What actually goes wrong
The incidents small businesses get hit by are boring, repetitive, and largely preventable.
An account with no second factor
Somebody reuses a password, that password turns up in an unrelated breach, and a stranger signs in successfully. Multi-factor authentication is the control that makes a stolen password worthless on its own, it is included in what you already pay for, and it is skipped more often than any other setting.
A leaver who never really left
The laptop came back. The accounts did not. Months later nobody can say for certain what a former employee can still reach, and the answer is often the email, the file storage and the shared logins.
Everyone is an administrator
Access gets granted in a hurry and never reviewed, so over a few years everybody accumulates everything. It is not malice, it is drift, and it means one compromised account is a compromise of the whole business rather than one person's mailbox.
A mailbox rule nobody put there
One of the first things an intruder does in a business mailbox is create a quiet forwarding or delete rule, then wait for an invoice conversation. This is how a payment gets redirected, and the account owner sees nothing unusual because the messages are being moved before they read them.
Devices that were handed out, not managed
A laptop set up out of the box, holding company mail and files, with no encryption anyone verified and no way to wipe it if it goes missing. It works fine right up until it is left somewhere.