← All field notes
Cyber

Ransomware Risks for Small Businesses

Ransomware is the cyberattack that turns the lights off. It encrypts your files and systems and demands payment to restore them — and for a small business that runs on those systems, it can mean no access to records, no operations, and no revenue overnight. The businesses that survive it aren't the ones that pay fastest; they're the ones that prepared, with backups and coverage in place before the screen ever locked.

How ransomware works

An attacker gets into your systems — usually through a phishing email, stolen credentials, or an unpatched vulnerability — and deploys malware that encrypts your data. You're locked out, and a ransom is demanded (typically in cryptocurrency) for the key to unlock it. Many modern attacks add a second threat: they steal a copy of your data first and threaten to leak it if you don't pay, so even good backups don't fully resolve the extortion. Common cyber threats.

Why small businesses are targets

Small businesses assume ransomware hunts big corporations. In reality, attackers favor smaller targets because they tend to have weaker defenses, no dedicated security team, and a desperate need to get operating again — which makes them more likely to pay. Automated attacks also scan broadly and don't care about company size. Being small is not protection; it can be the very thing that makes you attractive. Does your small business need cyber?

What it actually costs

The ransom is often the smallest part. The real costs stack up:

  • Downtime — every hour systems are locked is lost revenue and stalled operations, sometimes for days or weeks.
  • Recovery — restoring systems and data, even from backups, takes time and expertise.
  • Forensics and response — determining the scope and closing the hole.
  • Notification and liability — if data was stolen, breach notification and potential claims follow.
  • Reputation — customers learning their data was held hostage.

For a small business with thin reserves, this cascade can be existential. What does cyber cover.

The backup that decides everything

The single most important defense against ransomware is tested, offline (or immutable) backups. If you can restore your systems from clean backups the attacker couldn't reach, you have options the attacker can't take away — you're not forced to pay just to get operating again. The catch is in the details: backups that are connected to the network can be encrypted too, and backups never tested often fail when you finally need them.

Think of backups like a spare set of house keys kept somewhere the burglar can't reach. Keeping the spare on the same keyring inside the house defeats the purpose — and a spare you've never checked might not even fit the lock. Offline, tested, and separate is what makes a backup actually save you. Cybersecurity best practices.

How to prepare

  • Maintain offline, tested backups — the foundation of ransomware resilience.
  • Enable multi-factor authentication — blocks many credential-based entries.
  • Patch systems promptly — closes the vulnerabilities attackers scan for.
  • Train employees on phishing — the most common entry point.
  • Have a response plan — know who to call and what to do. Data breach response guide.
  • Carry cyber insurance — many policies cover ransomware response, recovery, downtime, and breach costs. What is cyber liability.

Should you pay the ransom?

This is a fraught decision with legal, ethical, and practical dimensions — paying doesn't guarantee recovery, funds criminal activity, and may carry legal restrictions depending on who's behind the attack. It's exactly the kind of decision you don't want to make alone in a panic. Cyber insurers and their response teams help navigate it, which is another reason coverage and a plan matter. How cyber claims are handled.

Frequently asked questions

  • Malware that encrypts your files and systems and demands payment to restore access. Many attacks also steal data and threaten to leak it, adding extortion on top of the lockout.
  • Small businesses often have weaker defenses, no dedicated security team, and an urgent need to resume operations — making them attractive, more likely to pay targets. Automated attacks also don't discriminate by size.
  • Tested, offline backups are the foundation — they let you restore without being forced to pay. Combine with multi-factor authentication, patching, employee training, and a response plan. Cybersecurity best practices.
  • Many cyber policies include ransomware/cyber extortion coverage for response and recovery, though terms, limits, and any restrictions vary. Confirm the specifics with your policy. What does cyber cover.
  • It's a complex decision — paying doesn't guarantee recovery, funds crime, and can carry legal restrictions. Don't decide alone; cyber insurers and response teams help navigate it. How cyber claims are handled.

Put it into practice

Bring us your current policy.

We'll mark up the gaps this article describes, line by line, no charge, no commitment.