Human error in cybersecurity incidents is consistent in the majority of successful attacks. Phishing, credential theft, accidental data exposure, and social engineering all share a common requirement for success, which is that a person on the other end of the screen makes a decision that benefits the attacker.
This problem scales differently for smaller organizations, and that is what makes it especially pressing for SMBs. Leaner teams typically mean individuals hold access to multiple critical systems, so a single successful deception can compromise far more than it would at a company with more segmented access controls.
The relationship between company size and security exposure means that attackers follow the path of least resistance, and in most organizations that path runs through people far more reliably than through technology. Investing in security infrastructure without investing in the behavior of the people operating within it is an incomplete strategy.