Skip to main content

Blog

A dim office at end of day with a single laptop screen glowing red with a blurred warning message

Ransomware in 2025: How Small Businesses Actually Get Hit

Ransomware in 2025: How Small Businesses Actually Get Hit

The image most people have of a ransomware attack is a sophisticated team of hackers targeting a hospital or a bank. The reality for small businesses is considerably more mundane, and more preventable. Most attacks on SMEs in 2025 follow one of three patterns, and all three are largely avoidable with basic security hygiene.

Here is how attacks actually happen, what the consequences look like, and what sensible prevention looks like for a business of ten to fifty people.

How most small business ransomware attacks start

Phishing email with a malicious attachment or link

The most common entry point. A member of staff receives an email that looks plausible (an invoice from a supplier, a courier notification, a message from "Microsoft" about their account) and either opens an attachment or clicks a link. The malicious code runs and begins encrypting files.

Modern phishing emails are sophisticated. They use correct branding, real-looking sender addresses, and contextually appropriate content. A tired member of staff on a Monday morning does not always catch them.

Compromised credentials

The second most common vector. An attacker obtains a username and password, usually from a data breach of another service where the staff member used the same password, and uses it to log into Microsoft 365, a VPN, or a remote desktop. Once inside, they move laterally until they find something worth encrypting or stealing.

This is why MFA and unique passwords per account are not optional extras for small businesses.

Unpatched software

Attackers actively scan the internet for machines running known-vulnerable software. An unpatched VPN gateway, a Windows server that has not had updates applied, or a router with a known firmware vulnerability can all be exploited automatically, without any human interaction required.

Small businesses that are not actively managing patches are effectively advertising themselves as soft targets.

What happens after an attack

The encryption phase is usually fast. Modern ransomware can encrypt a network drive in minutes. By the time anyone notices, the damage is done.

You will typically see: files renamed with an unusual extension, a ransom note on the desktop or in every folder, and systems behaving strangely. If your backup drive was connected to the network when the attack occurred, that is likely encrypted too.

The ransom demand for a small business attack in 2025 typically runs from £5,000 to £50,000, payable in cryptocurrency. Paying does not guarantee you get your files back. Many businesses that pay never receive a working decryption key.

What recovery actually looks like

If you have clean, offsite backups that were not connected to the network during the attack, recovery involves: isolating the affected machines, rebuilding or reimaging them, and restoring data from backup. That process takes days to a week for a small business. It is painful but survivable.

If you do not have clean offsite backups, recovery may be impossible without paying the ransom and hoping for the best. That is the scenario you are trying to avoid.

The prevention list

  • MFA on every account, starting with Microsoft 365.
  • Security awareness training so staff can recognise phishing. Even a basic online course is significantly better than nothing.
  • Patch management: all devices and software updated within 14 days of security patches. Managed automatically, not relying on staff to click "update later" at the right time.
  • Offsite, immutable backups. A backup that can be encrypted by ransomware is not a backup. Cloud backups with versioning and immutability (so they cannot be overwritten) are the right answer for most small businesses.
  • Endpoint detection: Microsoft Defender with Defender for Business (included in M365 Business Premium) provides a significant uplift over basic antivirus. It detects ransomware behaviour, not just known signatures.
  • Email filtering: Microsoft 365 Defender includes anti-phishing and attachment scanning. Make sure it is configured properly, not left on defaults.

The insurance question

Cyber insurance exists and is worth considering for small businesses, but it is not a substitute for prevention. Insurers are increasingly requiring evidence of MFA, patching, and backups before they will pay out. And an insurance payout does not give you back the days of downtime, the reputational damage, or the data that was stolen before encryption began.

If you are concerned about your current exposure, get in touch and I will run through the basics with you. Most of the key protections cost very little to put in place.

Cyber security for small businesses

ClearPath IT Services provides cyber security support and managed IT for small businesses across Kent, Medway and South East London.

ClearPath IT Services

Personal, reliable IT support for small businesses across Kent, Medway and South East London.

Clear IT. Sorted.

Get in Touch

Based in Kent, serving businesses across Medway, Dartford, Gravesend, Sidcup, Bexley and South East London.

Call: 0333 360 8308

Visit: 1a Saddington Street, Gravesend, DA12 1ED

Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

Contact me


© 2026 ClearPath IT Services Limited. All rights reserved. | Privacy Policy