The National Cybersecurity Alliance just published its 2026 Small Business Cybersecurity Awareness & Practices Survey, based on 1,000 small and mid-sized business leaders. It is a genuinely useful piece of research, and its central finding deserves attention: small businesses are more confident about cybersecurity than ever, but their actual readiness does not match that confidence.
Small businesses are aware of the threats and confident in their defenses, and that confidence is not baseless. They have real tools and real training in place. But awareness does not always translate into readiness, and even when the tools and training are there, one thing stays unprotected: the moment right before someone clicks. This is the gap Haven was built to close. Across the businesses we protect, that moment right before the click is where attacks land, again and again, no matter how strong the rest of the stack looks. The NCA data shows how wide the gap has already grown.
Confidence Is Up. Readiness Isn't
NCA found a striking level of optimism. 86.3% of SMB leaders report medium-to-very-high confidence in their ability to manage cyber risk, and most feel they could recover quickly from being knocked offline.
At the same time, 72.3% say their cyber risk increased or stayed flat over the past year, and only 23.7% review cybersecurity as a business risk on a monthly basis. Confidence is high. The conditions underneath it are not improving. NCA names this directly as a gap between how ready leaders feel and how ready they actually are.
The same pattern shows up in AI. Adoption among small businesses has reached 87.3%, but more than half have no formal guidelines for how AI should be used. Adoption is outpacing governance. The tools arrive faster than the practices that make them safe.
Keep your business safe from online threats
Haven for Business protects every employee from phishing, fake sites, and browser-based attacks.
The control-level data makes this concrete. 86.8% of businesses have implemented multi-factor authentication, but only 51.1% require it across all key accounts, with more than a third requiring it for only some. 88.4% have backups, but only 61.4% have actually tested them, leaving roughly a quarter of the market relying on backups that may not work when it counts.
NCA's conclusion is worth quoting directly: "Having a tool and using it correctly are two different things, and the gap between them is where attacks succeed."
That is true, and important. But there is a step beyond it that the data is pointing at.
The Last Mile Nobody Covers
Even a correctly configured tool does not eliminate the moment where a person has to decide.
MFA does not help if someone approves a push notification they did not expect. A tested backup does not help if someone hands over their password on a page that looked like the real thing. Thorough training does not help when a phishing email is polished enough that "look for the red flags" gives you nothing to work with.
Every layer of defense, tools, policy, and training, eventually routes through the same choke point: a person, in a browser, looking at something like bankofamerica-secure-login-whatever.com, deciding in a few seconds whether to trust it.
That is the last mile of cybersecurity. It is the moment right before the click. And none of the standard defenses fully reach it.
This is where the last-mile idea gets its teeth. The reason confident, well-equipped businesses still get breached is not apathy. It is architecture. Almost every control ends just before the decision that actually matters.
Training is the clearest example. Employees retain only about 20 to 30% of annual security training within 30 days (security-awareness research), which means for most of the year, people are running on very little of what they learned. And it shows in the outcomes: the human element is still involved in roughly 60% of breaches, a number that has stayed flat year over year even as training budgets rise (Verizon Data Breach Investigations Report).
The timing is the hard part. In the Verizon DBIR, the median time from opening a phishing email to clicking the link is about 21 seconds. That is not enough time to run a checklist, and people working under deadline pressure are more likely to click anyway. A well-run awareness program still leaves the person alone at the exact instant they need help most.
Small businesses are, largely, doing what they are supposed to. They are adopting MFA, keeping backups, and asking for training. The NCA data shows the intent is there. What is missing is anything that reaches the moment the intent has to become a decision, when someone is in a browser, staring at a convincing lookalike, with seconds to choose. Nobody guards that moment. That is the gap.
Haven guards the last mile
Tools and training end at the click. Haven starts there. It is a browser-based layer built for exactly that moment, the point of decision, not before it and not after.
When an employee lands on a page that imitates a bank, a Microsoft 365 login, a vendor portal, or any other trusted brand, Haven analyzes the actual page in front of them, not just how it looks or how they arrived, and flags it as fake or unverified before any credentials are entered. It does not matter whether the link came from a phishing email, a calendar invite, a sponsored search result, or a compromised sender that sailed past the email filter. Haven checks the page itself. And on unverified sites, it pauses downloads so the person can see what is about to land on their device before it runs.
This is not a replacement for MFA, backups, or training. Those still matter. Haven completes them. It reaches the one place they cannot: the few seconds where a person has to decide whether bankofamerica-secure-login-whatever.com is real, and gives them an answer instead of a checklist.
NCA's research draws the map precisely. Small businesses have the tools and the awareness. The gap is between having them and surviving the moment they are tested. Haven for Business is the layer that lives in that moment, so the last mile is covered for every employee, automatically.
About Haven
Haven is a browser extension that helps people make safer trust decisions online, at the moment they are about to click a link, enter a password, or download a file. It flags fake and impersonated login pages, suspicious links, and lookalike sites, and pauses downloads on unverified sites, so a convincing fake gets caught before it can cost anything. Rather than only checking a page against a list of known-bad sites, Haven analyzes the actual page in front of the user, so it can catch brand-new and convincing fakes that other tools miss.
Haven is free for individual use. For teams, Haven for Business extends this browser-level protection across every employee, and Haven for MSP lets managed service providers deliver it across their clients.