Skip to content
All resources
CybersecurityMarch 18, 2026·5 min read

How Small Businesses Get Hit by Ransomware (and How to Stop It)

Ransomware is one of the costliest threats facing SMBs today. Learn the common ways attacks start and the layered defenses that keep your business resilient.

By Cohesive Security

Ransomware encrypts your files and demands payment to get them back. For a small business, an attack can mean days of downtime, lost data, regulatory headaches, and a serious hit to customer trust. Understanding how these attacks start is the first step to stopping them.

Key takeaways:

  • Most ransomware gets in through phishing emails, stolen or reused passwords, unpatched software, or exposed remote access, and all four are preventable.
  • No single tool stops ransomware. Resilience comes from layers: prevent the break-in, detect and contain it fast, and recover cleanly.
  • Immutable, regularly tested backups are the single most important defense, because they leave the attacker with nothing to bargain with.
  • Security professionals and law enforcement advise against paying the ransom whenever possible.

How most ransomware attacks begin

Despite the dramatic headlines, the entry points are usually mundane:

  • Phishing emails. A convincing message tricks an employee into clicking a link or opening an attachment that installs the malware.
  • Stolen or weak credentials. Attackers log in to remote-access tools using passwords bought, guessed, or reused from another breach. Nothing gets “hacked” in the movie sense. Someone signs in.
  • Unpatched vulnerabilities. Known flaws in software that was never updated give attackers a way in.
  • Compromised remote desktop (RDP). Exposed remote-access services are a favorite target, because they are reachable from anywhere and often protected by a password alone.

Notice the pattern: these are preventable. The same handful of controls block nearly all of them.

The attack starts long before the files lock

The encryption is the ending, not the beginning. In most cases an attacker has been inside for days or weeks first, and understanding that changes what you defend.

Once in, they look around. They work out what your systems are, where the valuable data sits, and which account has administrator rights. Then, before encrypting anything, they do two things that matter to you. They find your backups and try to delete or encrypt those first, because backups are the thing that would let you refuse to pay. And they copy data out, so that even if you recover cleanly they can threaten to publish it. That second move is called double extortion, and it is why “we have backups” is a necessary answer rather than a complete one.

The practical consequence: a backup that your everyday administrator account can delete is a backup an attacker can delete. It needs to be beyond reach, and we walked through the ways that goes wrong in do your backups actually work.

A layered defense

No single tool stops ransomware. Resilience comes from layers that each catch what the others miss.

Prevent the initial compromise

  • Email security and anti-phishing to filter malicious messages before they land.
  • Multi-factor authentication so a stolen password isn’t enough to log in. Worth knowing that not all MFA is equal: the kind where someone types a code can still be phished.
  • Patch management to close known vulnerabilities quickly.
  • Security awareness training so your team recognizes the bait. Our Spot the Phish quiz is a free way to see how your team does today.

Detect and contain

  • Endpoint detection and response (EDR) to spot malicious behavior and isolate affected devices automatically.
  • 24/7 automated monitoring and alerting so a 2 a.m. attack is detected and contained automatically, not discovered the next morning.

Recover no matter what

This is the layer that turns a catastrophe into an inconvenience:

  • Immutable, offsite backups that ransomware can’t encrypt or delete.
  • A tested recovery plan with clear targets for how much data you can afford to lose and how long you can afford to be down (recovery point and recovery time objectives, RPO and RTO).
  • Regular restore drills so you know your backups work before you need them.

If you can restore clean data quickly, the attacker has nothing to sell you. That’s why backup and recovery is the cornerstone of ransomware resilience.

Should you ever pay the ransom?

The consensus among security professionals and law enforcement is to avoid paying whenever possible. Payment funds future attacks, marks you as a willing target, and offers no guarantee you’ll actually get your data back. Decryption tools supplied by attackers are often slow and incomplete, so even a cooperative extortionist rarely hands you a clean recovery.

It is worth being clear-eyed about what payment does and does not buy. It might get you a decryption key. It cannot un-copy data that has already left your network, which is why a ransom demand and a data breach are increasingly the same event, with the notification obligations that follow.

A solid backup-and-recovery strategy means you shouldn’t have to make that choice at all.

If it happens: the first hour

Improvising here is expensive, so decide the sequence now while nothing is on fire.

Disconnect affected machines from the network, but do not power them off: shutting down can destroy evidence that helps identify what got in and what was taken. Call whoever handles your IT and security before touching anything else. Report it, in the US to the FBI. Tell your insurer early, because most cyber policies require prompt notification and many provide an incident response team you have already paid for. Then work from your written plan rather than your memory.

The businesses that come through this well are not the ones with the best luck. They are the ones who had a plan, knew who to call, and had backups nobody could reach.

Build resilience before you need it

The businesses that weather ransomware best are the ones that prepared in advance: layered prevention, fast detection, and recovery they have actually tested. The ones that struggle are those who assumed it wouldn’t happen to them.

Building those layers is what our cybersecurity service covers, and the recovery half sits in backup and disaster recovery. Neither is complicated. Both need someone to own them.

Want to know how your business would hold up against a ransomware attack? Request a free assessment and we’ll find the gaps before an attacker does.

#ransomware#cybersecurity#backup#incident response

Enjoyed this article?

Get more like it by email. Short, practical security tips for business owners. No jargon, no spam, unsubscribe anytime.

We only use your email to send the tips. Nothing else, and never shared.

Want help putting this into practice?

Our team can assess your environment and handle the heavy lifting. Start with a free, no-pressure conversation.