If you own or manage a small business, cybersecurity may not be the first thing on your mind when you think about what’s happening in Washington – but it should be on your radar now. A new cybersecurity bill for small businesses just passed the U.S. House of Representatives unanimously, and it signals something important – even lawmakers are recognizing that small businesses are increasingly vulnerable to cyberattacks, and the current level of support isn’t enough.
Here’s what the bill does, why it matters, and most importantly – what your business should be doing right now.
What is the Small Business Cybersecurity Assistance Evaluation Act?
On June 23, 2026, the Small Business Cybersecurity Assistance Evaluation Act passed the House of Representatives with unanimous bipartisan support. Introduced by Congresswomen Lateefah Simon (D-CA) and co-led by Congressman Rob Bresnahan (R-PA), the bill directs the Government Accountability Office (GAO) to:
- Assess the specific cybersecurity threats and vulnerabilities facing small businesses
- Identify existing federal programs and resources available to help small businesses prepare for, mitigate, and defend against cyberattacks
The legislation specifically highlights that minority-, women-, disabled-, and veteran-owned small businesses face even greater risk – and that a single cyber incident can deepen existing economic gaps and significantly threaten a business’s ability to stay operational (Office of Congresswoman Lateefah Simon).
Why Small Businesses Are Being Targeted
Small businesses are an increasingly attractive target for cybercriminals – and it’s not by accident. Hackers know that small businesses often lack the dedicated IT staff, security budgets, and enterprise-grade tools that larger corporations rely on. That gap creates opportunity.
The most common threats facing small businesses today include:
- Phishing Attacks – fraudulent emails designed to trick employees into handing over credentials or clicking malicious links
- Ransomware – malicious software that locks your data and demands payment to restore access
- Payment Fraud – schemes targeting your accounts payable, payroll, or vendor payment processes
These aren’t just technical problems. They are business-survival problems.
What This Bill Actually Does (and What It Doesn’t)
It’s worth being clear here: this cybersecurity bill for small businesses does not immediately deliver new funding, tools, or resources to small businesses. The Government Accountability Office (GAO) is a nonpartisan federal agency that audits and investigates how the government spends money and evaluates federal programs. This bill directs the GAO to study the cybersecurity challenges small businesses face and report back to Congress with findings. Essentially, it gives lawmakers the information they need to take further action (Congress Bill to GAO)
That’s a meaningful step forward, but it also means real relief from the federal government could still be years away. The bill is a signal that change is coming – not a solution you can reply on today.
Why You Can’t Wait for Washington to Act
The cybersecurity threat landscape isn’t waiting for legislation to catch up. Attacks are becoming more sophisticated, more frequent, and more costly. As noted in the bill’s own language, a single cyber incident can significantly impact a small business’s ability to remain operational – and small businesses disproportionately lack the resources to recover
While Congress works through the process of studying, reporting, and eventually legislating – your business needs protection now. The good news is that you don’t have to figure it out alone.
What Your Business Should Be Doing Right Now
Regardless of what federal programs may become available down the road, there are foundational steps every small business should have in place today:
1. Know What You’re Protecting
Understand where your sensitive data lives – customer records, financial information, employee data – and make sure it’s properly secured and backed up
2. Train Your Team
95% of cyberattacks succeed because of human error (VikingCloud). Regular employee training on how to spot phishing emails and suspicious activity is one of the most cost-effective defenses you have.
3. Use Multi-Factor Authentication (MFA)
Require MFA on all business accounts – email, banking, cloud tools. It’s a simple layer of protection that stops a large percentage of credential-based attacks.
4. Have a Response Plan
If something does happen, do you know what to do? Having a clear incident response plan can be the difference between a manageable disruption and a full business crisis.
5. Partner with a Trusted IT Provider
You don’t need an in-house IT department to have enterprise-level protection. A managed IT services provider can monitor your environment, respond to threats, and keep your systems up to date, so you can stay focused on running your business.
Don’t Wait for Washington
The passage of this cybersecurity bill for small businesses is an encouraging sign – but awareness in Washington doesn’t automatically translate to protection for your business. Small business owners need to understand that cybersecurity is no longer just an IT concern; it is a business risk that deserves the same attention as any other operational threat.
Understanding the risks is the first step. Cybercriminals actively seek out businesses that are underprepared, and simply not knowing what threats exist can make your business an easy target. Staying informed about common attack methods – phishing, ransomware, payment fraud – puts you in a far better position to prevent them.
The fact that Congress is paying attention is a reminder that this is a growing national concern – and small businesses are at the center of it. Use this moment as motivation to take stock of where your business stands and make cybersecurity a priority before an incident forces your hand.
Have more questions about this bill or the impact cybersecurity has on your business? We’re here to help. Contact us for answers, guidance, or support.




