Most ransowmare attacks on small businesses follow predictable patterns: phishing emails, stolen passwords, unpatched software or exposed remote access.
There’s good news, though: because these routes are known, they can be closed. In this guide we’ll explore why SMEs are targeted in particular, and the layers to prevent attacks.
We’ll cover:
- Why SMEs are targeted
- How a ransomware attack actually unfolds
- The layers that stop it
- Recovering when something gets through
Why SMEs are Targeted
It can be tempting to think that your business is too small to be worth targeting, but the contrary is often true: SMEs are attractive to bad actors precisely because they tend to have more gaps and fewer defences.
Many of the risks are automated, too: attackers scan for weaknessess and hit whoever’s exposed. SMEs can also be a route into a larger client or partner, so there are layers to the threat.
In short: SMEs are targeted because small often means easier.
How a Ransomware Attack Actually Unfolds
Most attacks follow the same trajectory:
- Getting in: a vulnerability allows the ransomware into your systems - a clicked link, a reused password, an unpatched or otherwise exposed system
- Gain foothold and spread: once in, the ransomware moves from one device across the network
- Encryption: the ransomware locks your files - including copies synced to the cloud
- They make a demand: the ransom is demanded, and there’s no guarantee that paying it will actually undo the damage or remove the ransomware from your system
This is a familiar and well-understood chain, and breaking any one link stops or limits the whole process. This is where the concept of a layered defence comes in.
You can read more about the common attack types here.
The Layers that Stop Ransomware
No single tool stops ransomware - what works is layers, with each one removing a step the attacker needs. They are:
- Security-awareness training: this helps your team to spt the phishing attempts that start most attacks, reducing the likelihood of them accidentally initiating one
- Modern endpoint protection (Zero Trust): this detects and stops malicious activity that traditional antivirus software is liable to miss
- Managed patching: this closes the unpatched-sofwtware route by ensuring everything is fully up to date
- Dark-web credential monitoring: this flags stolen logins before they’re used maliciously
- Encforced MFA and access control: this limits what an individual compromised account can reach, slowing down the spread of ransomware
- Managed firewalls and secure remote access: this closes the exposed-access route
To summarise: no single tool or step stops ransomware - it’s a combination of layers that offer a staged defence.
Several of these are covered by the fundamentals assessed by Cyber Essentials.
Recovering When Something Gets Through
While the likelihood decreases significantly, even strong defences can be beaten. This means that the ability to recover fully and quickly when something goes awry is part of the defence.
The key is independent, regularly tested backups, held separately from your live systems, rather than relying on Microsoft 365's native tools (which we cover in [does Microsoft 365 back up your data?]).
If ransomware does encrypt your files, clean, recent backups are what let you restore and carry on instead of facing down a ransom demand. Combine that with a simple, documented recovery plan (who does what, in what order) and an incident that could have closed the business for a week becomes a manageable disruption measured in hours.
To Summarise
Ransomware is preventable and survivable with the right layers in place. For a review of your current defences and ability to recover, book a free IT consultation today.