Skip to content
Eudora Technology
Home  / Insights
Cybersecurity

How to Protect Your Business From Ransomware

New Zealand Army Lance Cpl. Luke Donovan, a host analyst assigned to the 1st Command Support Regiment, poses for a hometown news photo during a cyber operations event as part of Ex
Photo: Balikatan 2026- New Zealand Defence Forces Participate in Cyber Operations Exercise by Seaman Donald Freeman, Public domain, via Wikimedia Commons

Get one backup copy that an attacker holding your administrator password cannot delete, then patch everything facing the internet, then make sure a stolen password alone cannot sign in. In that order. Everything else in ransomware defence is useful, but those three jobs are the difference between a bad fortnight and a business that does not reopen.

New Zealand Army Lance Cpl. Luke Donovan, (right), a host analyst assigned to the 1st Command Support Regiment, works with a Philippine Navy cyber analyst during a cyber operations
Ransomware is a business model, not a prank. The people running it have support desks, affiliate programmes and a pricing strategy.Photo: Balikatan 2026- New Zealand Defence Forces Participate in Cyber Operations Exercise by Seaman Donald Freeman, Public domain, via Wikimedia Commons

The four numbers that should shape your plan

Ransomware keeps climbing. Verizon’s 2026 Data Breach Investigations Report, which examined more than 22,000 confirmed breaches, found ransomware present in 48% of them, up from 44% in the previous edition. The report is careful about how to read that: it does not mean your organisation has a 48% chance of being hit. It means that among breaches that happened, were noticed and were reported, nearly half involved ransomware.

The second number is the one small businesses tend to disbelieve. Of the ransomware cases where organisation size was known, roughly 96% of victims were small and medium businesses. Those cases rarely make the news, which is why the perception persists that this is a problem for hospitals and car manufacturers.

48%
of breaches involved ransomware (2026 DBIR)
96%
of ransomware victims were SMBs
69%
of victims did not pay the ransom
USD 139875
median ransom actually paid
Source: Verizon 2026 Data Breach Investigations Report.

The third and fourth numbers are better news. Ransom payments are declining: 69% of ransomware victims in the DBIR dataset did not pay, and the median amount paid fell to USD 139,875 from USD 150,000 the previous year. Refusing to pay is becoming normal, which it only can be if the victim has a way back without the key.

For context on frequency rather than severity, the UK Department for Science, Innovation and Technology’s Cyber Security Breaches Survey 2025/2026 found just 1% of UK businesses identified a ransomware attack in the previous 12 months, down from 3% in each of the two prior years. Rare and catastrophic is a different planning problem from common and survivable, and ransomware sits firmly in the first category.

How attackers actually get in

The DBIR looked at what distinguished ransomware victims from everyone else and found it had little to do with industry or revenue. What mattered was that the victims had credentials that had been compromised, in 38% of cases, or unpatched vulnerabilities in edge devices, in 29%. Firewalls, VPN concentrators, remote access gateways: the boxes that sit at the boundary and get forgotten because nobody logs into them day to day.

What set ransomware victims apart in the 2026 DBIR
Credentials already compromised38%
Unpatched vulnerabilities in edge devices29%
These are characteristics of the victim organisations, not a full initial-access breakdown. Source: Verizon 2026 DBIR.

That is an unglamorous answer and a useful one, because both halves are fixable with work you can schedule. There is no zero-day in that sentence. There is a password that should not have worked on its own and a firmware update that was six months late.

CISA’s #StopRansomware Guide, written jointly with the FBI, NSA and MS-ISAC, organises its prevention advice by initial access vector for exactly this reason. Internet-facing vulnerabilities and misconfigurations come first, then compromised credentials, then phishing, then precursor malware. Work the list in that order and you are working it in the order the attackers do.

Backups decide the outcome, and only some backups count

A backup that your domain administrator account can delete is a backup an attacker can delete, because taking that account is the whole point of the intrusion. Modern ransomware crews hunt for backup servers and cloud backup credentials before they encrypt anything, and they are patient about it.

So the test is not whether you have backups. The test is whether you have at least one copy that cannot be altered or destroyed by someone who holds every credential in your environment. In practice that means object storage with immutability or an object-lock retention policy, a backup service whose deletion requests are delayed and alerted, or simply a copy on media that is disconnected.

Backup tierSurvives an attacker with admin rightsTypical restore timeWhat it is good for
Snapshots on the same host or arrayNoMinutesFat-finger mistakes and failed updates
On-site backup server or NASRarely, unless hardened and separately credentialedHoursEveryday restores and large data sets
Cloud backup with versioningOnly if deletion is protectedHours to daysOff-site resilience and geographic separation
Immutable cloud copy with object lockYes, for the retention windowHours to daysThe copy you actually rebuild from
Offline or air-gapped mediaYesDaysThe last resort that has never let anyone down
Restore times are indicative for a small business data set. The column that matters is the second one.
Three questions that tell you if your backups are real
  • Can the account that runs the backup also delete old backups? If yes, fix that first.
  • When did you last restore a file, a mailbox and a whole server? Not test-read: restore.
  • How long would a full restore take, measured rather than estimated?
Maryland Air National Guard Brig. Gen. Joed Carbonell-López, 175th Wing commander, left, visits with Lt. Col. Bob DeLuca, 175th Cyberspace Operations Squadron flight commander, lef
Key management and retention policy are dull topics right up until the morning you need an unalterable copy of last Tuesday.Photo: Maryland cyber personnel strengthen collective defense during NATO Exercise Locked Shields 26 by U.S. Air Force 175WMANG by Staff Sgt. Laura Virtue, Public domain, via Wikimedia Commons

Patch the edge of your network first

The patching data in the 2026 DBIR is genuinely alarming, and it is worth sitting with. Working from aggregated scan data across more than 13,000 organisations, Verizon found that only 26% of the CISA known-exploited vulnerabilities present in those environments had been fully remediated, a considerable drop from 38% the previous year. Vulnerabilities left entirely unremediated rose from 12% to 16%.

Speed got worse too. The median time for a vulnerability to be fully patched after detection rose to 43 days, almost two weeks longer than the previous year’s 32 days. Part of the explanation is volume: the median organisation had 16 known-exploited vulnerabilities to patch in 2025, against 11 the year before, which is close to 50% more work for the same team.

CISA known-exploited vulnerabilities: how organisations are coping
Previous DBIR dataset2026 DBIR dataset
Fully remediated38%26%
Left unremediated12%16%
Aggregated scan data from more than 13,000 organisations. Source: Verizon 2026 DBIR.
MeasurePrevious DBIR2026 DBIRDirection
Breaches involving ransomware44%48%Worse
Ransomware victims who did not paynot stated69%Better
Median ransom actually paidUSD 150,000USD 139,875Better
CISA KEV vulnerabilities fully remediated38%26%Worse
CISA KEV vulnerabilities left unremediated12%16%Worse
Median days to fully patch after detection3243Worse
Median KEV vulnerabilities to patch per organisation1116Worse
Year-on-year comparison drawn from the Verizon 2026 DBIR, which reports both figures in each case.

The practical response for a small business is not a vulnerability management programme. It is a short list and a calendar. Write down every device and service that answers from the internet, including the ones you inherited from a previous supplier. Subscribe to the vendor advisories for each. Agree a rule, in writing, that anything on the CISA known-exploited list gets patched within 14 days, and that the firewall and the VPN get patched within 48 hours. The UK survey found only 34% of businesses have any policy to apply updates within 14 days, so this one puts you ahead of two thirds of the field.

The infostealer pipeline nobody watches

Here is the part most ransomware advice misses. The DBIR tracked whether ransomware victims had an infostealer or credential-leak event in the year before they were publicly named. Twenty-seven per cent had none. Of those that did, half had the credential event within 95 days of the ransomware attack.

That is a warning you can act on. An infostealer infection on a laptop, often on a personal device used for a bit of work, harvests saved browser passwords and session cookies. Those get packaged and sold, and a few weeks later somebody uses them. The window between the leak and the attack is the window you have.

Credential leaks are not the aftermath of a ransomware attack. They are usually the three months before it.

Two controls close that window. Phishing-resistant authentication means a harvested password is not enough on its own, which our guide to multi-factor authentication covers in detail. And a credential-monitoring feed tells you when your domain shows up in a leak, so you can force resets before anyone else gets round to trying them. Our notes on current password rules explain why blocklist screening beats forced rotation for the same purpose.

Decide the payment question before anybody asks it

Decide the payment question on a quiet afternoon, with your insurer and your lawyer in the conversation, rather than at 2am with a countdown timer on a screen. Write down who is allowed to authorise a payment, under what circumstances, and who must be told first.

Several jurisdictions now require you to report a ransom payment, and the rules differ by country and sector. Australia’s Cyber Security Act 2024 brought in a mandatory ransomware payment reporting regime from 30 May 2025, and other regimes impose breach-notification deadlines measured in hours rather than days. These are legal obligations with real consequences and they are not something to work out from a blog post. Get advice from a lawyer qualified in the jurisdictions you operate in, before an incident, and keep the contact details where your incident responders can find them.

What we can say technically is that paying does not reliably return your data, does not undo the exfiltration that usually happened first, and does not stop a second visit. CISA’s response checklist is a good template for the first few hours, and it leads with isolation and evidence preservation rather than negotiation.

Maryland Air National Guard Brig. Gen. Joed Carbonell-López, 175th Wing commander, discusses exercise objectives and priorities with a Finnish project officer during his visit to N
A rehearsal finds the problems a document cannot: the out-of-date phone number, the backup nobody can authenticate to, the decision nobody owns.Photo: Maryland cyber personnel strengthen collective defense during NATO Exercise Locked Shields 26 by U.S. Air National Guard photo by Staff Sgt. Laura Virtue, Public domain, via Wikimedia Commons

Write the plan down, then rehearse it once

NIST rewrote its incident response guidance in April 2025, and the change in approach is instructive. SP 800-61 Revision 3 drops the old static playbook model and instead frames incident response as a profile of the Cybersecurity Framework 2.0, on the reasoning that the detail of how to respond changes too fast to fix in a single document. What it keeps is the insistence that response work belongs inside ordinary risk management rather than in a binder on a shelf.

For a business of under 50 people, the plan that works is two pages. Who decides. Who calls the insurer, the lawyer and the clients. Which systems come back first and in what order. Where the offline copy of the plan lives, because it is no use in the file share that just got encrypted. And the phone numbers, as numbers, not as links to a directory you will not be able to reach.

The UK survey found 25% of businesses have a formal incident response plan: 21% of micro businesses, 57% of medium-sized ones and 76% of large ones. Writing yours puts you in the minority, and rehearsing it once a year puts you in a much smaller minority still. Spend ninety minutes walking through a scenario out loud with the people who would be involved. You will find three problems you did not know you had.

What recovery really costs

IBM’s 2026 Cost of a Data Breach Report, based on 602 breached organisations, put the global average breach cost at USD 4.99 million, up 12% and a record for the series. The report breaks that down in a way that is useful for small businesses even though the absolute figure is not: detection and escalation plus lost business made up 63% of the total. Those are both time-dependent. The faster you detect and the faster you restore, the smaller both lines get.

IBM also found that organisations using AI and automation in their security operations saved an average of USD 1.93 million per breach, though it noted adoption is uneven: 50% of breached organisations had deployed AI agents in threat hunting and response, while only 18% had applied them to vulnerability scanning and management. That gap maps neatly onto the patching figures above.

For planning purposes, the costs that actually land on a small business are staff time, contractor rates, lost revenue during downtime, and the cost of rebuilding trust with clients whose data was exposed. Estimate your own downtime cost per day and compare it with what an immutable backup copy costs per month. The arithmetic usually settles the argument in one line. The rest of the groundwork is in our small-business cybersecurity checklist.

Frequently asked questions

Should we ever pay a ransom?

That is a legal and commercial decision, not a technical one, and it needs a lawyer in the room. Technically, paying does not guarantee a working decryption key, does not retract data that was already copied out, and does not prevent a repeat visit. Some jurisdictions now require you to report payments. Decide your position in advance and write it down.

How many backup copies do we need?

Enough that one of them cannot be deleted by a compromised administrator account. A common shape is a local copy for fast restores, a cloud copy for off-site resilience, and one immutable or offline copy as the rebuild source. The number matters less than that last property. Test a restore quarterly, because an untested backup is a hypothesis.

Is cyber insurance worth it for a small business?

Often yes, and the application process is useful on its own because underwriters ask the questions you should be asking. Read the conditions carefully: cover frequently depends on MFA being in place, backups being tested and patching being current. Check what the policy says about ransom payments and about notification deadlines before you need it.

Does antivirus stop ransomware?

It stops some of it, and endpoint detection and response stops rather more by spotting the behaviour rather than the file. Neither helps if the attacker signs in with valid credentials and uses legitimate administration tools, which is a common pattern. Treat endpoint tooling as one layer alongside identity, patching and backups.

We were hit three months ago. Are we more likely to be hit again?

Unfortunately yes, if the way in has not changed. The DBIR data on credential leaks preceding attacks suggests many victims were exposed for weeks before the encryption started. After an incident, rotate every credential, re-enrol MFA, rebuild rather than clean the affected hosts, and check for persistence in scheduled tasks and mail rules.

We review backup immutability, patch cadence and identity controls remotely for clients worldwide as part of our cybersecurity services, and we will tell you plainly if your current backups would not survive the attack. Get in touch with Eudora Technology to talk about your project.

Sources

  1. 2026 Data Breach Investigations Report (19th edition) Verizon Business · 19 May 2026
  2. #StopRansomware Guide CISA, FBI, NSA and MS-ISAC · retrieved October 2026
  3. Cost of a Data Breach Report 2026 IBM X-Force · July 2026
  4. Cyber Security Breaches Survey 2025/2026 UK Department for Science, Innovation and Technology · April 2026
  5. SP 800-61r3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management NIST · April 2025
  6. I’ve Been Hit By Ransomware (response checklist) CISA · retrieved October 2026
Keep reading

Related insights