If you run a small business, you probably insure the building, the inventory, and the vehicles. Someone sat down at some point and worked out the odds of a fire, a theft, a collision — and priced the risk accordingly. Almost nobody does that same exercise for the network the business now runs on. This is that exercise. No product, no policy pitch — just the numbers a risk assessor would actually hand you.
What a Zero-Day Attack Actually Is
Every piece of software your business runs — your accounting platform, your email server, the firewall itself — has flaws nobody has found yet. A "zero-day" is one of those flaws the moment a criminal finds and uses it before the vendor knows it exists. The name refers to how much time the vendor has had to fix it: zero days.
That timing is what makes it different from an ordinary attack. There's no patch to install, because no patch exists yet. There's no known signature for security software to check against, because nobody has catalogued this attack before. The door isn't just unlocked — nobody has drawn a blueprint of it yet.
Why Antivirus and a Firewall Don't Cover This
Traditional antivirus works by comparison: it keeps a list of known bad files and known bad patterns, and it flags anything that matches. A firewall works by rules: it lets traffic through or blocks it based on ports, addresses, and known-bad sources. Both are useful. Neither one is built to catch something that has never been seen before, because there is nothing yet to compare it to and no rule yet written against it.
A specific example, because it's more useful than a vague one: the standard antivirus most small businesses run — Bitdefender, Norton, Windows Defender, whichever brand — is built to check files against a list of known threats. That's genuinely good at what it does. It is not built to notice an AI agent being talked into misusing its own permissions, or a brand-new exploit chained together against your VPN appliance last week. Tellingly, even Bitdefender doesn't sell that base antivirus as the answer to this problem — its GravityZone Business Security line is a separate, more expensive product built specifically to add behavioral monitoring. The vendors themselves treat "antivirus" and "the thing that catches unknown attacks" as two different products, sold at two different price points.
This isn't a fringe problem. Google's Threat Intelligence Group tracked 90 zero-day vulnerabilities actively exploited in the wild in 2025 — up from 78 the year before, and within the 60–100 range the group now considers the stable, ongoing baseline rather than a spike.[^1] Nearly half of those, 43 of the 90, targeted enterprise technology — firewalls, VPNs, and business software — the highest share Google has ever recorded, and a category that includes the exact equipment a small business is likely to have sitting on its network right now.[^1]
Verizon's 2025 Data Breach Investigations Report found exploitation of software vulnerabilities as an initial way into a business rose 34% year over year, with attackers increasingly aiming at perimeter devices and VPNs specifically — the hardware many businesses assume their "firewall" already handles.[^2]
Why This Is Accelerating Right Now
Zero-days used to require real technical skill to find and weaponize. That barrier is falling, because the criminals no longer have to do all the work themselves.
Case File: Russian-Speaking Hackers Used an AI Coding Assistant to Breach Seven Companies
Reuters reported this week that a Russian-speaking ransomware group, tracked as Aur0ra, used SpaceX's AI coding tool Cursor to help break into a Belgian chemical company and at least six other firms earlier this year.[^3] Researchers at the cybersecurity firm Gambit Security discovered the operation after finding a server the group had accidentally left exposed online, which let them review 28 chat conversations between the hackers and Cursor's AI agent.[^3]
According to Gambit's report, the hackers didn't break the AI's guardrails with clever code — they talked their way past them. They told the AI agent they were cybersecurity professionals running an authorized penetration test, and the agent, believing it was helping with legitimate simulated testing, carried out hundreds of genuinely malicious actions on its behalf, including credential theft and account takeover.[^3]
Gambit's chief strategy officer, Curtis Simpson, described what this signals for every AI vendor building these tools: "this is going to be a cat-and-mouse game."[^3] The point for a small business isn't which tool was involved. It's that the skill required to run a sophisticated intrusion just dropped substantially, because the AI can now supply the skill the attacker doesn't have.
IBM's 2025 Cost of a Data Breach Report found attackers already used AI to power phishing or deepfakes in 16% of breaches, and that "shadow AI" — employees or attackers using ungoverned AI tools inside a company's systems — was a factor in 20% of breaches, adding an average of $670,000 to the cost of the ones it touched.[^4] That's the direction of travel: more zero-days found, less skill required to use them, and AI tools sitting on both sides of the fight.
What This Costs, In Numbers
This is the part an insurance agent would actually show you before talking about coverage: what the loss looks like if the event happens. These are the current, sourced figures — not projections.
| Schedule of Loss | 2025 Data |
|---|---|
| Average global cost of a data breach | $4.44M |
| Average cost of a breach at a U.S. company — a record high | $10.22M |
| Breach cost at organizations under 500 employees (IBM's most recent size-specific breakdown) | $3.31M |
| Share of small-business breaches that involved ransomware, vs. 39% at large enterprises | 88% |
| Median ransom actually paid (down from $150,000 the year prior) | $115,000 |
| Average time to identify and contain a breach — a nine-year low, still the better part of a year | 241 days |
| Zero-day vulnerabilities exploited in the wild in 2025 | 90 |
Sources: IBM Cost of a Data Breach Report 2025; Verizon 2025 Data Breach Investigations Report; Google Threat Intelligence Group, "2025 Zero-Days in Review."
Read the ransomware line again. Small businesses aren't just as exposed as large enterprises — they're more than twice as likely to have ransomware involved once a breach happens. Attackers aren't ignoring small businesses because they're small. They're targeting them because they're the softer entry point.
The Same Math You Already Use for Insurance
You don't insure your building because you expect a fire. You insure it because a small, predictable monthly cost is a rational trade against a large, unpredictable one. Endpoint Detection and Response (EDR) and managed threat hunting work on the identical logic, and it's worth actually putting the two numbers next to each other instead of treating "cybersecurity spending" as an abstraction.
EDR watches what's actually happening on a device — process behavior, unusual network calls, privilege changes — instead of just checking files against a known-bad list. Managed threat hunting adds a human team that actively looks for the things automated tools miss and can act in real time when something is found. Together, this is the layer that's actually positioned to catch a zero-day, because it doesn't need to have seen the attack before.
| Premium vs. Claim | 2026 Market Data |
|---|---|
| Typical self-managed EDR software, per endpoint / month | $3 – $15 |
| Managed EDR/MDR with 24/7 threat hunting, per endpoint / month | $8 – $45 |
| Annual cost of full MDR for a 50-endpoint business (roughly what a single dedicated security hire would cost in salary alone) | $15,000 – $30,000 |
| Breach cost at a company under 500 employees, if the attack succeeds | $3.31M |
| Combined top-10 U.S. data breach class-action settlements, 2024 — up 15% from 2023, which was itself up 50% from 2022 | $593.2M |
| Federal data-breach class actions filed in a single year, 2023 — roughly 30% more than the year before | 1,800 |
Sources: Unió Digital / Bellator Cyber MDR & EDR pricing indexes (2026); IBM Cost of a Data Breach Report 2025; Leader's Edge Magazine, citing Duane Morris and the UC Berkeley Center for Law & Technology.
That last two rows matter separately from the breach cost itself. A breach isn't just an operational loss — it's the event that opens a business up to a negligence claim. The standard legal argument in these suits is straightforward: the company held customer data and didn't take reasonable, industry-standard steps to protect it. A business that can show it had behavioral detection and active threat hunting in place is in a fundamentally different legal position than one that can only show it had the antivirus that came with its computers. That difference doesn't just reduce the odds of a breach — it materially changes the odds of what happens to the business afterward if one occurs anyway.
Run the comparison the way an underwriter would: a few dollars per device each month, against a claim that averages in the millions and carries a real chance of a lawsuit attached to it. That's not a marketing framing. It's the same premium-versus-claim math you already accept for the building and the fleet vehicles — applied to the part of the business that's actually most exposed right now.
In-House, Outsourced, or AI-Managed: Three Ways to Get There
Knowing you need continuous threat detection is one thing. Deciding how to actually staff it is a separate, and often bigger, decision — and the cost gap between the three routes is wide enough that it changes the answer for most small businesses on its own.
Building it in-house means hiring your own security analysts to watch for threats. The catch is that "24/7 coverage" isn't a job for one person — it's three shifts, seven days a week, which industry staffing models put at 5–6 full-time analysts just to keep a single seat covered around the clock, before you've added a manager or any tooling.[^6] At a fully loaded cost of roughly $95,000–$125,000 per analyst once benefits and overhead are included, that's $475,000–$750,000 a year for tier-1 monitoring alone — a number that puts a real in-house SOC out of reach for the large majority of small businesses.[^6]
Outsourcing to a traditional MSSP or MDR provider hands that staffing problem to someone else's human team. For a small business, this typically runs $2,000–$7,000 a month (roughly $24,000–$84,000 a year), or $25–$75 per endpoint per month if priced by device count.[^7] You get professional, human-staffed monitoring without carrying six salaries — the tradeoff is that you're one client among many, and response speed depends on that provider's queue.
AI-managed threat detection is the newer third option, and it's the direct product of the same shift this article opened with: AI can now do meaningful security work at machine speed. Platforms in this category — AIVault among them — use AI models trained on attacker behavior patterns to watch endpoint and network activity continuously, flag the anomalies a signature-based tool would miss, and triage alerts in real time, without needing a human being awake at 3 a.m. to notice first. It's worth sitting with the irony: the Cursor case earlier in this piece showed what happens when that same category of AI capability is pointed at a business by an attacker. Pointed the other way, defensively, it's what's starting to make continuous, behavior-based monitoring affordable for businesses that could never have staffed a human SOC around the clock. Pricing varies by provider and typically scales per endpoint, but the category as a whole is generally positioned below the cost of a fully staffed traditional MDR contract, precisely because it isn't paying six human salaries to achieve the same round-the-clock coverage.
None of the three is universally "right" — a business with strict compliance requirements may need a human-staffed provider regardless of cost, and a larger business may genuinely be at the scale where in-house makes sense. But for the small business sitting between "just antivirus" and "a security team we can't afford to hire," AI-managed monitoring is the option that didn't really exist a few years ago, and it's worth putting on the list next to the other two before deciding.
An underwriter doesn't quote a policy on vibes — they ask specific questions and price the answer. These are the equivalent questions for zero-day exposure. You don't need a perfect score. You need an honest one.
- Detection method: does your current security tool only match against known threats (signature-based), or does it also watch for unusual behavior that could flag something new?
- Patch cadence: when a vendor issues an emergency security patch, how many days typically pass before it's actually installed across your systems?
- Edge devices: are your firewall, VPN, and remote-access hardware running current firmware, and do you know who's responsible for checking?
- AI tool governance: do employees use AI coding, writing, or automation tools with access to company systems or data, and does anyone review what those tools are authorized to do?
- Response time: if a breach happened today, how long before someone at your business would actually notice?
- Backup isolation: are your backups stored somewhere a ransomware attack on your main network couldn't also reach and encrypt?
If more than one or two of those made you pause, that pause is the accurate read on your exposure — not an exaggerated one. The gap between what antivirus and a firewall cover and what a zero-day attack requires isn't a marketing framing. It's the literal difference between matching known patterns and catching something nobody has catalogued yet.
What to Do With This
None of this is a reason to panic, and it isn't an argument for any one vendor or brand. But the category matters: if your current setup is standard antivirus and a firewall and nothing else, you are covered for yesterday's threats and exposed on exactly the one that's growing fastest. Moving to behavioral EDR with active threat hunting is the direct fix for that specific gap — it's the layer built to catch something it has never seen before, which is the entire definition of a zero-day. Pair it with a written incident response plan; IBM's data shows businesses with a tested plan saved an average of $2.66 million per breach compared to those without one.[^5]
The point of this assessment was never to make you afraid. It was to make sure the number in your head — the cost of doing nothing versus the cost of a monthly premium — is the real one, not the comfortable one.
This article summarizes publicly reported research and news coverage for general education. It is not cybersecurity, legal, or insurance advice, and figures are averages that will not match every business's specific exposure.
Sources
[^1]: Google Cloud Blog / Google Threat Intelligence Group, "Look What You Made Us Patch: 2025 Zero-Days in Review," and reporting by BleepingComputer, SecurityWeek, and The Record (March 2026). [^2]: Verizon, "2025 Data Breach Investigations Report" (April 2025); coverage by Infosecurity Magazine and About Verizon. [^3]: Raphael Satter, Reuters, "Russian-speaking cybercriminals used SpaceX's Cursor AI tool to hack seven companies" (August 27, 2026), based on research from Gambit Security and CloudSek. [^4]: IBM, "Cost of a Data Breach Report 2025" (July 2025). [^5]: IBM, "Cost of a Data Breach Report 2025" — incident response plan cost-savings finding. [^6]: SOC Cost Calculator 2026, "In-House vs MSSP vs Hybrid" (securityoperationscost.com, 2026); Glassdoor, Salary.com, and Coursera 2026 cybersecurity salary guides — tier-1 SOC analyst compensation and 24/7 staffing requirements. [^7]: MSSPProviders.io, "MSSP Pricing 2026" and "Best MSSPs for Small Business: A 2026 Guide"; Defend My Business, "Managed Security Services for Small Business in 2026."