Back to Blog
    your-business-ransomware-attack

    What Happens to Your Business During a Ransomware Attack

    12 min read

    Let me paint you a picture. Not the polite version. The real one.

    But first some numbers, because the gap between what small business owners believe and what's actually happening to companies like theirs is the entire reason this post needs to exist.

    Microsoft surveyed two thousand small businesses last year. Forty-four percent of them said they probably wouldn't get attacked again because they already had been. Twenty-six percent said they were probably safe because they never had been. Twenty-six percent said they were too small to be targeted at all.

    Those are the exact three things every company says right up until the morning their VP of Operations calls about the encrypted shared drive.

    So here's that morning.

    It's a Tuesday. Your VP of Operations calls. She can't open any files on the shared drive. Then she sends you a screenshot. There's a text file on her desktop she doesn't remember creating. The file says "ALL YOUR FILES HAVE BEEN ENCRYPTED" in caps, and then a bitcoin address, and then a deadline.

    Your stomach drops through the floor. You text your IT person. He's at the dentist. You text him again. Now you're calling. He answers with novocaine in his mouth and a tone you've never heard from him before, which is terror.

    This is hour one. There are about 72 of them ahead of you, and you have prepared for exactly none of it.

    Welcome to ransomware. Let me walk you through the next three days, because nobody else will.

    Hour 1 through 6: the meltdown

    You spend the first hour assuming this is a misunderstanding. Maybe it's just one computer. Maybe it's a phishing test you forgot you authorized. Maybe IT can just "remove the virus."

    It's not. It's not. He can't.

    By hour two, four more people have called. The CFO's QuickBooks file is locked. The sales team can't open the CRM exports they had on the file server. Production has stopped because the network drive with the work orders is unreachable. The phones are still working, because phones are on a separate system, which is the only stroke of luck you're going to get all week.

    By hour three, you're on a conference call with your IT guy and a cybersecurity firm he Googled in a panic. They want a $25,000 retainer wired by end of business to start the investigation. You wire it. You don't even argue.

    By hour four, you find out you don't have a cyber insurance policy that actually covers this. Your broker mentioned a rider eight months ago. You didn't buy it. The policy you have covers $50,000 of incident response, which the cybersecurity firm just consumed in retainer.

    By hour five, the cybersecurity firm tells you the attackers got in three weeks ago. They've been inside your network the whole time. They have a copy of your data already. The encryption you're staring at is the finale, not the start.

    By hour six, you tell your wife you're going to be late. You don't sleep.

    Day 1 through Day 3: the real cost

    Here's where the numbers get ugly. Pay attention.

    You can't run payroll because the payroll software depends on data on the encrypted file server. The CFO is doing math by hand on a whiteboard. Your bookkeeper is in tears.

    You can't fulfill orders because production is offline. You're calling your three biggest customers personally to explain. One of them is sympathetic. One of them is angry. The third one starts asking what your data security looks like, because they have an audit coming up and they're not sure they can do business with you if this gets worse.

    Your insurance broker is asking why you didn't buy the cyber rider. The cybersecurity firm is asking whether you want to negotiate with the attackers. The FBI is on a call with you because someone told you that you have to report it. Your attorney is on a different call telling you about your notification obligations. Your wife is asking if she should cancel the family trip.

    The cybersecurity firm now wants another $80,000. You ask why. They explain. You wire it.

    Day two, the attackers post a sample of your data on their leak site. It includes employee social security numbers, customer contracts with pricing, and a folder labeled "Compensation Plan 2026" that your HR director thought was secure.

    Day three, your largest customer cancels their renewal. They didn't say it was because of the breach. But it was because of the breach. You don't even bother asking.

    Day 4 through Day 30: the slow bleed

    Restoration takes weeks. Your IT person doesn't sleep. The cybersecurity firm bills $400 an hour. Your backups, which you thought you had, were on the same network the attackers encrypted. The backups are also encrypted. Of course they are. Why would you separate the backups from the production network? That would have made too much sense.

    Your team is on egg shells. Half of them are scared. The other half are scrolling Indeed during their lunch breaks. Three people quit by week three. Two of them are people you couldn't afford to lose.

    You hire a public relations firm because the local business journal called. The PR firm is $15,000 a month. You hire breach notification counsel because you have to send letters to 12,000 customers. That's another $40,000. The state attorney general's office wants to talk to you. The cyber insurance carrier wants to know if you would like to pursue a denial appeal on the part of your policy you thought was covered.

    Six weeks in, you reach a steady state. The systems are restored. Most of the data is recovered. You did not pay the ransom, against the cybersecurity firm's advice, because the FBI told you not to. The attackers leaked your data on the dark web anyway.

    The total bill, when the smoke clears, is somewhere north of $400,000. About $120,000 of that is the cybersecurity firm. About $80,000 is the breach notification effort and legal counsel. About $60,000 is the lost revenue from the customer who walked. The rest is the long tail: the new hires you have to make because three people quit, the cyber insurance premium that triples at renewal, the audit work you have to do every year now to satisfy the customers who almost left, and the salary you pay your CFO to spend a quarter of her time on incident-related cleanup for the next year.

    You're a 50-person company. You did $12 million in revenue last year. The breach is going to cost you 3 to 4 percent of revenue for two consecutive years. You don't recover the EBITDA on the timeline you had planned. The fundraising you were preparing for is delayed by 18 months because the diligence cycle now includes a forensic security review.

    That's what ransomware looks like. That's the actual picture.

    Why we don't bother securing on-prem servers anymore

    Here's the part nobody else will tell you, and it's the actual answer.

    Most of the advice you've ever heard about ransomware is about securing what you have. Better firewall. Better antivirus. Better backups. Better monitoring. The whole industry is selling you a more expensive way to defend a castle you can't afford to garrison.

    We don't tell our customers to do that.

    We tell them to leave the castle.

    The growth-stage company with three on-prem servers, a file share, and a backup NAS in the closet is paying for the privilege of being a ransomware target. Every server is an attack surface. Every backup that lives on the same network as the production data is a backup the attacker also encrypts. Every patch you don't apply because you're "afraid it'll break something" is a vulnerability with a public CVE and a working exploit somebody downloaded last Tuesday. The math of defending it properly is brutal, and most small businesses don't have the appetite or the budget to do it right.

    So we don't ask them to.

    Our operating model for growth-stage companies is cloud-first, SaaS-first, no on-premises servers at all. Email lives in Microsoft 365. Files live in OneDrive and SharePoint. Identity lives in Entra ID. Line-of-business systems live in SaaS applications somebody else hosts. The endpoints are still endpoints, so they still need protection, but the surface area the attacker can reach is a tiny fraction of what an on-prem environment exposes.

    Here's the concrete example. One of our managed customers gets phished. Malware lands on a user's laptop. It encrypts every file the user has access to: their personal OneDrive, every team SharePoint site they belong to, all of it. Sounds catastrophic. It is not.

    We isolate the device in seconds via endpoint management. We revoke the user's session tokens across every service. Then we restore their OneDrive and SharePoint content to the version that existed before the encryption ran. Microsoft 365 has versioning baked into both. The recovery is literally two clicks per library. The user is back online inside an hour, and the attacker walks away with encrypted copies of files the legitimate owner never lost access to.

    This is not theoretical. This is the operating model. The reason we won't take on a managed customer who insists on keeping their on-prem file server isn't snobbery. It's that we know what that file server costs them when (not if) an attacker reaches it. We can't undo a ransom encryption on a Windows file share the same way we can on a SharePoint site. The math doesn't work, and we're not going to lie to a customer about it to win the deal.

    If you're a 20 to 100 person company and you still have on-prem servers, the highest-impact security decision you can make in the next 12 months is to retire them. Not to secure them. To replace them with a stack that doesn't have them in the first place. The migration is the security investment.

    That said, if you're going to stay where you are for the next year or two, here's the floor.

    The math that should have happened six months ago

    Here's the thing that will keep you up at night six weeks after the breach.

    The whole damn thing was preventable for $40,000 to $60,000 in annual security spend. That's it. Less than the price of one decent salesperson. Less than the deductible you didn't realize you had on your insurance.

    What that $40,000 to $60,000 a year buys, if you spend it like an adult instead of an optimist:

    • Endpoint protection on every device that actually catches modern threats, not the antivirus you've been running since 2019
    • Email filtering that catches the phishing email that got you in the first place
    • Multi-factor authentication on every system, not just the ones IT remembered to configure
    • Backups that live separately from your production estate, with immutable copies and versioning. For cloud-native shops that means Microsoft 365 native versioning on OneDrive and SharePoint plus an immutable third-party backup like Dropsuite. For the on-prem-still holdouts, it's a backup service that ships your files to a cloud vault the attacker has no path to. The non-negotiable: the backup is not on the network the attacker is on.
    • A 24/7 monitoring service that would have caught the attackers in week one of their three weeks of recon, not when they triggered the encryption
    • A documented incident response plan so you don't spend the first six hours of the worst day of your career on the phone with a cybersecurity firm you found by Googling

    Every single one of these is table stakes in 2026. None of them is exotic. None of them is expensive. None of them requires a 12-month implementation project. The barrier to having them is not technical. It's that nobody is making the CEO sit down and do the math.

    I am asking you to sit down and do the math.

    The conversation I want you to have with yourself

    Take a hard look at where your business sits today. Ask yourself, with brutal honesty:

    Do you have MFA on every account, including the admin accounts your IT guy uses? Or just the ones you got around to?

    Do you have backups that are physically separated from your production network, with immutable copies, that someone has actually tested by restoring? Or do you have a NAS in the closet that you assume works?

    Does your endpoint protection stop ransomware behaviorally, not just by signature? Or do you have a five-year-old antivirus suite that you renew every year because nobody has time to evaluate alternatives?

    Does anyone watch your environment at 2 AM on a Sunday? Or do attacks have a 72-hour head start every weekend because your IT person is asleep?

    If you can't answer all four with confidence, you are exposed. Not theoretically. Practically. The attackers know exactly which businesses look like yours, and they have automated tools running against you right now.

    The fix is not complicated. It is not expensive. It is, however, now.

    Look, I'm writing this hard because I've watched it happen to good people running good companies. Smart founders. Hardworking teams. None of them thought it would be them. They were wrong, and most of them are still recovering a year later. The version of this post where the company is yours is the one I'd rather not have to write.

    You're past the part where ignorance is an excuse. You read this far. That counts for something. The fix is still cheap, the conversation is still quiet, and the window is still open. Use it.


    If you want a real assessment of your current security posture without a sales pitch, take the 10-minute IT Stack Diagnostic. You'll get a scored output and the specific gaps that an attacker would find first.

    Or call us. Right now. If something on this page made your stomach drop, that's your gut telling you the truth. Listen to it.