maintenance item.
What a Reasonable Defense Looks Like in 2026
None of this requires building an in-house security department. For most Los Angeles small businesses, a reasonable defense combines a handful of specific capabilities:
- Continuous monitoring, so unusual activity gets flagged the moment it happens rather than discovered weeks later. This is the role a managed SOC plays: watching your environment around the clock instead of during business hours only.
- Detection and response, so a flagged threat gets investigated and contained quickly instead of sitting in a queue. Managed detection and response (MDR) is built specifically for this, pairing monitoring with an active response.
- Dark web visibility, so leaked credentials tied to your business get caught before they’re used against you, not after. Dark web monitoring covers this specific gap, though it’s worth understanding what it can and can’t catch on its own.
- A clear picture of where the gaps actually are. Most businesses don’t know which of the risks above apply to them until someone looks. A network and security risk assessment is usually the fastest way to find out.
These pieces work together rather than as substitutes for one another. Monitoring without response just tells you something bad happened. Response without monitoring means you’re relying on luck to notice in the first place.
Getting Started
The businesses that come out ahead in 2026 aren’t necessarily the ones spending the most on security. They’re the ones that know where their actual gaps are and close them before an attacker finds them first.
If you’re not sure where your business stands, DCG offers a free network and security risk assessment for Los Angeles businesses, which is a practical starting point before deciding what level of monitoring or protection makes sense for your size and industry.







































