You are not a target, you are in the way
Small business owners frequently believe they are too small to be attacked. That is a reasonable inference from how attacks are described and it is wrong, because it assumes someone chose you.
Most attacks on small organisations are not targeted. They are automated. Systems scan continuously for exposed services, known vulnerabilities and reused credentials, and they act on whatever they find. Nobody decided your business was worth attacking; a program found a door.
What that changes about the analysis.
Being uninteresting provides no protection, because nothing evaluated whether you were interesting.
You are attacked at the same rate as anyone with a similar exposure, and you have fewer defences than a large organisation, which makes you a better outcome for the same effort.
And the second common route in is your relationships. Small businesses are attacked as a path to a larger customer, and small businesses handling other people's money or data are attacked for that. An accountant, a bookkeeper, a lettings agent and a small law firm all hold material worth more than their own turnover suggests.
The practical consequence for how to think about this. The question is not who would attack us. It is what is exposed, and what would happen if it were taken.
And the encouraging part, which the rest of this lesson develops. Because most of what reaches a small business is opportunistic rather than crafted for you, a small number of basic controls removes a disproportionate share of the actual risk. You are not defending against a determined adversary who has chosen you. You are trying not to be the easiest available option.

