
Cybersecurity for Wisconsin Businesses: What the Statewide Numbers Miss About Your Building
Statewide numbers describe a state, not your building. What a Wisconsin business owner can and cannot conclude from the headline figures, and what to measure instead.
You've probably seen the headline: more than half of cyberattacks target small businesses. The FBI reported nearly 860,000 cybercrime complaints in 2024, with losses exceeding $16.6 billion. Numbers like these are everywhere, and they feel urgent. But here's the problem: they describe what happened to small businesses as a group, not what's happening in your building right now.
What the big numbers actually say
The Wisconsin SBDC reports that more than half of cyberattacks target small businesses. That's true. It's also a statement about a category, not a prediction about your shop.
The FBI's Internet Crime Complaint Center received 859,532 complaints in 2024, with potential losses exceeding $16.6 billion. Those are real numbers. But they count reported incidents, most incidents go unreported. And they're national figures, not Wisconsin-specific. They tell you what happened somewhere, not what's likely to happen in your building.
When you read these numbers, you're reading an average. An average across 457,769 small businesses in Wisconsin alone, 99.4% of all Wisconsin businesses, employing 1.3 million people. That population includes a two-person consulting firm, a 50-person manufacturing shop, a 200-person logistics company, and everything in between. An average across that range tells you almost nothing about any single one of them.
Why statewide stats don't describe your building
A statewide number is useful for policy. It's useless for deciding whether your business is at risk right now.
Your risk depends on what data you hold, who can reach it, whether your staff can spot a phishing email, whether your systems are patched, and whether you have backups that actually work. None of those things show up in a statewide average. A two-person bookkeeping firm and a 200-person manufacturer both count as "small businesses," but they face completely different threats and have completely different defenses available.
The same is true for national numbers. The FBI IC3 figures are real, but they describe incidents that were reported to the FBI, a small fraction of what actually happens. They don't break down by state. They don't tell you which industries are hit hardest in Wisconsin, or which threats are most common in the Chippewa Valley versus the Coulee Region. They're a national snapshot, not a local one.
What to measure at the building level instead
If statewide numbers can't tell you whether your business is at risk, what can?
Start with the things you can see and verify in your own environment:
- Do you require multi-factor authentication (MFA) on critical accounts?
- Are your operating systems and software current, or are you running versions that stopped receiving security updates months ago?
- Do you have backups, and have you actually tested whether they restore?
- Can your staff recognize a phishing email, or would they click a link in a convincing fake?
- What personal information do you actually hold, customer data, employee records, payment information, and where is it stored?
- Can you see what's connected to your network, or do devices just appear and disappear?
These are building-level measurements. They're concrete. They're actionable. And they're what a local engineer can walk through and verify.
The NIST Cybersecurity Framework 2.0 (SP 1300) is built specifically for small-to-medium businesses with modest or no cybersecurity plans. It walks you through the basics: what to measure, how to prioritize, where to start. CISA publishes small business guidance because most security advice is out of date or doesn't address the actual compromises small businesses face, a federal acknowledgement that generic stats don't translate to a specific shop.
Wisconsin-specific obligations you may not know about
If a breach happens, Wisconsin law requires you to act.
Under Wisconsin Statute 134.98, most businesses operating in Wisconsin and holding personal information about Wisconsin residents must notify affected individuals of an unauthorized acquisition of that data. That's not optional. It's not a best practice. It's a legal requirement.
If your business holds an insurance license, the rule is tighter. Under Wisconsin Statute 601.954, insurance licensees must notify electronically and within 3 business days of determining a cybersecurity event occurred. Three business days. Not three weeks. Three days.
If an incident does occur, Wisconsin Emergency Management directs private businesses to report to the Wisconsin Statewide Intelligence Center, CISA, and the FBI. That's the official state channel.
Free Wisconsin and federal resources you can use this week
You don't have to hire anyone to start measuring your own building.
The Wisconsin SBDC offers a free "Small Business, Big Threat" confidential risk assessment that takes 20–30 minutes. It's the closest thing to a building-level measurement a Wisconsin owner can take for free. You answer questions about your current practices, and you get a sense of where you stand.
WEDC publishes a free video series with a broad overview, key factors for small businesses, and three cyberthreat exercises. It's Wisconsin-specific and designed for business owners, not IT professionals.
ReadyWisconsin offers password and antivirus guidance tailored to Wisconsin businesses. The FBI IC3 website (IC3.gov) is where you report cybercrime, and the FTC's ReportFraud.ftc.gov is where you report fraud.
What a local walkthrough catches that a stat never will
A statewide number can't see your router. It can't see the password written on a sticky note under someone's monitor. It can't tell you whether your backup actually works, or whether the person handling customer data has ever been trained to spot a phishing email. It can't walk through your building and see the things that matter.
That's what a local, on-site assessment does. We work with businesses across the Coulee Region, the Chippewa Valley, and into Monroe County and Winona. A local engineer can walk through your actual environment, measure the things that matter to your specific building, and tell you what to fix first.
Start with the free Wisconsin SBDC "Small Business, Big Threat" risk assessment, about 20–30 minutes, then book a building-level walkthrough with a local engineer who can measure what a statewide stat never will.


