For ten years I have helped companies grow, usually through two areas: marketing and putting internal sales processes in order. From that vantage point one thing stands out very clearly: companies understand better and better how to invest in growth, yet they still rarely think about how to protect it.
The campaign budgets are there. The CRM is there. The automations are there. The sales funnel is there. The sales team is working. The board watches the numbers, the cost of acquiring a customer, how effective the team is, how quickly deals close. And I agree, all of that matters. The trouble starts when a company builds that growth on a digital environment it does not actually protect.
That view was one of the reasons we founded PWNONE together. I believe cybersecurity is no longer a subject for the IT department alone. It concerns owners, boards and the leaders who answer for results. Sales, marketing and operations all run on data, on access, on mailboxes, ad accounts, systems and processes. Their security is therefore simply part of the company's financial health.
TL;DR - Key takeaways
- Cybersecurity does not start with technology. It starts with asking what drives the business
- The biggest mistake? Believing this only happens to large companies
- Most incidents do not begin like a film. They begin with access
- Data, not just systems, is now one of a company's most valuable assets
Cybersecurity does not start with technology. It starts with asking what drives the business
Many companies, once they finally start thinking about cybersecurity at all (most do not, because "who would want to attack us"), still treat it as something separate. As a technical layer sitting somewhere next to the business. I see it differently.
If a company wins customers through its website, ad campaigns, forms, sales activity, mailings and a CRM, then that is exactly where its real growth infrastructure sits, and it can be a tempting target.
Working with businesses every day and moving into the world of cybersecurity, I have come to see it this way: security should start with the question "what in our company has to keep running so that revenue does not stop?" Look at it like that and cybersecurity stops being an abstraction or an IT department indulgence. It becomes protection for very concrete things:
- the website that generates enquiries,
- the mailbox that carries sales conversations,
- the CRM that holds the pipeline,
- the ad account where the budget is working,
- the domain the brand stands on,
- the proposal documents that contain commercial terms,
- the access held by employees, partners and subcontractors.
A change of perspective
Seen this way, cyber is not a "just in case" cost. It protects investments the company is already making.
The biggest mistake? Believing this only happens to large companies
One of the most expensive illusions I still see is this: "we are not big enough for anyone to bother with us." It sounds logical right up until the first incident.
Verizon's data says something very different. The 2026 Data Breach Investigations Report analysed more than 31,000 security incidents, including over 22,000 confirmed breaches across 145 countries. And here is the number that matters most to anyone running a smaller company: in ransomware cases where the size of the organisation was known, around 96% of victims were SMEs.
For comparison, in the previous edition ransomware appeared in 88% of breaches involving SMEs and in 39% of breaches at large organisations. That is a different measure, so the figures are not directly comparable. The conclusion is much the same though: smaller companies are not a rounding error to attackers.
The report recorded 7,152 confirmed breaches at SMEs alone. In 55% of them a third party was involved: a supplier, an agency, an integrator, someone from outside. All of these cases had one thing in common: behind each stood an external, financially motivated actor.
The conclusion is fairly simple. Smaller companies are not "off the radar", they are usually just less prepared. The report itself puts it almost bluntly: what matters to attackers is not the victim's industry or turnover, but harvested credentials or an unpatched vulnerability on an edge device.
The lollipop effect
Attackers go where it is easiest to get in. A bit like the proverbial lollipop: it does not get taken from the richest child, but from the one it is easiest to snatch from.
Most incidents do not begin like a film. They begin with access
In business it is very easy to overrate the spectacular threats and underrate the mundane ones. From where I stand, the most dangerous attacks are often not the ones that sound most dramatic, but the ones that go after access and identity.
Verizon's 2026 report shows a shift that had been building for several years. Exploitation of vulnerabilities overtook stolen credentials for the first time as the most common opening move, accounting for 31% of breaches against 13% for credential abuse. The human element still appeared in 62% of breaches, so the problem has not moved purely into technology.
Two more figures show how fast this is moving. Breaches involving third parties rose by 60% and already accounted for 48% of all cases. Of the vulnerabilities listed in the CISA KEV catalogue, companies fully remediated only 26%, down from 38% a year earlier. The median time to full remediation grew from 32 to 43 days.
There is also one finding that shows the order of events nicely. In the data set analysed, 73% of ransomware victims had, during the preceding year, a trace linked to an infostealer or a credential leak. In half of those cases the trace appeared no later than 95 days before the attack itself. Ransomware is often not the beginning of the story. It is the end of it.
Taking over a salesperson's mailbox gives an attacker more than email. It gives them customer relationships, conversation history, proposals, attachments, agreed pricing and the ability to impersonate the company. Taking over an ad account means access to the budget, to campaign data and to a tool that directly drives lead generation and sales. Losing access to the CRM, or leaking data from the pipeline, brings the sales process to a halt quickly.
A fine is a real line in the accounts
In every one of these places we work with data, often sensitive customer data. GDPR allows fines of up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher. For lesser infringements the ceiling is EUR 10 million or 2% of turnover. In Poland fines rarely come close to those ceilings, but they do not have to in order to hurt.
Data, not just systems, is now one of a company's most valuable assets
Looking at how companies grow through the lens of marketing, sales and process, it becomes clearer and clearer that the real value today is not the tools themselves. The greatest value sits in the data that flows through those tools, accumulates in them, and on which the company builds its growth.
- Data about customers and how they behave.
- Purchase data and remarketing data.
- Mailing lists built up over years.
- The history of commercial relationships.
- Data about contractors and partners.
- Information about orders, margins, preferences, segments and customer retention.
Losing data is a business problem, not a technical one
Losing control of your data means more than losing access to files or a system. It means losing part of your operational, marketing and sales advantage.
An e-commerce example: the value is in the data, not in the ads being switched on
Say we have a growing online shop. The company invests in Meta Ads, Google Ads, SEO, email marketing and automation. From the outside everything looks fine: traffic is rising, sales are working, remarketing closes transactions, the customer base keeps growing.
What we are dealing with here is a first purchase (considerably more expensive in the ad platforms than any that follow) and customer lifetime value. Put a stick in the spokes of that data and you can kill the business, because profitability often rests on a few percentage points of margin, and a rise in CPC or CPS, or the loss of a list and a drop in LTV, can finish a company off.
The value of a business like this does not lie in the ads being switched on or the shop being up. It lies in the data the company has gathered and learned to use: customer lists with purchase history, remarketing segments, abandoned cart data, mailing lists, information about which traffic sources actually work, profiles of returning customers.
Together that is real business value. Not only operational, but financial. Because that data lets the company sell more effectively, acquire customers more cheaply, personalise its communication better and plan further growth more accurately. Losing the data, or losing access to it, is therefore above all a business problem.
The ransomware scenario is particularly damaging
One of the most painful scenarios for a company is a ransomware attack: data or systems are encrypted and the organisation loses access to them. If you want to understand the mechanism itself, we have described it separately: what ransomware is and how it works.
In a case like that, "something is not working" is only the beginning. In e-commerce it can mean no access to order data and the customer base, no way to run campaigns or remarketing, returns and complaints on hold, and part of the logistics process paralysed. In a services business it means losing access to proposals and contracts, a stalled sales pipeline and chaos in the paperwork.
From a business point of view, ransomware is dangerous mainly because it can cut a company off from its own know-how, relationships and operational resources for a time.
If you want to understand the mechanism itself, we have described it separately: what ransomware is and how it works.
And there is one more line in the accounts: the fine
This is what companies think about least, and it is the part of the cost that can arrive after the incident. A leak or loss of personal data does not automatically mean a fine from the Polish data protection authority. The regulator looks at what safeguards were in place beforehand, whether the company carried out a risk assessment, how it responded and whether it reported the breach correctly. But where there is visible negligence, another very concrete line can be added to the bill.
In Poland 2025 was a record year: the President of the data protection authority imposed over PLN 64 million in fines, and the three highest sanctions in the history of GDPR enforcement in Poland fell that year, led by Poczta Polska (PLN 27.1 million) and ING Bank Śląski (PLN 18.4 million). Those are easy examples to wave away though: "fine, but those are huge institutions."
So I would rather point to a different case, closer to the reality of an SME. A company selling security doors fell victim to ransomware. An employee had switched off the antivirus, the system was not being updated, there was no risk assessment and no regular security testing. The company lost access to data on customers and on current and former employees: national ID numbers, identity document numbers, bank account numbers, addresses. The regulator fined it PLN 353,589 (decision DKN.5131.1.2021, October 2024). The company appealed and lost.
And here is the most interesting part of that case. The processor was fined too, the firm providing IT services: PLN 9,822. For failing to tell the controller that the server lacked proper safeguards and that the system needed updating. If anyone believes that handing infrastructure to an external supplier means handing over responsibility, this is a good moment to revisit that belief. The responsibility falls on both sides.
"That does not apply to us" is one of the most expensive decisions a company can make
One of the riskiest assumptions I still meet in companies is the belief that cyber threats mainly concern large organisations, public institutions or "particularly sensitive" industries. In practice the problem starts far more simply: with no control over access, with dependence on a single supplier, with an untidy environment, or with a vulnerability nobody treated as a priority.
At one company I worked with shortly after the war broke out across our eastern border, the business accelerated sharply. The marketing and sales work was well organised. The problem appeared when, overnight, it turned out that neither the client nor we as the agency had real control over some of the tools, over access to the site and over the administrative accounts. It was not a classic spectacular attack, more a collision with the fact that the company had grown faster than it had put its technology and ownership arrangements in order.
At another organisation the threat was more conventional. We were running SEO for a client when an incident occurred in which some of the site's subpages were replaced. Content and links leading to external spam sites of an adult nature began appearing on the site. For the business, "fixing the site" does not close the matter. There is the risk of losing visibility in search, losing trust in the brand, and chaos across marketing activity.
Situations like these do not have to end in disaster to hurt. Sometimes a few days of chaos, a brief loss of control, activity on hold or an urgent scramble to tidy the environment is enough to show how much a company's growth now depends on things that many organisations, until recently, treated as technical plumbing.
What does an incident really cost?
IBM publishes its Cost of a Data Breach report every year. This year's edition came out on 29 July 2026 and puts the global average cost of a data breach at USD 4.99 million. That is a 12% year-on-year rise and the highest figure in the history of the study. The year before it was USD 4.44 million. In the United States the average is now around USD 11.5 million.
That figure covers far more than the work of the IT department: detecting the incident, escalation, downtime, lost revenue and reputational damage. IBM also reports that attacks assisted by artificial intelligence rose by 56%, most often deepfake impersonation and AI-assisted malware.
Not every company will bear a cost on that scale, of course. It is a global average, weighted heavily towards large organisations, so for a Polish SME it is a reference point rather than a forecast. A more practical number comes from Verizon: the median ransom paid was USD 139,875, while 69% of victims paid nothing at all. And the ransom is usually the smallest line in the bill anyway.
The best documented collapse of recent years is KNP Logistics, a British haulage firm with 158 years of history and a fleet of roughly 500 lorries. The Akira group got into the network by guessing one employee's password. No MFA, no exploit. The data was encrypted, the ransom was estimated at around GBP 5 million, and the company could neither pay it nor restore the data. The result: insolvency and around 700 people out of work. One thing most articles leave out is worth adding: the administrator said plainly that the company had been in difficulty before the attack, and that the incident made it impossible to raise urgent financing.
To me that is a much better argument than plain scaremongering. Ransomware is rarely the sole cause of a collapse. Far more often it turns a difficult quarter into a situation with no way out. Because the bill includes things companies do not usually put in a spreadsheet: the hours people spend fighting the fire instead of working, leads lost during the outage, delayed purchasing decisions, lost credibility and campaigns on hold.
Want to work out roughly how much your company could lose? We built a calculator for that: work out your risk.
AI is changing the economics of an attack
In its Digital Defense Report, Microsoft states that AI-generated phishing emails achieve a 54% click-through rate, against 12% for hand-written messages. That is 4.5 times more effective. Microsoft estimates that automation can raise the profitability of such a campaign as much as fiftyfold, and calls it the biggest change in phishing of the past year.
The same report contains one figure worth remembering: MFA, especially in its phishing-resistant form, blocks over 99% of access attempts using stolen credentials. The way attackers get into an organisation is changing too. Microsoft sums it up in a sentence: criminals are logging in rather than breaking in.
CrowdStrike, meanwhile, reported a 442% rise in vishing, that is phishing by phone, between the first and second halves of 2024. Breakout time, the interval between compromising the first system and moving to the next, is also telling. The average fell from 98 minutes in 2021 to 29 minutes in 2025. Adversaries increasingly get in through people, access and trust rather than through a noisy break-in. And they do it faster than anyone can get the IT team on the phone.
One decision with a high return
Phishing-resistant MFA blocks over 99% of access attempts using stolen credentials. It is one of the cheapest and most effective decisions a company can make.
And what does it look like in Poland? The scale nobody mentions in the boardroom
So far I have leaned mostly on global data, because that is where the best research is. But someone could reasonably say that is not our market. So here are the local numbers. CERT Polska, the team within NASK, published its 2025 report in April.
- 658,320 reports, 10% more than the year before,
- 260,783 registered security incidents, a 152% year-on-year increase,
- 97% of them were computer fraud, which rose by 158%,
- 78,391 phishing incidents, that is 30% of everything recorded,
- 244,341 domains on the warning list, roughly 670 new ones every day (one new malicious domain every two minutes),
- 1.88 million malicious text messages blocked, 27% more than the year before,
- 179 ransomware attacks, 21% more than in 2024, or one every other day on average.
This is not happening "somewhere in America"
Part of that rise comes from CERT getting better at spotting criminal infrastructure before it is used. But the direction is unambiguous, and 179 ransomware attacks is a count of confirmed cases, not of reports.
Business Email Compromise is closer to everyday business than it may seem
If I had to point to one area that owners and senior management should care about in particular, it would be company email and everything that follows from it.
The FBI publishes its IC3 report every year and the 2025 edition is merciless on this point. More than a million reports in total and USD 20.88 billion in losses, 26% more year on year. Business Email Compromise is the second most costly category in the whole report: USD 3.05 billion in losses. Divide total losses by the number of reports and you get an average of over USD 122,000 per case. On top of that, 86% of the money leaves by bank transfer or ACH, channels that are hard to reverse.
These are numbers worth reading twice, because they show that email is no longer just a communication tool. It is one of the main routes attackers use to get into a company, borrow its trust, manufacture urgency and trigger a financial or operational decision. Think how many companies send proposals, invoices, contract amendments, payment confirmations, requests to change a bank account number and purchasing decisions by email.
The real risk often only becomes visible once a company starts to grow
The smaller the company, the easier it sometimes is to work on trust, at speed, on common sense. The trouble is that growth usually increases not only revenue but also the surface area of risk. More people arrive, more access is granted, more tools, more external partners and more places where someone holds permissions that nobody quite remembers.
And then something starts that I see very often from a process point of view: the company moves to a higher level of scale but still manages access, responsibility and control the way it did at an earlier stage. Someone once set up the ad account. Someone once had access to the domain. Someone once wired up the forms. Someone once integrated the CRM. A few years on, the organisation has a working ecosystem but no certainty about who can reach what.
I am not an advocate of communication built purely on fear. In business a mature approach works far better: I understand the risk, I know what is critical to me, and I put the environment in order before the problem forces me to. So a sensible conversation about cybersecurity should not start with worst-case scenarios, but with a few simple management questions.
What is worth protecting in a company that invests in growth
From where I stand, any company that is growing should start by putting a handful of basic areas in order. There is no need to launch a huge security programme straight away. It is often enough to start with the foundations.
- Mailboxes and access to communication. That is where both the customer relationship and the real risk of abuse concentrate.
- The CRM and the contact database. That is the heart of the sales process.
- The domain, the website and the forms. Without them many companies lose their main entry point for enquiries.
- Ad and analytics accounts. If marketing runs on data and budgets, the place where they live needs protecting.
- Access held by employees, partners and subcontractors. Growth very often increases the mess around access and procedure.
- Commercial documents, proposals and shared resources. That is where information of real business and negotiating value tends to sit.
Cybersecurity is increasingly a condition of scaling responsibly
Most companies understand the idea of investing perfectly well. Money goes into lead generation, branding, sales, people, systems, automation and growth. Far less attention goes to protecting that foundation. Companies build a website but do not think enough about how resilient it is. They launch campaigns but do not keep control over access. They grow the CRM but do not treat it as a critical asset.
And then a company can end up brilliant at accelerating but not good enough at protecting what it has just accelerated. Looking at this from the business side, I have no doubt: cybersecurity is less and less an optional extra and more and more one of the conditions of growing up well.
And if that is so, the question should not be "does cybersecurity matter for us too?" The question should be "which parts of our growth are now critical enough that we cannot afford to leave them unattended?" To me cybersecurity is simply part of running a business responsibly, not solely a technology topic.
An honest audit. Fifteen questions worth answering truthfully
I will finish with a list of the failings I see most often in companies. Not to frighten anyone, but so that in five minutes you can see where you stand. If you answer "yes" even once, write to us. We will check free of charge whether your company's data has already turned up in a known breach. And without dressing it up: yes, for us that is also a first step towards a conversation about working together. But you get the report itself with no obligation and no catch.
- We do not know exactly who has access to key tools and systems.
- Former employees, agencies or freelancers may still have access.
- Key accounts are registered to personal email addresses or to individuals.
- Some important systems have no MFA or 2FA.
- Passwords are shared or stored in a disorganised way.
- We have no clear procedure for a compromised mailbox, website or account.
- We are not confident the backup works and can be restored quickly.
- The website, CMS, plugins or tools are not updated regularly.
- We do not know which data is critical to the running of the business.
- Customer, remarketing, mailing and contractor data is not treated as a business asset.
- The team receives no training on phishing and basic threats.
- Nobody holds a full map of the tools, integrations and dependencies.
- Too many people have administrative access.
- Security has no single owner in the organisation.
- We keep putting security off because "nothing has happened so far".
"No" to all of them?
Excellent, feel free to scroll on. If even one "yes" appeared, this is a good moment to get in touch.
Summary
A company can pour enormous resources into growth. But if it does not protect the environment that growth runs on, it is in a sense leaving that growth uncovered. Cybersecurity is no longer a subject for the IT department alone, it is part of running a business responsibly. This is not about every company falling victim to a spectacular attack tomorrow. It is that almost every company now runs on digital assets that sales, marketing, customer trust and operational liquidity all depend on.
Bibliography
Verizon's annual report analysing tens of thousands of security incidents and breaches worldwide.
The official summary of the main findings of the DBIR 2026 report.
A report estimating the global average cost of a data breach and the effect of AI on incident costs.
Microsoft's report on the threat landscape, the effectiveness of AI-assisted phishing and the role of MFA.
The FBI report on internet crime, including losses from Business Email Compromise.
The CERT Polska report summarising the reports and security incidents handled in 2025.
The decision imposing fines on both the controller and the processor after a ransomware incident.
Mandiant's report on incident response trends, including the growing role of interactive vishing.
An account of the insolvency of British haulier KNP Logistics after a ransomware attack by the Akira group.

