It's a good question. Crypto companies aren't a monolith, but using crypto as a comparison to an SMB, and in this case sounds like SMB==startup, then requires some nuance if you want facts behind that claim.

SMB vs. web3/Defi, 30 person teams, no security engineers? The web3 company probably is a lot more vulnerable.

SMB/startup vs. generic crypto exchange like Poloniex? This gets harder to parse. Poloniex gets the malicious traffic and has a pretty small security team I think. But, they and companies similar are a tech company in the cloud and with a solid infra engineering team and leveraging AWS tooling, it's not like they're totally exposed. The SMB/startup has none of this, so arguably they are a similar risk profile in surprising ways, or maybe even more exposed than the exchange.

SMB/startup vs. a Tier 1 exchange like Coinbase? Very silly comparison, CB has a pretty large security team, knows their stuff, etc. etc, very good track record until very recently, and as a industry group the Tier 1 exchanges do well on the security front.

Compare this to the SMB instances of malware sitting on a Point-of-sale system for months/years until it gets discovered? Family dentists getting ransomwared fairly consistently? The retail/SMB space is a bit of a security nightmare. For someone building a product here and is able to sell the "so what" of it to a dentist, there's opportunity. If SMB == startup, well that's likely a startup with 10 hires, extremely product focused, especially with fintech integrations, and presumably a lot of PII as an insurance fintech? If a consultant isn't explaining the fairly large inherent risks there for the SMB/startup and using crypto as a comparison of something worse, that's wonky to me.