24/7 SOC active — threats blocked today: 14,209

The Third Question

A short paper on how to read a security statistic — using the most famous one about your business

You have seen this number. It is on conference slides, in sales decks, in congressional testimony, and it has probably been used to sell you something:

"Sixty percent of small businesses close within six months of a cyberattack."

It is not true. More precisely, it has no source. It first appeared in a September 2011 business-news article whose author, asked five years later, could not name the expert who supplied it. It was widely attributed to a large security vendor, which denied producing it. In 2022 the national awareness organization most associated with it published a formal statement: the figure was not generated from its research, it could not verify the original source, it had removed all references, and it did not recommend the statistic’s continued use.

By then the number had already been cited in draft federal legislation and in testimony by senior federal officials. A figure with no origin had been laundered into policy by repetition alone.

The Myth

60%

Estimated closure rate cited in federal policy for over a decade with no primary source data.

The Evidence (2026)

~35 Companies

Total documented worldwide business closures resulting from a breach since 2001.

What is striking is what the evidence shows instead. Compiled case research presented at a security conference in 2026 identified roughly thirty-five companies worldwide that have gone out of business as a result of a breach since 2001 — most with fewer than ten employees, most closing within two weeks, undone by thin cash reserves rather than by the attack itself. Against that, a single recent year saw many thousands of confirmed breaches at smaller organizations. Nobody has produced a true closure rate — but thirty-five documented closures in twenty-five years, against thousands of breaches in one, is not the picture of an extinction event.

Most organizations of that size survive a breach. What they don’t escape is the cost, the downtime, and the customers who quietly stop coming.

We are not raising this to score a point. We are raising it because the habit that catches it is learnable, and it takes about ten seconds.

Most people ask two questions of a statistic: is it plausible, and who said it. Both fail here. Sixty percent is entirely plausible. And the source appeared to be a household name in security. Plausibility and authority are exactly the properties a bad number needs to travel.

The Breakthrough

The third question is the one that works.

"Who counted, and how would they have known?"

Apply it here and the number collapses immediately. To establish that sixty percent of breached small businesses close within six months, someone would need a defined population of breached small businesses, a way to observe closures, and a control group — because small businesses close at a meaningful rate anyway. That study would be expensive, slow, and famous. Its absence is not an oversight. It is the answer.

The same question dismantles a great deal of what circulates in this field. Claim-denial rates for cyber insurance, with no methodology behind them. Average recovery times drawn from vendor surveys of their own customers. Breach costs from a benchmark study of large enterprises, quoted at businesses a hundredth their size.

Ask it of us, too. When we cite a number, we tell you who counted and what they left out — including the three places in our own threat library where nobody counted at all.

Plausible is not true. Authoritative is not true. Counted is true.

Defending small & mid-sized businesses across the USA and U.S. territories. Eleven walls. One way through.

Industries

Healthcare

Legal

Manufacturing

Retail

Credit Unions

Gov Contractors

Blogs

Explainers

Frontiers

Citizen Awareness

Threat Reports

Newsletter

Company

Careers

Trust Center

Partners

Report an Incident

© 2026 way11.io · All rights reserved · Serving the USA & U.S. Territories

Privacy · Terms · Accessibility · Responsible Disclosure