Ransomware coverage in the news tends to focus on massive enterprise breaches with eight-figure ransom demands. That framing is misleading for a small business owner trying to figure out what actually matters. Here’s a more grounded look at the real risk and what actually reduces it.
Why small businesses are targeted, specifically
Verizon’s 2026 Data Breach Investigations Report found that extortion-style malware appeared in 88% of confirmed breaches at small organizations, compared to 39% at larger ones — small businesses aren’t an afterthought for attackers, they’re disproportionately targeted, largely because they’re more likely to lack basic defenses like MFA and endpoint monitoring that make an attack harder to pull off.
What an incident actually costs a small business
Industry-wide averages that include large enterprise breaches (often cited in the millions) aren’t a realistic picture for a 20–100 person NJ business. The numbers that matter more at that scale: average ransomware-related downtime runs around 24 days, and 40% of small business owners say an incident costing $100,000 could end the business entirely. The median ransom payment in 2025 was around $115,000 — and that’s before accounting for downtime, recovery labor, and lost business during the outage.
The layers that actually prevent or limit damage
No single tool stops ransomware. What actually works is layering defenses so that a failure in one doesn’t become a full breach:
- Endpoint detection and response (EDR): modern behavioral protection that can catch and isolate an attack in progress, not just known malware signatures.
- Multi-factor authentication everywhere: the single highest-leverage control against the credential-theft attacks that lead to most ransomware incidents.
- Patch management on a real schedule: most ransomware exploits known, already-patched vulnerabilities on systems that simply never got updated.
- Email and phishing defense: phishing remains the most common way ransomware gets an initial foothold. See our phishing and security page for what real filtering looks like.
- Network segmentation: keeping one compromised device from having a direct path to everything else on the network.
Backups are not the same thing as ransomware protection
This is the most common misconception we run into. Having backups matters — but if they aren’t tested, isolated from your main network, and actually restorable within a timeframe your business can survive, they don’t protect you from anything. Modern ransomware actively hunts for and encrypts connected backup systems. This is exactly why disaster recovery planning is a separate discipline from simply “having backups.”
What to do in the first hour if it happens anyway
Disconnect affected systems from the network immediately to limit spread — don’t power them off, which can destroy forensic evidence. Don’t engage with a ransom demand on your own. Call your IT or security provider and your cyber insurance carrier before making any other decisions. Speed in the first hour has a real, measurable effect on how far an incident spreads.
How Mii2 approaches ransomware protection
We build layered protection — endpoint detection through our partnership with SentinelOne, email and phishing filtering, MFA enforcement, and tested, segmented backups — rather than treating any single tool as the whole answer. If your business is in a regulated industry, this usually overlaps directly with regulatory compliance requirements too. See our full managed cybersecurity services, or the vendors we work with on our partners page.
Ransomware Protection — Common Questions
Should we ever pay a ransom?
Most guidance from federal agencies and insurers advises against it — payment doesn’t guarantee data recovery, and roughly two-thirds of victims in 2025 refused to pay. This decision should be made with your legal counsel, insurer, and IT/security provider together, not unilaterally.
Does cyber insurance cover ransomware?
Many policies do, but increasingly require proof of specific controls — MFA, EDR, tested backups — to pay out or even issue a policy at all. Check your policy’s specific requirements before assuming you’re covered.
Is a small business really a realistic target?
Yes — small organizations account for a disproportionate share of confirmed ransomware victims, largely because they’re easier targets, not because attackers are only after large companies.
