Ransomware did not disappear after the headline years. It got quieter, faster, and far more targeted at the businesses that assume they are too small to matter. In 2026 the typical victim is not a hospital or a national bank; it is a 25-to-100-person company with one stretched IT contractor, a flat network, and backups nobody has ever tried to restore. This guide covers what small business ransomware really looks like now, and the handful of mistakes that keep turning a bad week into a closed business.
Small businesses became the target, not collateral damage
For years, owners comforted themselves with a simple idea: attackers chase the big fish. That was never quite true, and today it is actively dangerous thinking. Ransomware-as-a-service has industrialized the whole model. Affiliates rent ready-made tooling, and initial-access brokers sell footholds into thousands of small companies at a time. The attacker does not need to know your company name to encrypt your files. Automated tooling finds an exposed remote-desktop port or a reused password, and moves on.
Smaller companies are attractive precisely because they are under-defended. The economics are simple: a five-figure ransom demand against a business with no in-house security team, no tested recovery, and enormous pressure to reopen. Effective ransomware protection in 2026 starts by accepting that you are already in scope.
The mistakes that keep costing owners everything
Across incident after incident, the same avoidable failures show up:
- ▸Backups that were never restored. Owners point to a backup job that is green in the dashboard. Nobody has ever performed a full restore, so nobody knows it takes four days, or that the database dumps are corrupt, or that the backup server itself was encrypted.
- ▸Flat networks. One infected laptop can reach every server, share, and workstation because there is no segmentation. The attacker moves laterally in minutes.
- ▸Local admin everywhere. When everyday users run as local administrators, a single click hands the attacker the keys.
- ▸Remote access left exposed. Open RDP, unpatched VPN appliances, and management ports facing the public internet remain the number-one entry route.
- ▸No multi-factor authentication. Reused or phished passwords are still the cheapest way in, and MFA is still skipped on the accounts that matter most.
None of these are exotic. They are boring, and boring is exactly why they get ignored until the morning the screens go red.
Backups are not a strategy until you have tested a restore
The single most important shift you can make is treating recovery, not prevention, as the core of your plan. Prevention will eventually fail. Recovery is what determines whether failure is an inconvenience or an extinction event.
Modern attackers deliberately hunt and delete backups before they trigger encryption, so your backup design has to assume the attacker is already inside. The practical standard remains a version of the 3-2-1 rule: three copies of your data, on two different media, with at least one copy offline or immutable and off-site. In 2026, the word that matters most is immutable, storage that cannot be altered or deleted for a defined retention window, even by an administrator with stolen credentials.
Then test it. Schedule a restore drill at least quarterly. Measure two numbers honestly: how much data you would lose (your recovery point) and how long a full rebuild actually takes (your recovery time). Most owners discover their real recovery time is measured in days, not the hours they assumed. Better to learn that in a drill than during an outage.
Identity is the new perimeter
Firewalls still matter, but the modern break-in is a login, not a hack. Attackers phish a password, buy it from a broker, or spray common credentials, then walk in through your VPN, your email, or your cloud console. That makes identity your real front door.
Three controls carry most of the weight:
- ▸Phishing-resistant MFA on email, remote access, cloud admin, and financial systems. App-based or hardware-key MFA, not SMS where you can avoid it.
- ▸Least privilege. Remove standing local-admin rights. Give elevated access only when needed and log it.
- ▸Fast offboarding. Ex-employees and dormant contractor accounts are a favourite foothold. Disable accounts the same day someone leaves.
If you do only one thing after reading this, turn on MFA everywhere it is missing. It is the highest-return control available to a small business.
Paying the ransom is a business decision, not a technical one
When the demand arrives, panic pushes owners toward paying. Understand what paying actually buys. It buys a decryption tool that is often slow and buggy, from criminals with no obligation to deliver. It does not buy silence, double extortion, where attackers steal your data before encrypting and threaten to publish it, is now standard, so paying to decrypt does nothing about the copy they already hold.
There are also legal dimensions. Payments can run into sanctions exposure if the group is on a restricted list, and under EU breach rules the theft of personal data is a reportable event regardless of whether you pay. Decide your posture in advance, in calm conditions, and write it into an incident plan. Line up a specialist incident-response contact and legal counsel now, so you are not searching for help while the clock runs.
What NIS2 and EU rules mean for smaller companies
Many owners believe regulation is only a big-company problem. The NIS2 Directive widens the net considerably across the EU, pulling in medium-sized organisations in a long list of sectors and, crucially, their suppliers. Even if NIS2 does not name you directly, your enterprise customers will increasingly push its requirements down their supply chain through contracts and security questionnaires.
Separately, because ransomware almost always involves personal data, GDPR breach-notification duties apply. A qualifying breach generally must be reported to your supervisory authority without undue delay and typically within 72 hours of becoming aware. That deadline is unforgiving when you have no plan, no logs, and no idea what was taken. Basic readiness, knowing where personal data lives, keeping logs, and having a notification template drafted, turns a scramble into a process.
A 90-day ransomware readiness checklist
You do not need an enterprise budget to close most of your exposure. Work through this in order:
- ▸Weeks 1-2: Enable MFA on email, VPN, and all admin accounts. Inventory every internet-facing service and close or patch exposed remote access.
- ▸Weeks 3-4: Stand up immutable, off-site backups and run your first full restore test. Document your real recovery time.
- ▸Weeks 5-6: Remove standing local-admin rights, tighten offboarding, and patch the systems that have been red for months.
- ▸Weeks 7-8: Deploy endpoint detection and response on every device, and make sure someone actually watches the alerts.
- ▸Weeks 9-12: Write a one-page incident plan with names and phone numbers, segment your network so one machine cannot reach everything, and run a tabletop exercise.
Revisit the list every quarter. Resilience is a habit, not a purchase.
How a partner like TuniCyberLabs helps
Most small companies do not lack awareness; they lack the time and specialist hands to close the gaps before an attacker finds them. This is where a focused engineering partner earns its keep. TuniCyberLabs helps growing businesses across the EU and North Africa harden identity, design immutable and tested backup architectures, segment networks, and stand up detection that a lean team can actually operate. Our nearshore engineering base in Sousse means senior security work at a cost that fits a small-business budget, with EU data-residency and GDPR alignment built in from the start.
Ransomware readiness is not a product you buy once; it is a posture you maintain. If you want an honest assessment of where you stand and a prioritized plan to fix it, get in touch with TuniCyberLabs and we will help you build resilience before you need it.
