At the end of 2024, a ransomware attack on Change Healthcare, a subsidiary of UnitedHealth Group, disrupted claims processing across the United States. Pharmacies were unable to process prescriptions, providers faced delays in reimbursements, and the operational impact spread far beyond a single organization.
Only months later, another major incident hit MGM Resorts, where attackers gained access through a social engineering attack targeting IT help desk processes. The breach led to system outages, service disruption across hotels and casinos, and an estimated loss of over $100 million.
These events did not originate in obscure technical vulnerabilities. They began with access: credentials, identity systems, and trusted entry points.
California, with its dense digital economy and strict regulatory environment, continues to surface these patterns early. What happens here rarely stays local. It becomes a preview of how cyber risk evolves across the broader U.S. market.
For small and mid-sized businesses, the message is direct. The same dynamics behind these high-profile breaches (identity compromise, third-party exposure, and delayed detection) exist in scaled-down environments every day.
The difference lies in visibility and preparedness.
The Expanding Attack Surface: Why SMBs Are Increasingly Targeted
The structure of cyberattacks has shifted. Scale is no longer the defining factor for targeting. Accessibility is.
Verizon’s Data Breach Investigations Report shows that a large share of breaches involve organizations with fewer than 1,000 employees.
This reflects a deliberate strategy. SMBs operate in connected environments (cloud platforms, SaaS tools, vendor integrations) but often without the layered controls found in larger enterprises.
Cloud adoption plays a central role. Infrastructure is more flexible, but also more exposed. A single misconfiguration, an open storage bucket, or excessive permissions can create an entry point that remains invisible until exploited.
In several recent breaches, attackers entered quietly, mapped the environment, and escalated privileges over time. The disruption came later. The access came first.
For local businesses, this changes the risk model. Cybersecurity is no longer about preventing entry alone. It is about limiting movement and detecting activity early.
Identity & Access: The New Attack Surface
Modern attacks increasingly revolve around identity.
According to Microsoft’s Digital Defense Report, identity-based attacks dominate today’s threat landscape, with compromised credentials acting as the primary entry vector.
The MGM breach provides a clear example. Attackers did not exploit infrastructure weaknesses. They used social engineering to obtain access through legitimate channels. Once inside, they operated within trusted systems.
This pattern repeats across industries. Credentials are easier to obtain than system-level exploits, and they provide immediate legitimacy.
The challenge for many organizations lies in access sprawl. Permissions accumulate over time. Former employees retain access. Vendors operate with broad privileges. Internal systems trust authenticated users by default.
Zero trust principles address this by continuously validating access rather than assuming it. Multi-factor authentication, role-based access control, and real-time monitoring form the foundation.
For SMBs, the opportunity is clear. Strengthening identity controls delivers immediate and measurable risk reduction.
Third-Party Risk: When Trust Becomes Exposure
The Change Healthcare breach illustrates another critical dimension: third-party risk.
A single compromised provider disrupted a large portion of the U.S. healthcare payment infrastructure. The impact extended across organizations that were not directly breached but depended on the affected system.
This reflects a broader trend. Gartner projects that supply chain attacks will continue to increase as attackers exploit interconnected systems.
Modern businesses operate through ecosystems. Software vendors, IT providers, and service partners integrate directly into operational workflows.
Each connection introduces efficiency … and risk.
Vendor access is often persistent, rarely audited, and difficult to monitor in real time. When compromised, it allows attackers to operate with a level of trust that bypasses traditional controls.
Managing this risk requires continuous oversight. Access must be limited, monitored, and revocable at any moment. Vendors must be evaluated not only at onboarding, but throughout the relationship.
Organizations that extend their security model to include their ecosystem significantly reduce their exposure.
The Real Cost of a Breach
The financial impact of cyber incidents continues to increase, but the most significant cost is operational.
IBM’s Cost of a Data Breach Report highlights how downtime, response complexity, and business interruption drive total impact.
The MGM incident alone resulted in over $100 million in losses, driven largely by service disruption rather than data recovery.
Harvard Business Review further notes that companies often experience sustained performance decline following major breaches.
In California, regulatory frameworks such as CCPA and CPRA add another layer.
Compliance requirements accelerate response timelines and increase exposure to penalties and legal action.
For SMBs, these combined pressures create a disproportionate impact. Limited redundancy and tighter margins amplify the consequences of downtime.
Cybersecurity, in this context, becomes directly tied to business continuity.
From Detection to Resilience
The defining difference between disruption and containment lies in visibility.
Organizations that respond effectively to incidents detect anomalies early. They correlate signals across systems. They act before attackers can escalate.
Managed detection and response (MDR), centralized logging, and continuous monitoring provide this capability without requiring large internal teams.
Recovery also defines resilience. Secure, immutable backups ensure that operations can be restored quickly, even in ransomware scenarios.
Human awareness completes the picture. Many attacks still begin with a single interaction; a phishing email, a password reset request, a social engineering attempt. Training employees to recognize these signals creates an additional layer of defense.
Resilience is not a single solution. It is a system of controls, visibility, and response working together.
Building Control in an Uncertain Landscape
The breaches that swept across California in 2026 reveal how quickly digital risk can translate into business disruption. They also show that resilience is achievable with the right approach.
Organizations that move early, strengthen visibility, and control access build environments where attacks are contained, not amplified. This shift transforms cybersecurity from a reactive function into a core driver of stability and growth.
With the right partner, every organization can move from uncertainty to control, creating systems that support performance, protect data, and adapt to evolving threats.
IT Consulting & Strategy: clear, actionable roadmaps aligned with business priorities and risk exposure.
Managed IT Services: continuous oversight, proactive intervention, and operational continuity.
Cloud Solutions: secure, scalable environments designed for flexibility and resilience.
Cybersecurity: identity-driven protection, real-time detection, and continuous risk management.
Procurement & Infrastructure: efficient, future-ready technology built around your workflows.
👉 If your organization is ready to strengthen its security posture and build a more resilient IT foundation, contact our team today to start a strategic conversation.



