5 Cybersecurity Threats Every Utah Small Business Should Know in 2026

5 Cybersecurity Threats Every Utah Small Business Should Know in 2026

Quick Summary: Most cybersecurity incidents at Utah small businesses trace back to one of five causes: phishing and business email compromise, ransomware, software that is unpatched or past its support date (Windows 10 is this year's example), weak or reused passwords without multi-factor authentication, and risk introduced through a vendor. None of these require a large company to be worth targeting. This guide explains each threat in plain terms and links to the specific WITS guides that cover incident response and compliance in depth, instead of repeating them here.

A threat list built around a few years of headlines is not much use to a business trying to decide what to fix first. The five categories below are the ones that CISA, the FBI and independent breach researchers keep coming back to year after year, because they explain how most incidents actually start, not because they are the most dramatic. This is an awareness and prevention guide. If you are dealing with an active ransomware incident right now, go straight to our ransomware response guide instead of reading further here.

Phishing and business email compromise

Phishing is still one of the easiest ways into a small business because it does not need a software flaw. It needs one employee to click a link, open an attachment, or approve a payment. Business email compromise (BEC) is the costliest version of it: the FBI's Internet Crime Complaint Center (IC3) describes BEC as a scam that uses a compromised or spoofed email account, set up through social engineering or a computer intrusion, to talk a business into sending a transfer of funds it would not otherwise send.

In practice this shows up as an invoice from a "vendor" with new bank details, a message that looks like it came from the owner asking for a same-day wire, or a payroll change request that appears to come from an employee. IC3's own prevention advice does not require new software. Confirm any request to change payment or account details through a second channel, such as a phone call to a number you already had on file, not by replying to the email. Check sender addresses carefully, since a spoofed domain often differs by only one character. Review financial accounts on a regular schedule for transactions nobody authorized.

Ransomware

Ransomware encrypts a business's files and demands payment to unlock them, and increasingly the attacker also copies the data first and threatens to publish it. CISA's #StopRansomware Guide lists the same prevention measures every time it is updated: phishing-resistant multi-factor authentication, especially on email, VPNs and anything that reaches critical systems; patching internet-facing servers first, with regular vulnerability scanning; offline, encrypted backups that are actually tested, not just taken; staff training on spotting and reporting suspicious messages; and limiting who holds administrator access, with those accounts audited on a schedule.

This article will not repeat the response steps here, since it is about prevention rather than what to do mid-incident. If ransomware ever reaches your network, our ransomware response guide walks through isolating affected systems, who to call in what order, the decision to pay, the recovery order, and Utah's breach notification law.

Unpatched and end-of-life software

A patch closes a hole attackers already know about, so software that stops receiving patches is a hole that stays open indefinitely. The clearest example for 2026 is Windows 10. Microsoft's support ended on October 14, 2025, and from that date Microsoft no longer provides security updates, technical support, or feature updates for that version.

A business still running Windows 10 has two real paths, not one. Microsoft's Extended Security Updates (ESU) program lets a commercial or educational organization keep receiving critical and important security updates for up to three years past end of support. Pricing starts at $61 per device for the first year and doubles each following year, and ESU does not include new features or general technical support. The other path is upgrading eligible machines to Windows 11 or replacing hardware that cannot run it. Either option beats doing nothing: an unpatched, unsupported PC sitting on the same network as everything else is a door that stops getting locked.

Windows 10 is the version making headlines this year, but the same logic applies to any end-of-life server operating system, a firewall no longer receiving firmware updates, or line-of-business software the vendor stopped maintaining. An IT provider that tracks every device in your environment on a schedule can flag these before the support window closes, not after a breach.

Weak or reused credentials, and no MFA

Passwords remain a weak point because people reuse them across services, and because a password by itself can be guessed, phished, or bought cheaply from a previous, unrelated breach. CISA is direct on this point: a password alone is not the protection most people assume, and multi-factor authentication (MFA), meaning a second proof of identity beyond the password, makes an account meaningfully harder to break into even when the password itself is compromised. CISA's strongest recommendation is phishing-resistant MFA, built on the FIDO/WebAuthn standard, because it blocks the classic trick of a fake login page harvesting a one-time code along with the password.

Verizon's 2026 Data Breach Investigations Report adds a detail worth noting for anyone who assumes this problem is already solved: exploiting a known software vulnerability has now overtaken stolen credentials as the single most common way attackers get their first foothold, accounting for roughly 31 percent of breaches, and phishing attempts sent to a mobile device get clicked at a noticeably higher rate than the same attempt sent by email. In plain terms, credential attacks have not gone away. They have simply stopped being the only thing worth worrying about. The practical response covers both: turn on MFA everywhere it is offered, retire shared logins, and patch on a set schedule instead of only after something breaks.

Third-party and vendor risk

A small business can lock its own systems down carefully and still get breached through someone else's, an accountant, a software vendor, a managed IT provider, or any other party with access to its network or data. CISA's guidance on this is direct: attackers deliberately look for weak points outside an organization's own control, including through third-party vendors, because it is often easier than attacking the target head on.

Before signing with a vendor that will touch your systems or data, CISA suggests asking a short list of questions up front: who is responsible for security once work is outsourced to that vendor, what the vendor can show you about its own security controls before a contract is signed, and what level of network or system access the vendor genuinely needs versus what it is asking for. A vendor that cannot answer these clearly is itself part of the risk.

This is also where vendor risk and compliance overlap. Frameworks like HIPAA, PCI DSS, and SOC 2 generally expect a business to be able to show it reviewed the vendors that touch regulated data, not only its own internal systems. Our IT compliance hub covers what each of those frameworks actually requires in practice.

Five questions worth asking your IT provider before year-end

  • Phishing and BEC. Do we have a written process for verifying any request to change payment or bank details, and does everyone who handles money know it?
  • Ransomware. Are our backups offline, encrypted, and actually tested with a real restore, not just scheduled?
  • Unpatched software. Do we know which of our PCs, servers, and network devices are already past their vendor's support date, and which are approaching it?
  • Credentials and MFA. Is MFA turned on for email, VPN, and anything that reaches financial or patient data, with no exceptions carved out for convenience?
  • Vendors. Can we name every vendor with access to our network or our data, and do we know what each one can actually reach?

Where WITS fits

WITS IT Services is based in Lehi, Utah, and its engineers hold Cisco CCIE Enterprise Infrastructure and Kali Linux Professional certifications. Of the four WITS managed IT tiers, WITS Sentinel covers monitoring and patch management, WITS Command adds unlimited business-hours remote support with on-site coverage included, and WITS Inner Circle layers on CCIE-designed security architecture, annual penetration testing, security awareness training, and assistance with HIPAA, NIST 800-171, PCI DSS, and SOC 2. Exactly which plan covers phishing simulation training, an MFA rollout, or a specific compliance framework can vary by client, so ask directly which of the five threats above a given plan actually addresses before you sign anything.

No plan and no provider, WITS included, can promise your business will never be targeted. What a good plan can do is close the doors described above before someone tries them.

Next steps

A phone or video consultation with WITS is free for the first 30 minutes, then a flat fee applies. An on-site visit, including a formal risk assessment, is never free and starts at $200 on weekdays for a business assessment. Start at Get Started or call 385-313-9898. If you are already in the middle of a ransomware incident, use the ransomware response guide first.

Other Blogs

How to Choose a Business IT Provider in Utah (Without Getting Burned)

How to Choose a Business IT Provider in Utah (Without Getting Burned)

A Utah buyer's checklist for choosing a managed IT provider: signs you have outgrown break-fix IT, pricing, and...

Learn More
How to Fix WiFi Dead Zones in Your Utah Home (2026 Guide)

How to Fix WiFi Dead Zones in Your Utah Home (2026 Guide)

The real causes of WiFi dead zones in Utah homes, from stucco walls to basements, and how mesh, wired access points,...

Learn More
How Much Does Managed IT Cost for a Small Business in Utah?

How Much Does Managed IT Cost for a Small Business in Utah?

WITS publishes its per-user managed IT plans at $85 and $125 per month. See what each includes, costs for 5, 10 and 25...

Learn More