Ransomware is malicious software that locks a business out of its own files and systems and then demands payment to restore access — and in most modern cases the attacker copies the data out before locking anything. That second half is what changed: recovery is no longer only about getting files back, because a copy of them already sits somewhere else.
There is a myth that this is a big-company problem. The opposite is true. Attackers increasingly look at small and medium businesses precisely because they assume — often correctly — that no one is watching closely, that backups are shaky, and that there is no dedicated security team. A single successful attack can freeze operations for days and cost far more than the ransom itself. Understanding how these attacks actually unfold is the first step to stopping them.
Verizon's 2026 report puts ransomware in 48% of all breaches — while noting that payouts are shrinking, as more organisations decline to pay. Both halves matter: it is common, and paying is becoming less normal.
Figure verified 31 July 2026. Source linked above.
How does a ransomware attack actually unfold?
Almost always in the same order, and rarely with anything resembling dramatic hacking. Access usually comes from an ordinary opening: a convincing phishing email, a password reused from an unrelated breach, or a remote-access service left reachable from the internet. From there the attacker moves quietly, collecting credentials and mapping what matters. Sensitive files are copied out before anything is locked, which is what makes double extortion possible. Encryption comes last, because it is the only step that announces itself.
By the time the ransom note appears, the quiet work is finished — the access, the mapping, and the copy of your data all came first.
Which controls actually stop most attacks?
A short list of fundamentals, none of which needs an enterprise budget. The measures that block most small-business ransomware are unglamorous, well understood, and mostly one-time work.
Offline, tested backups come first. Keep at least one copy that ransomware cannot reach — genuinely offline, or in storage that cannot be overwritten — and then restore from it as a rehearsal. A backup nobody has ever restored is a hope rather than a plan.
Multi-factor authentication on email, remote access and administrator accounts takes the value out of a stolen password, which is the most common way in. If you change one thing this month, change that one.
Updates on internet-facing systems matter next. Remote access services, firewalls and web servers are the doors tried first, so keep them current and switch off anything you do not actively use. Fewer administrator accounts then limits what any single compromise is worth.
What should you do in the first hour if you are hit?
- Isolate the affected machines. Disconnect them from the network and from shared storage so that encryption stops spreading. Where you can, leave them powered on — useful evidence lives in memory and helps whoever investigates.
- Do not rush to pay. Payment funds the next attack, does not guarantee that files come back intact, and does nothing about data that has already been copied out. It is a business decision to weigh calmly with advisors, never a reflex.
- Bring in help early. Engage incident-response professionals, notify your insurer if you carry cyber cover, and check what the law requires you to report and by when. Those notification deadlines are often short.
- Write down what you see. Times, screens, affected systems, and anything unusual in the days before. That record shortens the investigation and supports any claim you make later.
Where should a small business start?
With the handful of steps that close the openings attackers rely on most, in the order that gives the most protection for the least disruption. None requires a security specialist or a new platform, and each is a change you make once and then largely leave alone. Work down the list rather than attempting all of it in one week.
| Step | What it closes off | Typical effort |
|---|---|---|
| Multi-factor on email and remote access | The stolen or reused password, the most common way in | An afternoon, no budget |
| One backup copy out of reach | Encryption of every copy at once, including the backup | A day to set up, small monthly cost |
| A rehearsed restore | The backup that turns out not to work when it is needed | Half a day, twice a year |
| Updates on anything internet-facing | Known weaknesses in the systems reachable from outside | Ongoing, mostly automatic |
| A one-page response plan | Lost hours and bad decisions on the worst possible morning | An hour, reviewed yearly |
The bottom line
Ransomware succeeds on unlocked doors: no multi-factor authentication, unpatched internet-facing systems, and backups nobody has tested. Close those and most of your real-world risk goes with them. The harder question is which doors are open right now, which an external review answers.