I Read the FBI’s New Internet Crime Report. Here’s What Business Leaders Should Take Away
The FBI recently released its 2025 Internet Crime Report, and like many business leaders, I took the time to read it.
The headline numbers are staggering:
- More than 1 million cybercrime complaints
- More than $20.8 billion in reported losses
- A 26% increase in losses over the previous year
Those statistics certainly got my attention.
But after spending my career leading businesses (and now leading a cybersecurity company) the numbers themselves weren’t my biggest takeaway.
What stood out was something much simpler.
I’m going to share observations I think every business leader should take from this year’s report.
1. Cybersecurity is no longer an IT issue. It’s a business issue.
The financial impact of cybercrime has reached a level that every leadership team should be paying attention to.
When cybercrime is successful, it impacts:
- Business continuity
- Customer trust
- Financial performance
- Regulatory exposure
- Brand reputation
In other words, cyber risk has earned a permanent seat alongside financial, operational, and legal risk.
2. Most organizations aren’t losing because attackers are smarter. They’re losing because attackers exploit the basics.
The FBI reports that phishing and spoofing remain the most commonly reported cybercrime. Business email compromise continues to generate billions in losses.
That mirrors what we see every day.
Our own SMB Cybersecurity Statistics & Benchmark Report found:
- Only 28% of leadership teams receive regular cybersecurity briefings.
- 55% of organizations never conduct cybersecurity awareness training.
- 55% never perform vulnerability scans.
These aren’t failures of technology.
They’re gaps in execution.
3. The FBI’s recommendations aren’t complicated.
One thing I appreciated most about the report is that the FBI doesn’t recommend chasing the latest security trend.
Instead, they reinforce proven fundamentals:
- Multi-factor authentication
- Timely patching
- Strong backups
- Least-privilege access
- Continuous monitoring
- Incident response planning
There’s an important lesson here.
The challenge for most organizations isn’t knowing what to do.
It’s consistently doing it.
4. Leadership may be the biggest cybersecurity control.
Throughout my career, I’ve learned that organizations improve when leadership pays attention.
Cybersecurity is no different.
When executives regularly discuss cyberhealth, establish accountability, and treat cyber risk as an ongoing business function—not an annual IT project—better decisions follow.
Technology matters.
Leadership determines whether technology is used effectively.
5. The good news: Cyber resilience is achievable.
One of the most encouraging findings in our own research is that improvement doesn’t require perfection.
Organizations that commit to foundational cybersecurity practices improve dramatically over time.
In fact, businesses working through structured cyberhealth improvements with SensCy improved their scores by an average of 107% within the first year.
That’s important because the FBI report can feel overwhelming.
It shouldn’t.
The takeaway isn’t that cybercrime is unstoppable.
The takeaway is that disciplined organizations become significantly harder targets.
6. Don’t wait until your organization becomes part of next year’s report.
One lesson has stayed with me throughout my career.
Strong businesses don’t wait for problems to become crises before they build discipline.
The same principle applies to cybersecurity.
The FBI’s report documents what happened last year.
The question every business leader should ask is:
What are we doing today to make sure our organization isn’t part of next year’s statistics?
I came away from the FBI’s report with more urgency—but also more optimism.
The threats are real. They’re growing. And they’re costly.
But they’re also manageable.
The organizations that fare best aren’t necessarily the ones with the biggest security budgets. They’re the ones that treat cybersecurity as a business discipline, commit to the fundamentals, and improve consistently over time.
That’s a lesson worth taking from this year’s report—and one worth acting on before the next one is published.

The SensCy Solution
We provide an affordable, easy-to-understand, sensible solution specifically tailored to each client. Our clients tell us that they are thrilled with the value that they derive for the price they pay. Schedule a consultation with one of our experts.

Your SensCy Score® is a good indication of your organization’s cyber hygiene and how prepared your organization is against cyber threats. We can generate your score in less than 30 minutes—at no cost to you!
Recent Posts
