What the 2026 Threat Reports Mean for Iowa Businesses
October 6, 2026
Iowa had the fewest cybercrime complaints per capita of any state in 2025, according to the FBI. It would be nice to read that as good news. It is more likely a sign of how many incidents never get reported.
The national picture is harder to wave off. Verizon's 2026 Data Breach Investigations Report found that 96% of ransomware victims were small and mid-sized businesses. Headlines go to the Fortune 500, but the companies actually getting hit look a lot more like a Cedar Rapids manufacturer, a Des Moines accounting firm, or a family-owned ag supplier.
Every year the big security vendors and the FBI publish their data on the previous year's attacks. We read the 2026 editions and pulled out what matters for Iowa businesses. The short version fits on one page, and you can download the Iowa SMB Threat Brief (PDF). The longer version is below.
The breach you don't see coming
Sophos surveyed 2,158 organizations that were hit by ransomware. Among the smallest group they track, companies with 100 to 250 employees, only 34% stopped the attack before their data was encrypted. The largest organizations surveyed did better, at 46%.
When asked why the attack succeeded, 43% of those smaller organizations said they didn't have enough people or capacity. Across all victims, the second most common answer was a security gap they hadn't known about.
Put those answers together and a familiar picture emerges. The typical victim isn't facing a nation-state operation or a movie-style hack. It is an organization with a weakness it didn't know about, and by the time anyone noticed, an attacker already had.
Three ways attackers get in
The 2026 reports disagree on which entry point ranks first, but they do agree on the same three.
Unpatched internet-facing systems. Verizon found that exploiting a software flaw started 31% of breaches, overtaking stolen passwords for the first time. Many of the targets were devices that sit at the edge of a network, including firewalls, VPNs, and file-transfer tools. SonicWall, CrushFTP, Veeam, and Gladinet products were all behind major exploitation waves in 2025. Verizon also found that organizations fully fixed only 26% of the critical vulnerabilities flagged by CISA, the federal cybersecurity agency.
Phishing and malicious email. In the Sophos survey, half of all ransomware attacks started in someone's inbox. Microsoft remained the most impersonated brand, used in 22% of brand phishing in late 2025 according to Check Point. A fake "your password expires today" email still works.
Stolen credentials. Sophos found that 79% of ransomware attacks started with identity, either stealing logins or using ones already stolen. Here is the uncomfortable part. Multi-factor authentication (MFA) was turned on in some form at 97% of the organizations where stolen credentials started the attack. Sophos's read is that MFA often didn't cover every system, which left gaps, and that attackers keep finding ways around it. MFA is still essential. It just isn't a finish line.
Business email compromise and the wire you can't get back
Business email compromise (BEC) cost US victims $3.05 billion in 2025, according to the FBI's Internet Crime Complaint Center. That averages out to about $123,000 per complaint, and 86% of the money moved by wire transfer or ACH.
The common Iowa version goes like this. A vendor you have paid for years gets their email account taken over. The attacker watches the conversation for a few weeks, then sends a polite note saying the vendor's bank details have changed. The invoice looks right, the amount is right, and the email thread is real. The payment goes out and never reaches the vendor.
BEC hits hardest at small finance teams where one person can change payment details and release a wire. The fix is mostly process, not technology.
Iowans filed 5,436 complaints with the FBI in 2025 and reported $95.5 million in losses. Those are only the losses people chose to report, so the real number is likely higher.
Hours to do harm, months to notice
These two numbers should change how you think about security.
According to Huntress, the average time from an attacker's first foothold to deploying ransomware was 20 hours in 2025. That is up from 17 hours, because attackers now spend extra time stealing data before they encrypt anything.
IBM's 2026 Cost of a Data Breach report found that the average time to identify and contain a breach was 247 days. That is up from 241 days and the first increase in five years.
Twenty hours to do the damage and eight months to notice. A clean firewall and a current patch list are necessary. They are not sufficient on their own, because something will eventually get through, and what matters then is how fast you see it.
Five things to do this quarter
Most of these cost more time than money.
- Patch the edge first. Make a list of everything that faces the internet, including firewalls, VPNs, remote access tools, and file-sharing apps. Turn on automatic updates where you can, and check vendor advisories monthly for the rest.
- Verify every payment change by phone. Any change to bank details gets a call to a number you already have on file, never one from the email. Require a second person to approve wires above a set amount.
- Close the MFA gaps. Check that MFA covers every system that accepts a login, including email, VPN, remote access tools, and admin accounts, not just the ones you set up first. For administrators and finance staff, prefer phishing-resistant options such as passkeys or hardware keys.
- Make sure someone is watching. If no one reviews login alerts or security logs today, decide who will, or bring in a managed detection service.
- Find out what you can't see. One of the most common reasons attacks succeed is a gap the business didn't know about. An outside look is the fastest way to find it.
Get the one-page brief
We put the key numbers on a single page you can share with your leadership team, your board, or your IT provider. Download the Iowa SMB Threat Brief (PDF).
If you want to know where your own gaps are, a vulnerability assessment shows what attackers can reach from the outside. A security posture review looks at the people and process side, including the payment controls and monitoring covered above. A documented security program can also help you qualify for legal protection under Iowa's cybersecurity safe harbor law.
Sources
- Verizon, 2026 Data Breach Investigations Report
- Sophos, The State of Ransomware 2026
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report
- Huntress, 2026 Cyber Threat Report
- IBM, Cost of a Data Breach Report 2026
- Check Point Research, Q4 2025 Brand Phishing Report