Small businesses survive ransomware attacks on the strength of four basics: backups kept offline or immutable, multi-factor authentication on email and remote access, prompt patching of known-vulnerability software, and staff trained to recognize phishing — controls that cost little relative to one incident. FBI Internet Crime Report data has for years shown tens of thousands of reported ransomware and business-email-compromise incidents with losses in the billions, and small organizations are heavily represented among victims precisely because attackers assume weaker defenses. This guide explains the threat and the defense stack in small-business terms.
Business News 7 publishes information, not security or legal advice; incident response planning deserves professional input for businesses with real exposure.
How Does an Attack Actually Start?
Most small-business intrusions begin with one of two doors. The first is phishing: an employee enters credentials on a convincing fake login page, handing attackers a working mailbox, from which they pivot to payment fraud or launch ransomware. The second is unpatched, internet-facing software — firewalls, remote-access tools, servers — where known vulnerabilities are scanned automatically by attackers around the clock. Neither door requires sophistication to close; both are closed by the controls in the next section. Once inside, attackers typically spend days or weeks escalating access, exfiltrating data, and only then detonating encryption — which is why early anomalies matter and why offline backups are the control of last resort.
What Does the Defense Stack Look Like?
- Offline or immutable backups: a copy of critical data that ransomware cannot reach — separated credentials, offline media, or immutable cloud storage — tested by an actual restore at least quarterly. An untested backup is a hope, not a control.
- Multi-factor authentication (MFA): enabled on email, VPNs, administrator accounts, and cloud platforms. MFA defeats the overwhelming majority of credential-theft entry points, including phishing pages that capture passwords.
- Patching cadence: a monthly routine applying updates to operating systems, browsers, and especially anything exposed to the internet; known-vulnerability exploitation is the classic second door.
- Staff training: short, repeated phishing recognition drills and a no-blame reporting channel, because a employee who reports a suspicious email within minutes converts an incident into a non-event.
Complementary measures — email filtering, endpoint detection software, least-privilege account practices, and disabled or time-limited remote desktop exposure — strengthen the stack but do not replace the four pillars.
What Should the Response Plan Contain?
Written before an incident, the plan can fit on one page: who decides whether to isolate machines, how to disconnect and shut down (pulling the network plug early can stop encryption mid-spread), which authorities to contact — the FBI and CISA both accept reports, and many states require notification of affected data — who speaks to customers, and whether cyber insurance is in force and what it requires. The decision whether to pay a ransom is a business and legal question with no good options: payment funds the attacker, offers no guarantee of working decryption or deleted data, and may carry sanctions exposure if the attacker is a designated entity. Businesses with tested backups rarely face the question at all, which is the strongest argument for the backup pillar.
What Does Recovery Look Like?
Reconstruction from backups is measured in days when the restore has been rehearsed and in weeks when it has not. After restoration, the business must close the entry point — resetting credentials wholesale, patching the exploited system — or the attacker returns. Post-incident obligations can extend beyond the network: customer notification, regulatory filings, and card-brand requirements if payment data was involved. The documented difference between businesses that weather an attack and those that close afterward usually traces to two things: whether data existed somewhere the attacker could not reach, and whether anyone had practiced using it.
The lesson: ransomware defense is not a product purchase — it is offline backups, MFA, patching, and trained people, rehearsed before the day the phone rings.
For more context, read How to Close a Business in Good Order.
For more context, read Why Profitable Small Businesses Still Run Out of Cash.
For more context, read Which Insurance a Small Business Actually Needs.
