Ransomware Attacks on Small & Mid-Size Businesses: How to Actually Stop One

88% of small business breaches now involve ransomware, and most owners find out how vulnerable they are on the worst possible day. Here is what is actually happening in 2026, what an attack costs in real numbers, and the exact steps to close the gaps before an attacker finds them.

Category
Cybersecurity
Focus
Small Business Owners
Published by
Bunty
The Problem

Why Ransomware Attacks Are Surging Against Small Businesses in 2026

Attackers are not picking targets by name. They are scanning for open doors, and small businesses leave more of them unlocked.

Ransomware operators run their campaigns like a sales funnel: scan for exposed systems, unpatched software, and leaked credentials at scale, then work through whoever answers. Recorded Future threat analyst Allan Liska put it plainly in an interview about the mindset behind these attacks. The biggest mistake he sees at small and mid-size organizations is assuming they are not a target. In reality gangs go after vulnerabilities and opportunities, not specific company names, and only find out who they have hit after the fact.

That indifference is exactly why small businesses have become the preferred target. They typically run fewer layers of defense, patch less consistently, and rarely have a dedicated security team watching for the first signs of intrusion, while still holding the customer data, payment systems, and operational software that make an attack worth running.

+45%

rise in recorded ransomware attacks in 2025 vs 2024

350%

more social engineering attempts hit SMB employees than enterprise staff
StrongDM / TotalAssure 2026

181 days

median time a breach goes undetected inside a small business

This is not a hypothetical trend. In the last two weeks of August 2026 alone, CISA disclosed that Medusa ransomware affiliates had breached more than 500 organizations across critical infrastructure sectors, a UK power generator was taken offline for four days by a cyberattack, and medical device maker Boston Scientific confirmed a network outage after a cybersecurity incident disrupted the systems it uses to process and ship customer orders.

Real Examples

What Actually Happens When Ransomware Hits a Small Business

These are not hypothetical scare stories. They are what the last few years of ransomware attacks on small and mid-size businesses actually looked like.

Sherwood, Arkansas - The Heritage Company

A 60-year-old fundraising firm shut down for good

A ransomware attack encrypted the company’s servers. The firm paid the attackers to get its systems back, but the two months of disruption that followed proved too costly to absorb. Just before Christmas, all 300 employees were let go and the 60-year-old business closed permanently.

Impact

Paid the ransom. Business still closed permanently. 300 jobs lost.

Spring Valley, Illinois - St. Margaret's Health

A hospital’s billing system went dark and never fully recovered

A ransomware attack knocked out the hospital’s billing systems, which meant it could no longer submit claims to Medicaid, Medicare, or private insurers. Already financially strained after the pandemic, the hospital could not absorb months of unpaid claims on top of the attack, and it closed.
 

Impact

Months to restore systems. Lost insurer reimbursements during outage. Hospital closure.

United Kingdom - mid-size manufacturer, ~£9M annual revenue

A £9M UK manufacturer lost half a million pounds in two weeks

Attackers exploited the fact that its backups were not segregated from the main network, a common gap at businesses this size. Every critical system was encrypted within hours. The company could not trade, take orders, or access core files for more than two weeks and was forced to pay the ransom with no way to recover data independently.

Impact

14+ days offline. Approximately £500,000 in lost revenue. Ransom paid due to no working backup.

August 2026 - Boston Scientific

Right now: a global medical device maker is still recovering

Boston Scientific, which employs 59,000 people across 127 countries, identified a cybersecurity incident on August 25, 2026 that caused a network outage across its IT systems, disrupting the systems used to process and ship customer orders. As of the company’s latest update, the investigation with third-party responders is still ongoing.

Impact

Global order processing disrupted. Investigation ongoing as of publication.

The Real Cost

What a Ransomware Attack Actually Costs a Small Business

The ransom demand is rarely the biggest number on the bill.

The figure that scares business owners is the ransom demand, but it is usually the smallest part of the real cost. Downtime, forensic investigation, lost customers, legal exposure, and the labor of rebuilding systems from scratch typically dwarf the payment itself. That is exactly why prevention is so much cheaper than recovery.

✅ Prevention (Annual)

~$5K–$15K

  • MFA tools and setup
  • Backup solution (offline or immutable)
  • Staff phishing training
  • Cyber liability insurance
  • Patch management process

❌ Recovery (After Attack)

$638K+

  • Forensic investigation fees
  • 37 avg hours of downtime costs
  • Lost customers and revenue
  • Legal and regulatory exposure
  • Ransom demand on top of all this

37 hrs

average downtime per successful ransomware incident

Sophos / Programs.com 2026

60%

of small businesses close within six months of a serious cyberattack

40%

of SMBs say a $100K attack would put them out of business entirely
VikingCloud 2026
The Decision

Should Your Business Pay the Ransom? What the Data Actually Says

A side-by-side look at what tends to happen after each choice.

Outcome Pay the Ransom Don't Pay (Restore From Backups)
Full data recovery
Only ~4% recover all data
High, if backups are tested and segregated
Repeat attack risk
~80% are targeted again within 12 months
Significantly lower once the entry point is closed
Downtime
Days to weeks, plus decryption issues
Hours to days, if backups are ready to restore
Legal and insurance standing
Complicated, some insurers and regulators restrict payment
Cleaner claims process with most cyber policies
What it funds
Directly finances the next attack, on you or someone else
Nothing

64% of organizations now refuse to pay outright, and the businesses that fare best after an attack are almost always the ones that could restore from backups without needing to negotiate with anyone.

Data: Fortinet Ransomware SurveyVerizon DBIR 2025 via StationX Ransomware Statistics 2026

Ransomware Attacks on Small & Mid-Size Businesses: How to Actually Stop One?
The Fix

How to Protect Your Small Business From Ransomware: A Step-by-Step Plan

You do not need an enterprise security budget. You need these six things done properly, in order of impact.

01

Turn on multi-factor authentication everywhere

This is the single highest-leverage fix available. As then-CISA Director Jen Easterly put it on X, enabling multi-factor authentication makes an account roughly 99% less likely to be compromised. Apply it to email, banking, remote access, and any admin login, not just your most sensitive systems.

02

Keep backups that ransomware cannot reach

A backup connected to the same network as everything else gets encrypted right along with it. That is exactly what happened to the £9M UK manufacturer above. Keep at least one backup copy offline or in immutable cloud storage, and restore from it on a schedule to confirm it actually works.

03

Patch the software you actually use, on a schedule

Most successful attacks exploit known vulnerabilities that already had a patch available. Set a fixed weekly or monthly patch window for operating systems, VPNs, and any software that touches the internet, rather than patching reactively after a warning. CISA’s known exploited vulnerabilities catalog is a free resource to help prioritize.

04

Train employees to spot the click before it happens

Boston Scientific, which employs 59,000 people across 127 countries, identified a cybersecurity incident on August 25, 2026 that caused a network outage across its IT systems, disrupting the systems used to process and ship customer orders. As of the company’s latest update, the investigation with third-party responders is still ongoing.

05

Segment your network so one breach cannot become a total one

If a single compromised laptop can reach your customer database, your accounting system, and your backups, one phishing click becomes a company-ending event. Separate critical systems onto their own network segments with restricted access. This is a core principle of zero-trust security architecture.
 

06

Write the incident response plan before you need it

Decide now who calls the cyber insurer, who calls a forensics firm, who talks to customers, and who has authority to take systems offline. Businesses that have this mapped out in advance consistently recover faster than those improvising mid-attack. The NIST Cybersecurity Framework provides a free template to get started.
Ransomware Attacks on Small & Mid-Size Businesses: How to Actually Stop One?
Quick Self-Check

Ransomware Readiness Check: How Exposed Is Your Business?

Check off what is already in place. This is not a formal audit. It is a five-minute gut check.

Ransomware Readiness Checklist - Check What's In Place

✅ Multi-factor authentication is required on email and any remote-access or admin login
 
✅ We have a backup that is offline or immutable, not just another folder on the network
 
✅ We have actually restored data from that backup in the last 6 months to confirm it works
 
✅ Operating systems and internet-facing software are patched on a set schedule
 
✅ Employees have had phishing-awareness training in the last 12 months
 
✅ We carry cyber liability insurance
 
✅ We have a written incident response plan with named responsibilities
Already Hit?

Your First 24 Hours After a Ransomware Attack

What you do in the first few hours has more effect on the outcome than almost anything after it.

0 to 30 min

Disconnect affected devices from the network

30 to 90 min

Call your incident response team and cyber insurer

2 to 8 hrs

Preserve evidence, check backup integrity, notify law enforcement

8 to 24 hrs

Brief employees and customers, begin restoration

Organizations that loop in law enforcement early save an average of $990,000 per incident compared with those that do not, according to IBM’s Cost of a Data Breach research. Reporting the attack is not just a formality, it materially changes the outcome. You can report to the FBI’s IC3 or your local law enforcement cybercrime unit.

Ransomware Attacks on Small & Mid-Size Businesses: How to Actually Stop One?
Expert Voices

Ransomware, in the Words of the People Who Track It

What you do in the first few hours has more effect on the outcome than almost anything after it.

The biggest mistake I see at small and mid-size organizations is assuming they are not a target. Ransomware groups mostly go after software they can exploit, credentials that have leaked, or a clicked phishing email. Who the victim turns out to be is not something they think about until after the attack.
Allan Liska, ransomware researcher at Recorded Future · @uuallan on X
Enabling multi-factor authentication makes you roughly 99% less likely to get hacked.
Jen Easterly, then-Director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA) · @CISAJen on X

FAQs

Why do ransomware gangs target small and mid-size businesses?
Ransomware operators mostly hunt for exploitable software, leaked credentials, and clicked phishing links rather than picking specific companies by name. Small and mid-size businesses tend to run weaker patching and have no dedicated security staff, which makes them easier to hit even though each individual payout is smaller than an enterprise breach.
 
Most incident responders and law enforcement agencies advise against it. Paying does not guarantee full data recovery, a large share of businesses that pay are attacked again within a year, and the payment funds the next attack. Tested, segregated backups remove the pressure to pay in the first place.
Recovery costs commonly run from the low hundreds of thousands into several million dollars once downtime, forensics, lost revenue, and reputational damage are included, usually far more than the ransom demand itself.
Many do, but a large share of small businesses that suffer a serious cyberattack close within six months, typically from cash-flow disruption rather than the ransom. Businesses with tested backups, cyber insurance, and a written incident response plan recover meaningfully faster.
Bottom Line

Prevention Costs $5K. Recovery Costs $638K.

The gaps that let ransomware in, no MFA, backups on the same network, unpatched software, untrained employees, are all fixable before an attacker finds them. Every day you wait is a day the door stays open.

Table of Contents

Not sure where your business actually stands?

Bunty and the TechBunty team can review your setup, close the gaps that matter most, and help you build a backup and response plan that actually works when you need it, not just on paper.

181 days. That is how long the average breach goes undetected in a small business. Is yours already compromised?
Scroll to Top