Tech

Why Small Businesses Get Hit by Ransomware (and How to Close the Gaps)

0

Four out of five times I ask a small business owner when they last tested their backups, they shrug. That shrug is exactly what attackers are looking for. Here’s the uncomfortable truth: most small businesses don’t get breached by genius hackers.

They get breached because someone clicked a link, reused a password, or forgot a server existed. The fix isn’t one giant purchase. It’s a handful of boring, repeatable habits most companies skip because nobody makes them do it. This piece walks through where ransomware actually enters, which gaps attackers check first, and what a realistic cleanup looks like for a business under 200 people. No jargon, no scare tactics. Just the stuff that works.

Where ransomware actually gets in

Attackers don’t break in. They log in. According to the Cybersecurity and Infrastructure Security Agency, compromised credentials remain one of the most common initial access vectors in ransomware incidents. That means the front door isn’t a firewall problem. It’s a password problem.

Think about how your team actually works. Someone in accounting uses the same password for the payroll portal and their personal Gmail. A project manager approves an MFA prompt at 11 pm because they’re tired and assume it’s them. A contractor shares a login with a subcontractor because “it’s just faster.” None of those people are stupid. They’re busy. And busy people take shortcuts.

The second most common entry point is software nobody’s watching. That plugin you installed on the website three years ago, the old VPN appliance in the closet, the Windows Server running a line-of-business app that only one vendor supports. Attackers scan for these constantly. A patch released in March is worthless to you in November if nobody applied it.

I’d rather defend a business with five boring tools and disciplined users than one with twenty tools and no policy. Tools don’t close gaps. People do.

Why your backup isn’t the safety net you think it is

Every owner I’ve talked to says the same thing: “We’re fine, we have backups.” That’s the sentence that keeps incident responders employed.

Ask three specific questions. First, are your backups offline or immutable? If they’re connected to the same network, modern ransomware will encrypt them along with everything else. Second, have you restored one in the last six months? A backup that hasn’t been tested is a hope, not a plan. Third, how long would a full restore take? If the answer is “a week,” that’s a week of payroll, invoicing, and customer emails that don’t happen.

The National Institute of Standards and Technology treats recoverability as a core function of its cybersecurity framework for exactly this reason. Backup isn’t the finish line. Restoring fast enough to keep the business running is. Here’s the part that catches people: ransomware crews now spend days or weeks inside a network before they pull the trigger. They map your systems, steal data first, then encrypt. By the time the ransom note appears, they already have what they came for. Detection speed matters far more than most owners realize.

What a real cleanup looks like

You don’t need a Fortune 500 budget. You need to close the loudest gaps first. Here’s the order I’d work in for a business your size.

  1. Turn on MFA everywhere. Email, VPN, banking, cloud apps. Every account that can log in remotely gets a second factor. No exceptions for the CEO.
  2. Kill reused passwords. Roll out a password manager. Require unique credentials for every business system.
  3. Patch on a schedule. Not “when we remember.” A calendar date, every month, with someone accountable for it.
  4. Isolate and test backups. One copy offline, one copy offsite, and a restore drill on the calendar.
  5. Turn on endpoint detection. Antivirus signatures don’t catch what attackers use today. Behavior-based monitoring does.
  6. Train your people quarterly. Short, specific phishing simulations tied to real scenarios beat a 40-minute annual video nobody watches.

Notice what’s missing from that list: a giant firewall project. Firewalls matter, but they’re not where most small business breaches start. They start with a login.

If your team doesn’t have someone who owns security full-time, outsourcing the monitoring layer is often cheaper than hiring. That’s a big part of why so many companies end up evaluating network security services in Minneapolis or their own metro, where a managed provider can run 24/7 detection while the internal team handles day-to-day IT.

What ransomware actually costs when it lands

Owners tend to think about the ransom number. The ransom is the smallest line item.

According to IBM, downtime and lost business typically represent the largest share of breach costs, well above the payment itself. Add forensic investigation, legal fees, regulatory notifications, customer churn, and the weeks your team spends recovering instead of selling. Then add the reputational hit, which is harder to price but very real when your biggest client asks why their invoices went quiet for two weeks. That last part is what I’d worry about most. Small businesses don’t usually die because they paid a ransom. They die because they lost six weeks and a handful of customers they couldn’t afford to lose.

A simple weekly routine that holds up

You don’t need a security operations center to stay ahead. You need a rhythm. Here’s what a healthy week looks like for a 30-person shop.

  • Monday: review the patch status on servers and network gear. Anything missed gets scheduled the same week.
  • Tuesday: check backup job reports. Flag failures the same day, not next quarter.
  • Wednesday: review failed login attempts and MFA prompts. Anything odd gets investigated.
  • Thursday: spot-check a phishing email with one employee. Five-minute conversation, real learning.
  • Friday: confirm the offline backup ran and was stored correctly.

That’s maybe two hours a week total. Compare that to the cost of a two-week shutdown.

One thing I’d push back on: don’t treat cyber insurance as a substitute for any of this. Insurers increasingly require documented controls, MFA, and tested backups before they’ll pay a claim. The paperwork is real, and the questions on those forms are the same ones attackers are asking.

Where to start this week

Pick one item from the list above and finish it before Friday. MFA on email is usually the fastest win with the biggest reduction in risk. Then schedule the backup restore test for next month, because that one always slips. You’ll never make your business unhackable. That’s not the goal. The goal is being harder to hit than the next company, and there are thousands of companies doing nothing. A handful of disciplined habits puts you past almost all of them. What’s the one gap you already know you’ve been ignoring?

Tongue Weight, Axle Placement, and Where to Put the Skid Steer: Loading a Trailer So It Doesn’t Sway

Previous article

You may also like

Comments

Comments are closed.

More in Tech