Semel Consulting

Semel Consulting The trusted compliance expert helping you to secure your business since 1980. CMMC - DFARS - HIPAA - NIST

Search your website for “60%” and “six months.”Then check your proposals, presentations, email campaigns, blogs, client ...
09/11/2026

Search your website for “60%” and “six months.”

Then check your proposals, presentations, email campaigns, blogs, client reports, and cybersecurity sales materials.

If you find the claim that 60% of small businesses close within six months of a cyberattack, remove it.

The organization commonly cited as the source says it did not generate the statistic and cannot verify where it originated.
Recently, I saw a respected cybersecurity industry organization repeat the claim in a video. I contacted them and explained the problem with the source. They removed it.

I am not going to name them because that is not the point.
They did what responsible organizations should do. When they learned the information could not be supported, they corrected it.

The first time I saw the statistic, it did not pass my smell test. I knew many businesses that had experienced cyberattacks, and none had closed because of them. I called industry colleagues and asked about their experience. They all had incident-response stories.

None could identify a client that had closed because of the attack.
That did not prove the statistic was false. It gave me a reason to investigate it.

Use common sense, then verify.

Here is one statistic I am comfortable publishing without a footnote:
100% of MSPs should stop using statistics they cannot verify.

When it comes to cybersecurity, a scary statistic can get attention. But for MSPs, using one without checking the facts can come at a cost.

Today, we honor and remember all those affected by the events of September 11, 2001. We stand together in remembrance of...
09/11/2026

Today, we honor and remember all those affected by the events of September 11, 2001. We stand together in remembrance of the lives lost, the heroes who emerged, and the resilience of our nation.

AI can make a bad statistic sound authoritative.One website cites another. A marketing company adds the statistic to an ...
09/10/2026

AI can make a bad statistic sound authoritative.

One website cites another. A marketing company adds the statistic to an MSP’s content. An AI tool repeats it in another answer.

Eventually, nobody asks the most important question: Where did the number come from, and does the source actually support it?

I do not believe most MSPs repeating the “60% of small businesses close” claim are trying to mislead anyone. They have seen the number so many times that it looks legitimate.

Repetition is not verification.
Read that again.
Repetition is not verification.

MSPs use statistics in proposals, assessment reports, presentations, websites, and sales conversations. Every one of those claims reflects the credibility of the company using it.

When a prospect finds one statistic that cannot be supported, they may start questioning the rest of the recommendation.

AI can assist with research and writing. It should not be treated as the source. Ask for the original citation. Read it. Confirm that it says what the content claims it says.

A confident answer is not the same as a verified answer.

I wrote more about the statistic, its questionable history, and the responsibility MSPs have when publishing cybersecurity information:

When it comes to cybersecurity, a scary statistic can get attention. But for MSPs, using one without checking the facts can come at a cost.

The “60% of businesses close” cyberattack statistic is phony.For more than 15 years, people have repeated the claim that...
09/10/2026

The “60% of businesses close” cyberattack statistic is phony.

For more than 15 years, people have repeated the claim that 60% of small businesses close within six months of a cyberattack.

The National Cyber Security Alliance is frequently cited as the source. It says it did not generate the statistic, cannot verify where it came from, removed the claim from its website, and recommends that people stop using it.

At the 2026 BSides Las Vegas conference, security researcher Adrian Sanabria presented research he has conducted for nearly a decade. Over a 25-year period, he documented 35 businesses that appear to have closed primarily because of a cybersecurity incident.

His list may not include every business. But if the 60% claim were true, examples should not be difficult to find. We should see thousands of businesses closing every year after cyberattacks.
Instead, the same statistic keeps appearing on MSP websites, cybersecurity sales pages, blogs, presentations, and newly published reports.

Cyberattacks can cause serious business interruption, recovery costs, lawsuits, regulatory penalties, insurance disputes, and damaged customer relationships.

The real risks are serious enough. We do not need a phony statistic to sell cybersecurity.

I explain where the claim came from and why MSPs should stop using it here:

When it comes to cybersecurity, a scary statistic can get attention. But for MSPs, using one without checking the facts can come at a cost.

Labor Day is a chance to recognize the people who show up every day and keep our businesses and communities moving.We ar...
09/07/2026

Labor Day is a chance to recognize the people who show up every day and keep our businesses and communities moving.

We are grateful for our team, our clients, and all the hardworking people behind the companies we support.

Thank you for what you do.

Happy Labor Day from Semel Consulting.

The proposed CUI rule does more than create another cybersecurity requirement. It moves cybersecurity deeper into the fe...
09/04/2026

The proposed CUI rule does more than create another cybersecurity requirement. It moves cybersecurity deeper into the federal procurement process.

The agency would identify the CUI in the solicitation. If the contractor has unmet requirements, those gaps may have to be disclosed with the offer. The government could later request the SSP and associated plans of action during contract performance.

Now business development, finance, contracts, IT, and leadership all have a reason to understand the cybersecurity requirement before the work is awarded.

If the requirement changes the systems the company has to use, the cloud environment, the providers involved, the timeline, or the cost of performing the work, it belongs in the same conversation as every other contract requirement.

A company can be technically capable of doing the job and still get the business decision incorrect because nobody understood the cybersecurity obligation before the bid went out.

Federal contractors are going to have to get much better at connecting compliance to the way they price and pursue work.

Most contractors do not start from zero. They already have an MSP, security tools, policies, an SSP, an SPRS score, and ...
09/04/2026

Most contractors do not start from zero. They already have an MSP, security tools, policies, an SSP, an SPRS score, and some level of remediation underway.

The first question is whether those efforts are based on an accurate CMMC scope.

During a QuickStart, we review the contract requirements, how CUI enters and moves through the company, the systems and assets involved, the SSP, asset inventory, network diagram, current score, external service providers, and the assumptions the company is using to define its environment.

We are looking for alignment.

Does the SSP describe the environment that actually exists? Does the asset inventory include what is really handling or protecting CUI? Does the network diagram match the current architecture? Is the SPRS score based on the environment leadership believes it represents?

If those pieces do not align, additional remediation may be based on the wrong starting point.

A QuickStart is a one-day, on-site engagement led by a CMMC Certified Assessor. It does not complete the CMMC program in one day. It identifies whether the company has a supportable foundation before additional time and money are committed to preparation.

Comment QUICKSTART or send me a message if you want the details.

The proposed FAR CUI rule is not effective today.So I would not tell a business owner to start replacing systems, changi...
09/04/2026

The proposed FAR CUI rule is not effective today.

So I would not tell a business owner to start replacing systems, changing cloud providers, or spending money on Revision 3 because of a proposed rule.

I would tell them to look at the federal work they already have.
Which contracts involve CUI?
What cybersecurity requirements are already in those contracts? What information does the company actually receive or create? Where does it go?
Which systems and providers support the work?

You may find that the company is already doing what the current contract requires.

You may also find a requirement that has been sitting in the contract while everyone assumed it belonged to IT or would become important later.

Either answer is better than guessing.

Then, when the government finalizes the new CUI rule, leadership can compare the new requirement to a program it already understands instead of starting from scratch under a proposal deadline.

I would not spend money today trying to predict the final rule.
I would make sure I understand the contracts I am already being paid to perform.

If your company handles CUI for a civilian federal agency and you are not sure what is required today versus what is still proposed, send me a message.

If the government adds CUI after the contract is already awarded, that is not just an IT change.Under the proposed FAR p...
09/04/2026

If the government adds CUI after the contract is already awarded, that is not just an IT change.

Under the proposed FAR process, if the agency later identifies additional information as CUI and still wants the contractor to handle it, the government would have to update the CUI form and modify the contract. The contracting officer would also have to consider an appropriate request for an equitable adjustment.

Now the contractor has to look at what actually changed.

Do different systems have to be used? Does the cloud environment change? Does the MSP have more work to perform? Do additional employees need controlled access? Do subcontractors now have requirements they did not have when the job was priced?

Those costs can add up quickly.

I have seen companies absorb new compliance work because everyone treated it like a technical change instead of a contract change. IT starts fixing things, the MSP starts billing more hours, documentation gets rewritten, and nobody stops to ask whether the company agreed to perform significantly more regulated work for the same price.

If the CUI requirement changes after award, leadership needs to understand exactly what changed before the company absorbs the cost.

A federal contractor may have to disclose its CUI security gaps before the government awards the contract.That is one of...
08/28/2026

A federal contractor may have to disclose its CUI security gaps before the government awards the contract.

That is one of the most important parts of the proposed FAR CUI rule.

If an offeror does not comply with all of the requirements in the proposed CUI clause, the company would have to identify every unmet requirement and submit a plan of action and milestones with its offer.

That means the gap is no longer sitting inside an IT project. It may become part of the proposal the company submits to win the work.

Leadership needs to know exactly what is missing, what it will cost to fix, how long the work will take, and whether the plan being submitted is something the company can actually deliver.

The government would have a written record of what was not implemented when the offer was submitted. That should make business owners think differently about what “we’re working on it” means.

A plan of action is useful when it reflects a real plan.

It is much less useful when it gets written two days before the proposal deadline and nobody priced the work behind it.

Address

6547 Midnight Pass Road #90
Sarasota, FL
34242

Alerts

Be the first to know and let us send you an email when Semel Consulting posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share