“We’re too small for anyone to bother attacking us” is one of the most common things a small business owner says about website security, right before it turns out to be wrong. It’s an understandable assumption — but it’s built on a mental model of attacks that doesn’t match how most of them actually happen.
The Assumption This Relies On
The “we’re too small” reasoning assumes attacks are targeted the way a burglary is targeted — someone specifically choosing your business, for a specific reason, after some kind of deliberate scouting. Under that model, being small and unremarkable genuinely would make you a less likely target.
That’s not how most DDoS and bot attacks actually work.
How Most Attacks Actually Get Chosen
The overwhelming majority of DDoS attacks, credential-stuffing attempts, and bot traffic aren’t manually targeted at all — they’re automated, scanning broad ranges of websites for ones that are reachable and unprotected, with no regard for the business’s size, revenue, or prominence. A botnet doesn’t check whether a site belongs to a Fortune 500 company or a five-person local business before hitting it; it hits whatever responds and looks exploitable.
In this model, being small doesn’t make you invisible — it makes you a softer target, since smaller businesses are statistically less likely to have any protection in place at all.
The Actual Math That Makes Small Businesses Attractive
From a purely automated-attack perspective, small business sites are often more attractive, not less:
- Lower likelihood of existing protection — a large enterprise site is far more likely to already have a WAF, DDoS mitigation, and dedicated security staff. A small business site is statistically more likely to have none of that, making it an easier target to actually succeed against.
- Higher likelihood of outdated software — smaller sites, often self-managed or managed by whoever set them up initially, are more likely to be running outdated plugins or unpatched software, which automated scanners specifically look for.
- Lower likelihood of detection — a small site with limited traffic monitoring might not even notice an attack quickly, meaning it can persist longer than the same attack would against a monitored, larger target.
- Testing ground value — some attackers use smaller, less-monitored sites to test attack techniques or tools before deploying them against bigger targets, precisely because the smaller site is less likely to notice or respond effectively.
Why “We Don’t Have Anything Valuable to Steal” Misses the Point
This reasoning assumes the goal of every attack is stealing something specific and valuable from your business, but a large share of attacks aren’t about your data at all:
- Resource hijacking — using your server’s resources to send spam, mine cryptocurrency, or participate in a larger botnet targeting someone else entirely
- SEO manipulation — injecting spam links or content into your site to boost some other site’s search rankings, using your domain’s credibility
- Credential reuse — even if your site has “nothing valuable,” if customers reuse passwords across sites (which is extremely common), a breach of your login system can expose credentials attackers then try against banking or email accounts elsewhere
- Simple disruption — some attacks are just opportunistic vandalism or low-stakes extortion attempts, unrelated to the specific value of what’s on the site
What This Means Practically
The realistic threat model for a small business site isn’t “a sophisticated attacker specifically targets us” — it’s “an automated scanner finds us among thousands of other sites, and whether it succeeds depends entirely on whether basic protections are in place.” That’s actually a more manageable problem than the targeted-attack scenario, because baseline protection meaningfully changes the odds against this kind of automated, opportunistic attack.
The Baseline That Changes the Odds
This is precisely why unmetered DDoS protection, a hidden origin IP, and baseline firewall rules against bad bots and login abuse matter even for the smallest site — not because a sophisticated attacker is coming specifically for a small business, but because the automated scans that hit every reachable site on the internet will eventually reach yours too, and whether that scan finds an easy target or a protected one is the actual determining factor.
| Assumption | Reality |
|---|---|
| “Attackers choose specific targets” | Most attacks are automated and untargeted |
| “We’re too small to notice” | Small sites are statistically less protected, making them easier targets |
| “We have nothing worth stealing” | Resource hijacking, SEO abuse, and credential reuse don’t require valuable data |
| “It won’t happen to us” | It’s a matter of probability across broad automated scans, not deliberate selection |
The Bottom Line
Size doesn’t determine whether an automated attack reaches your site — it already can, and likely already has, in the form of scanning traffic most site owners never notice happening in the background. What size does affect is whether protection is already in place when it matters, which is the actual variable worth addressing rather than betting on being overlooked.



