The confidence gap: Why cybersecurity spend isn't the same as cybersecurity confidence
Most small and mid-sized businesses we talk to aren’t ignoring cyber security. They’ve invested in a firewall. They’ve rolled out antivirus. They’ve got a backup solution running in the background. There are policies, processes and people in place to help keep the business safe. If you asked them outright, “Are you covered?” most would say yes, without much hesitation.
But is that confidence supported by data? That might be one of the common cybersecurity oversights right now: the gap between believing your organisation is protected and actually knowing it.
The numbers behind the feeling
This is not just cybersecurity vendors or partners scaremongering. The data actually tells the same story.
A 2026 survey of small business leaders by the National Cybersecurity Alliance put a figure to this gap. 86.3% of leaders rated their confidence in managing cyber risk as medium to very high, but 56.1% of the same businesses had a confirmed or suspected incident, and another 5.6% were unsure whether a breach had even occurred.
That’s the confidence gap in one dataset – high self-assurance, sitting right alongside genuine uncertainty about what’s actually happening inside the business.
Buying the tool isn’t the same as testing it
Here’s where it gets more specific around individual security controls. The same survey found that 88.4% of small businesses have backups in place, but only 61.4% have ever actually tested them.
The pattern repeats with access control: 86.8% have implemented multi-factor authentication, but only 51.1% have it across every key business account. The rest leave exactly the kind of inconsistent coverage that attackers are built to find.
Again, the issue isn’t that these businesses haven’t invested in security. They have.
The issue is that implementation and assurance aren’t the same thing.
You may have the controls in place, but they may be partially implemented, incomplete, or outdated, creating a false sense of security rather than removing the risk they were meant to cover.
Across multiple studies, one thing is clear – cybersecurity overconfidence. It’s what happens when buying a tool is equated with assuming it’s working as intended.
Why the gap opens up in the first place
This is a common theme among many businesses simply because they are not standing still and they change over time. Roll out MFA today, and it’s genuinely true that every key account is protected today.
Six months later, you’ve had two new starters, a contractor has joined, someone has changed roles, and a new SaaS platform has been introduced.
It just kept moving, the way growing businesses do, while the confidence that was accurate on day one stayed frozen at day one.
The same thing happens with other controls. Each one was a genuine, correct decision at the moment it was made. But over time, it no longer held true, and nobody built a consistent way to check it.
How to replace confidence with evidence
Closing this gap doesn’t usually require new spend. It requires a different question. Instead of asking “do we have this in place,” ask “when did we last confirm it still works, exactly the way we think it does”:
- Backups. Don’t just check that backups are running. Pick a file or system that matters and test how quickly you can recover it, whether the data is intact and whether someone knows what to do if the restore fails.
- MFA. Don’t just check that MFA has been rolled out. Pick a few business-critical tools and check whether it’s enforced on them, not just the ones you remember switching on.
- Access. Don’t just rely on the fact that there’s an offboarding process. Pull your last three leavers and confirm that their accounts are actually gone, not just disabled.
- Monitoring. Don’t just check that alerts are being generated. Ask who actually reads them, and what happens if one lands at 6 pm on a Friday.
What they replace is a guess with a fact, and that’s really the entire difference between confidence and evidence.
Testing them once is a good start. Making it stick is what actually closes the gap for good, and that really comes down to three things.
Give every control a review date rather than a one-time “done” (whether that’s quarterly or another frequency that makes sense for your business). Give someone clear, named ownership of checking it. And keep a simple log of what was checked, when, and what you found. That log is your evidence – the thing you actually reach for when a customer, insurer or regulator asks the question for real.
Our ebook explores some of the common assumptions that can sit underneath a business’s sense of security and exactly how to put each one to the test.
You’ll find practical questions and checks you can use to test those assumptions in your own business, so you can see where your security stands up to scrutiny and where there might be gaps worth addressing.


