Earlier quoted context omitted.
I'm advising people at the executive level. They do not care about the details of hashing PII, they want to know how likely it is that they will be targeted and how likely that attack is to succeed. And the fact is that an insurance company gets targeted far less often than crypto companies.
Is that true? Are there metrics of how many attacks are completed on an SMB that does and does not have crypto? And how is it known that those with crypto are suddenly easier targets than those without it? Edit: For the downvotes, if this is such an obvious question then be proactive and share the metrics - I'm skeptical this is the case but happy to be proved wrong.
SMB vs. web3/Defi, 30 person teams, no security engineers? The web3 company probably is a lot more vulnerable.
SMB/startup vs. generic crypto exchange like Poloniex? This gets harder to parse. Poloniex gets the malicious traffic and has a pretty small security team I think. But, they and companies similar are a tech company in the cloud and with a solid infra engineering team and leveraging AWS tooling, it's not like they're totally exposed. The SMB/startup has none of this, so arguably they are a similar risk profile in surprising ways, or maybe even more exposed than the exchange.
SMB/startup vs. a Tier 1 exchange like Coinbase? Very silly comparison, CB has a pretty large security team, knows their stuff, etc. etc, very good track record until very recently, and as a industry group the Tier 1 exchanges do well on the security front.
Compare this to the SMB instances of malware sitting on a Point-of-sale system for months/years until it gets discovered? Family dentists getting ransomwared fairly consistently? The retail/SMB space is a bit of a security nightmare. For someone building a product here and is able to sell the "so what" of it to a dentist, there's opportunity. If SMB == startup, well that's likely a startup with 10 hires, extremely product focused, especially with fintech integrations, and presumably a lot of PII as an insurance fintech? If a consultant isn't explaining the fairly large inherent risks there for the SMB/startup and using crypto as a comparison of something worse, that's wonky to me.