Ransomware Is Hitting Small Business Harder Than You Think
June 5, 2026 · 6 min read
There's a persistent myth that ransomware gangs only go after big companies with deep pockets. It's wrong — and it's getting small businesses hurt. Companies with fewer than 1,000 employees are now the primary targets, not because they're worth more, but because they're easier to breach.
Small businesses are the target, not the collateral
This isn't fear-mongering — these are documented trends. Ransomware groups have shifted their focus to SMBs because the attack surface is softer. They know most small businesses don't have dedicated security teams, don't patch consistently, and often have RDP or VPN appliances exposed to the internet with default or weak configurations. A mid-sized manufacturing company or a 30-person accounting firm is a higher-percentage play than a Fortune 500 company with a 24/7 SOC.
Ransom demands for SMBs now routinely land in the $100,000+ range. Some go much higher. And the ransom is only part of the cost. The average downtime after a ransomware attack for a small business is three weeks or more — three weeks without email, without file access, without the ability to invoice clients or process payroll.
How they get in
The three most common entry points we see are predictable, and they're all preventable. Unpatched VPN appliances are at the top of the list — attackers scan the internet for known vulnerabilities in widely-used VPN products and walk right in. RDP exposed to the internet is another gift to attackers; once they guess or brute-force the password, they have full remote control of a machine inside your network. Phishing emails round out the top three, and they've gotten better — the days of Nigerian prince emails are long gone. Today's phishing emails spoof real vendors, real invoices, and real-looking Microsoft 365 login pages.
Double extortion is the standard now
Since roughly 2020, the dominant ransomware tactic has been double extortion: the attacker encrypts your data and steals a copy. If you refuse to pay to get your files back, they threaten to publish your client records, financial data, and employee information online. Even if you have good backups and can restore without paying, you still face a data breach with all the notification requirements and reputational damage that comes with it.
The FBI and CISA strongly recommend against paying the ransom. Paying funds future attacks, and there's no guarantee you'll get your data back or that the stolen copy will actually be deleted. We've seen cases where businesses paid and were hit again by the same group six months later — they knew the victim would pay.
What protection actually looks like
The good news is that the defenses that work against ransomware are well-understood and don't require a six-figure security budget. They do require consistency.
Practical protection steps
- ✓Patch management — VPN appliances, firewalls, and any internet-facing systems need updates applied within days of release, not months
- ✓Offline or immutable backups — ransomware explicitly hunts for backup files and connected backup drives. At least one copy needs to be physically disconnected or write-protected
- ✓Network segmentation — if an attacker compromises one workstation, they shouldn't have a straight shot to your servers, backups, and financial data
- ✓MFA on everything — email, VPN, RDP, cloud apps, and any administrative accounts. No exceptions
- ✓Endpoint Detection and Response — traditional antivirus doesn't catch modern ransomware. EDR monitors for the behavioral patterns that signature-based tools miss
None of these steps are complicated on their own. What trips businesses up is that you need all of them, not just one or two. A company with great backups but no MFA is still one guessed password away from a breach. A company with MFA everywhere but no tested backups is still staring at a $100,000 ransom demand with no way out.
If you haven't reviewed your ransomware defenses in the last year, now is the time. An hour spent closing the obvious gaps could save your business from three weeks of downtime and a six-figure recovery bill.
