Cybersecurity
July 27, 2026
When an emergency veterinary hospital in South Carolina was hit last year with a sudden ransomware attack, the computers went down. So did all the medical equipment, putting beloved pets at serious risk. While the staff scrambled to save lives, they ultimately paid hackers $10,000 to retrieve access to their systems.
These types of attacks are increasingly aimed at small- and medium-sized enterprises because they’re far less likely than large businesses to have the right protections in place, says Kevin Pierce, president and chief operating officer of VikingCloud, a global cybersecurity and compliance company. Mastercard research underscores the scale of the challenge, finding that nearly half of small and medium-sized companies have experienced a cyberattack at their current business.
VikingCloud’s solutions protect companies of every size, from global brands and multi-location businesses to millions of small and medium-sized enterprises through partnerships with the world’s largest acquirers. And, as a Mastercard global technology partner, VikingCloud combines its own AI-powered merchant platform and cybersecurity remediation expertise with Mastercard’s risk-scoring and evaluation capabilities to help smaller companies strengthen their cyber defenses.
Pierce says most cybersecurity companies offer solutions built to handle the needs of the Fortune 500, not a 200-person retailer with 50 stores, a services firm with small offices in multiple states, or a single storefront on Main Street. VikingCloud serves more than 4 million business locations of all sizes worldwide with enterprise-grade solutions that “simply work,” he says, regardless of budget.
But it’s not just about the tools, he says — it’s about knowing how to deploy them. Many smaller businesses are unlikely to have fully staffed professional IT departments at the ready. In fact, according to VikingCloud research, 84% of owners of smaller businesses self-manage their cybersecurity, often without dedicated training or support.
He recently sat down with Mastercard to discuss the unique requirements of small and medium-sized businesses, and what small businesses need to think about as they grow, their customer base expands, and their risks multiply.
Pierce: When I think of small businesses that we work with, they have a pretty clear set of basic needs: multifactor authentication, email security, basic endpoint protection like antivirus, backups, or a password manager, and basic employee training. Those are all good. If you have five or six controls like these, you implement them really well, and you ensure employees actually abide by the standards, it's going to cover most of your risk.
When you start heading to medium-sized businesses, maybe 150 to 200 employees, their needs change dramatically because their attack surface is very different. I call it the “valley of disadvantage” because they're big enough to be worth attacking, but without the resources of an enterprise to defend themselves.
Medium-sized businesses, in addition to the small business solutions I just mentioned, need single sign-on for all their devices. They need identity governance and identity access management. They need role-based access to all of their systems. If they are multi-location businesses, they need a segmented network so that if an attack occurs at one site, you can't have lateral movement from one site to another, or, worse yet, back to corporate headquarters.
The middle is tough ground to hold. One of the biggest things for businesses that are growing and know they're going to become midsize is that when you're 25 employees, you better start planning for what you'll need to do when you're 200.
Pierce: Most already think about cybersecurity, but they don't always include compliance as part of their defense planning. For all businesses that collect customer payment card information, for example, you have to meet the industry’s data security standards, called PCI DSS. If you’re a smaller company, you can do that yourself by filling out a questionnaire once a year. When you grow and your payment card transactions hit a certain threshold, you have to have a third-party assessor come in and examine your compliance posture. They're going to look at everything, and you have to pay them tens of thousands of dollars. And if you don't meet the standard, you've got to adopt new security technologies and implement new policies.
Pierce: You have to budget for it. There's a lot of internal work to meet PCI DSS standards. You really must have your house in order from a cybersecurity standpoint. So that's why I say the best companies, if they're growing, plan this early and have this well managed — typically partnering with professionals who can ensure they get it right.
Pierce: You see a lot of retailers who fall into this category. You see health care clinics, pharmacies, and restaurant chains as good examples. All typically operate in a hybrid environment where you have the needs of an enterprise company at corporate headquarters, with all the remote locations often operating as just very small businesses. That means if you have a security incident at a remote location, there's no one on site to manage it.
There are a couple of things that these organizations must think through that are unique to this environment. When they're deploying technology and security, it’s best if they have what we call one stack, or one common setup, that's deployed identically at each of these locations, so the same security control is rolled out uniformly across all locations and managed centrally.
This has to be a standardized approach, whether locations are franchised or corporate-owned, because one weak link can put the whole brand at risk. A standardized approach gives you a single view across the network so you can act fast if something goes wrong at one site — multiple vendors and multiple setups across the same environment are a recipe for disaster.
The other thing is that you must be able to deploy these in almost a plug-and-play mentality. If it needs local configuration or on-site troubleshooting, or someone has to go into settings and make changes, it's not going to work.
Pierce: If you look at what SMEs are reporting most often, it's things like AI-generated phishing, ransomware, and deepfake-related fraud — unfortunately pretty standard stuff at this point. What's changed is the sophistication behind it. You start seeing detailed dossiers that attackers put together around key executives, with org charts of your organization. They'll carry out a business email compromise attack that AI makes exceptionally hard to detect and then follow it up with phone calls that could have a deepfake of your CEO’s voice.
These are enterprise-level attacks against companies that lack the resources to defend themselves. Our 2026 SMB Threat Landscape Report found that 40% of SMEs say a cyberattack costing $100,000 or less would shut them down. A large company, for the most part, can weather that. They've got cyber insurance. You don't see much cyber insurance among small businesses. But it is recommended that once you reach the mid-market level, you invest in cyber insurance.
Pierce: We're using the same AI tools as attackers to help defend our customers. That’s the investment we make so they don’t have to. Our platform constantly scans for the same weak points an attacker would look for — exposed logins, outdated software, misconfigured firewalls — and tells our customers exactly what to fix and in what order, before anyone tries to exploit it. No SME owner started a business to become a cybersecurity expert, and they shouldn't have to be one. That's the point of all of this — we do the work so businesses can plan for security the way they plan for growth and never end up stuck in the valley of disadvantage.