Skip to content

WHT Cyber  /  Field Notes  /  SMB Guide

SMB Guide

The Charlotte SMB threat landscape: what we're seeing in NC right now.

Anonymized patterns from incidents across Charlotte-area small and midsized businesses in the first half of 2026 — which industries are getting hit, what the attackers are doing, and what closes the gap.

By WHT Cyber Engineering July 7, 2026 8 min read

Charlotte's business economy runs on financial services, healthcare, construction and trades, real estate, professional services, and manufacturing. Every one of those verticals has been targeted this year. What surprises most local owners we talk to is how ordinary the attacks are — not sophisticated nation-state operations, just criminals running proven playbooks against businesses that assumed they were too small to be interesting.

This is a summary of the patterns we've observed across our client base and the incidents we've been called into so far in 2026. All specifics are anonymized; the goal is to give local owners a realistic view of what's actually happening in the Charlotte metro right now.

Who's getting hit

Attackers don't care much about industry classification codes. They care about two things: is there money to steal or freeze, and how easy is it to get in. That said, the incidents we've seen cluster around a few verticals.

Registered investment advisers and small financial firms

Small and midsized RIAs have been prime targets all year. Attackers know these firms handle large wires, hold client PII, and are under new regulatory pressure from the SEC's amended Regulation S-P, which requires 30-day breach notification to clients as of June 3, 2026. The typical attack: business email compromise leading to a fraudulent wire request or an ACH change against a client account.

Healthcare (dental, small clinics, behavioral health)

Small practices continue to be attractive. Attackers target patient records for identity theft resale, and increasingly, they use ransomware to force fast payment because downtime directly stops patient care. HHS breach reporting data (HHS OCR Breach Portal) shows a steady stream of small-practice incidents in North Carolina.

Construction, trades, and specialty contractors

The Charlotte building boom has made local contractors a target for wire-fraud attacks tied to project payments. Common pattern: a fake “change of banking info” email from a supposed subcontractor, sent right before a scheduled payment. Six-figure losses are typical here because a single wire covers a project draw.

Real estate and title

Wire-fraud attacks against closing funds continue to be one of the highest-loss categories, tracked in the FBI's IC3 Annual Report. Charlotte's residential and commercial closing volume makes this an ongoing target.

Manufacturing and distribution

Ransomware crews continue to hit small manufacturers because production downtime creates immediate pressure to pay. NC's cluster of specialty manufacturers around the metro has seen its share this year.

How they're getting in

The initial-access methods are boringly consistent. There is almost never anything novel about them.

1. Phished or stolen credentials, no MFA

Still the #1 entry point. An employee clicks a phishing link that looks like a Microsoft 365 login page, enters their credentials, and the attacker is inside within minutes. Where MFA is missing entirely, or configured only for “risky sign-ins,” the account is compromised silently and the attacker sets up a hidden inbox rule to hide their tracks.

2. Compromised vendor mailboxes

Even businesses with strong internal controls get hit through a legitimate vendor whose mailbox was compromised. The attacker replies inside a real email thread, from the real vendor's real address, with a “we've updated our bank info” message. There is nothing wrong with the email — because it is genuinely coming from the vendor.

3. Exposed remote access

Small businesses running RDP on port 3389 open to the internet, unpatched VPN appliances, or aging remote-management tools continue to be found through automated scanning. Ransomware crews buy this access from initial-access brokers for a few hundred dollars.

4. Unpatched public-facing systems

Old on-premises Exchange servers. VPN appliances with known CVEs. File-transfer software with public exploits. CISA's Known Exploited Vulnerabilities catalog reads like a shopping list for the flaws we still see unpatched at Charlotte SMBs.

5. Insider or ex-employee access

The person who quit six months ago still has an active login somewhere. Sometimes it's an old SaaS account no one thought to remove. Sometimes it's a shared credential from a departed IT contractor. Offboarding gaps show up in a surprising share of incidents.

What they do once inside

The post-access playbook is nearly identical across incidents:

  • Enumerate the environment quietly for a few hours to a few days.
  • Set persistence — inbox rules, mail forwarding, OAuth grants to attacker-controlled apps, new admin accounts, or scheduled tasks on servers.
  • Escalate to admin, disable EDR/AV where they can, and start hunting for financial data or files worth encrypting.
  • Execute — a fraudulent wire, a ransomware detonation, or data exfiltration for extortion.

The whole cycle, in most Charlotte SMB incidents we've seen, runs from a few hours to a few days. That's the window where detection either happens or it doesn't. It's not a window for a helpdesk that opens Monday morning.

What's working locally

The Charlotte businesses that avoid incidents — and the ones that catch incidents early enough to contain them — share a small number of controls. None of these are exotic:

  • Phishing-resistant MFA on email, finance, and admin accounts. Not SMS. Number-matching push at minimum, hardware keys for admins.
  • Real EDR or MDR on every endpoint and server, with a 24/7 SOC behind it. Not just antivirus.
  • Enforced DMARC at p=reject with SPF and DKIM aligned. Kills a large share of domain-spoofing attempts before they hit inboxes.
  • Immutable, segmented backups that an attacker with admin credentials can't reach.
  • A callback rule for banking changes and wire requests. Written, signed, followed by everyone including the owner.
  • An offboarding checklist that actually gets used the day someone leaves.
  • Patched, supported systems facing the internet. If it's end-of-life, replace it before someone else finds it.

These controls are not expensive. They are, however, easy to defer — which is why so many incidents happen at businesses that intended to get around to them.

What WHT recommends

If you're a Charlotte-area SMB and you want a realistic 30-day plan to close the gaps we see most often locally, do these in order:

  1. Week 1 — Audit MFA everywhere. List every account with access to email, finance, remote access, backups, and admin functions. Any account still on SMS-only MFA or no MFA gets upgraded within seven days.
  2. Week 1 — Write and send the callback rule. One paragraph. Any request to change banking, send an out-of-pattern wire, share credentials, or grant new access requires a callback on a number from your own records. From anyone, including the owner.
  3. Week 2 — Confirm EDR is on every endpoint. Not antivirus. A real EDR product with a SOC behind it. Verify coverage on every laptop and server — missed endpoints are how ransomware still spreads.
  4. Week 2 — Check DMARC. Run a DMARC report. If you're at p=none, plan the move to p=quarantine and then p=reject over the next 60 days.
  5. Week 3 — Audit backups. Are they immutable? Are they on separate credentials from your production domain? When was the last full restore test? If you can't answer the third question, fix that first.
  6. Week 3 — Run an offboarding audit. Every employee who left in the last 12 months. Confirm every account — email, VPN, SaaS, shared systems — is disabled.
  7. Week 4 — Patch what's exposed to the internet. Any public-facing system. Firmware on firewalls and VPN gear. Anything on the CISA KEV list gets fixed this week.

The bottom line

The Charlotte SMB threat picture in 2026 is not exotic. It's phished credentials, compromised vendors, exposed remote access, and old servers — combined with the assumption that “we're too small to be a target.” The businesses that get hit are usually the ones that knew about the gaps and didn't get around to them. The businesses that don't get hit share a small, boring set of controls that anyone can implement in a month.

If you're not sure where you stand locally, that's what an outside opinion is for.

Want a Charlotte-specific gap assessment?

We'll walk through your environment with the local threat patterns in mind, tell you which of the seven controls above are actually in place, and give you a prioritized list. 45 minutes. No pitch.

Book the assessment More Field Notes →