The phony 60% cyberattack statistic refuses to die
Mark Twain famously wrote, “There are three kinds of lies: lies, damned lies and statistics.”
One cybersecurity statistic belongs in that category: “60% of small businesses close within six months of a cyberattack.”
This claim has circulated for more than 15 years, yet the organization often cited as its source has explicitly disavowed it. The statistic also fails a basic test of logic and common sense.
Worse, it is not buried on abandoned websites. In 2026, MSPs still use it on homepages, cybersecurity sales pages and newly published reports.
A false statistic that keeps spreading
The National Cyber Security Alliance (NCSA) has frequently been cited as the source. NCSA says it did not generate the statistic and cannot verify its original source. It removed the claim from its website and recommends that people stop using it.
At the 2026 BSides Las Vegas conference, security researcher Adrian Sanabria presented research he has conducted for nearly a decade. Over a 25-year period, he has documented 35 businesses that appear to have closed primarily because of a cybersecurity incident. His research is available at DestroyedByBreach.com.
His list is not necessarily exhaustive, but that’s not the point. If the 60% claim was true, examples of failed businesses should be easy to find. We should see thousands of businesses disappearing every year after cyberattacks.
Instead, that statistic keeps coming back like a zombie.
Even authoritative sources have repeated it. A 2015 speech by an SEC commissioner included a version of the claim. However, the footnote acknowledged that the congressional testimony it relied on provided no source and that it only suggested the number appeared to come from an NCSA infographic.
Recently, I saw a respected cybersecurity industry organization repeat the statistic in a video. I contacted them and explained the problem with the source, so they removed it
I will not name them because that is not the point. They did what responsible organizations should do. When they learned the information was not supportable, they corrected it.
How bad statistics gain credibility
A quick search still finds this claim across MSP websites and cybersecurity service pages. It also appears in blogs, sales materials and recently published cybersecurity reports.
I don’t believe these organizations are trying to mislead anyone. Most are repeating a claim they have seen many times. Repetition makes bad information look legitimate.
One website cites another, a marketing company puts the statistic into an MSP’s content, an AI tool repeats it and, eventually, nobody asks the most important question: Where did this number come from, and is it believable?
AI can make the problem worse. A polished answer can look authoritative even when the underlying source is weak or nonexistent. That is especially risky when MSPs use AI to create blogs, proposals, reports and sales content.
Why this matters to every MSP
You sell trust. Every statistic in a proposal, assessment report, presentation or sales conversation reflects your credibility.
If a prospect finds one unsupported statistic, what happens next? They may start questioning the rest of your claims. That can damage confidence in your recommendations, even when everything else is correct.
You do not need bad statistics to sell cybersecurity; the real risks are serious enough.
Use common sense, then verify
The first time I saw the 60% statistic, it did not pass my smell test. I knew many businesses that had suffered cyberattacks. None had closed because of them.
I called industry colleagues and asked about their experiences. Everyone had a client cyberattack story. Some incident-response specialists had helped dozens of businesses recover.
Then I asked how many of those businesses had closed because of the attack.
None.
Although that experience did not prove the statistic was false, it gave me a reason to investigate it. That distinction matters.
Your instincts can tell you when a claim deserves scrutiny. They are not a substitute for research, but they can give you a reason to investigate further.
Four steps to protect your credibility
- Search your own content. Check your website, blog and proposals. You should also check presentations, email campaigns and client reports. Search for “60%,” “six months” and similar versions of the claim. If you find it, remove it.
- Verify before you publish. Do not fall in love with a statistic because it has great marketing value. Find the original source and confirm what the research says. Cite the source when you use the number.
- Apply the smell test. If a statistic seems dramatically different from what you see in practice, investigate it. Do not treat experience as proof. Use it as a reason to verify the claim.
- Treat AI as an assistant, not a source. Ask AI tools for citations from authoritative sources. Then have a human review the sources and the final content. A confident answer is not the same as a verified answer.
The real risks are serious enough
Cyberattacks can destroy businesses.
The real risks include business interruption, recovery costs and lost data. They also include lawsuits, regulatory penalties and insurance disputes along with damaged customer relationships. Those risks are serious enough without exaggeration.
Here is one statistic I am comfortable publishing without a footnote: 100% of MSPs should stop using statistics they cannot verify.
Related: Kaseya’s SaaS report identifies critical vulnerabilities threatening SMBs
Power Your MSP Success with the Kaseya Community
Get fast answers, share product ideas, access exclusive resources, stay current on Kaseya product innovations, and connect with MSP peers.
2026 Kaseya State of the MSP Report

Get 2026 MSP insights from 1,000 plus providers and learn how to grow revenue, adapt to market pressure, and stay competitive.
Get More MSP Insights
Join 50,000+ MSP professionals receiving expert insights, best practices, and industry trends.






