Ransomware attackers now hit small businesses harder and more often than enterprises, because weak backups and no monitoring make recovery nearly impossible. The businesses that survive an attempt almost always have one thing in common: something caught it before encryption finished. Not after. During.
Ask most owners of a 15-person company why they’d be a target and you get some version of the same answer. Nothing valuable enough. Too small to notice. That logic made sense around 2015. It doesn’t anymore, and the shift happened quietly enough that a lot of small business owners are still operating on the old assumption, right up until the morning a shared drive won’t open.

The Math Changed, Not the Target
Verizon’s 2025 Data Breach Investigations Report found extortion malware, ransomware, in 88% of breaches at small and medium businesses, compared to 39% at larger organizations. That gap isn’t close. It’s the difference between occasional risk and the default outcome once someone gets in. Not a fluke. A pattern.
Attackers didn’t develop a sudden interest in 12-person accounting firms and 30-person medical practices. What changed is the economics. Ransomware-as-a-service kits let one operator run dozens of attempts a week with almost no manual effort per target. A large enterprise with a security operations center and a six-figure incident response retainer takes real work to breach and real risk to get caught inside. A small business running unpatched software, no MFA, and one overworked IT contact takes an afternoon. Volume beats precision when the tooling is this cheap. That’s the whole model.
The FBI’s Internet Crime Complaint Center logged 3,611 ransomware complaints in 2025, with reported losses of $32.3 million, up 259% from the year before. That number only counts the ransom and direct losses reported to IC3. It doesn’t count the week of downtime, the client who doesn’t come back, or the insurance premium that triples at renewal. The real bill comes later.
What Makes a Business “Small Enough” to Be a Target
To a ransomware crew running automated scans, a small business is any network with fewer than a few hundred endpoints, no dedicated security staff, and internet-facing services that haven’t been patched recently. VJNetworks’ own client base runs 5 to 60 employees, which sits squarely inside that profile. Nothing exotic about it. That’s part of why every engagement through VJNetworks’ cybersecurity services gets built around prevention rather than cleanup.
Most owners picture an attack as something dramatic. A ransom note, a countdown clock, a demand in Bitcoin. The actual damage is usually quieter and less cinematic. Payroll can’t run. The scheduling system is down. A client asks why their invoice bounced and nobody has an answer yet.
Where the Damage Actually Happens
Four gaps show up again and again, and three of the four trace back to the same root problem.
| Entry Point | Why Small Businesses Get Hit | What Actually Closes the Gap |
|---|---|---|
| Phishing email | One click, no MFA prompt to stop what happens next | MFA on every account, especially email and remote access |
| Unpatched software | Small IT teams fall behind on patch cycles without realizing it | A managed patch schedule, not “whenever there’s time” |
| Exposed Remote Desktop Protocol | Convenient for remote work, wide open to brute-force attempts | MFA plus IP restriction, or replacing RDP entirely |
| No real monitoring | Nobody notices until the files are already encrypted | Behavioral monitoring that acts in minutes, not after the fact |
Three of those four causes trace back to the same root problem. Somebody assumed a password was enough. It hasn’t been enough for years. Still isn’t.
New York Adds a Compliance Layer Most Owners Don’t Know About
The New York Department of Financial Services tracked 74 ransomware attacks reported by DFS-regulated companies between January 2020 and May 2021. Seventeen of those companies paid the ransom. DFS’s own guidance names the same three entry vectors nearly every incident traces back to:
- Phishing emails that trick someone into clicking before thinking. Still the top entry point by volume.
- Unpatched software. A vulnerability disclosed in March and still open in July isn’t a gap. It’s an invitation.
- Remote Desktop Protocol left exposed to the open internet with weak or reused passwords.
If your business is DFS-regulated, a successful ransomware deployment has to be reported within 72 hours, full stop. If you’re not DFS-regulated, New York’s SHIELD Act still applies once you’re holding any New York resident’s private information, which describes almost every small business with employees or customers in the state. A lot of owners assume the compliance layer only touches banks and insurers. It doesn’t.

What Actually Stops It
No single tool stops ransomware. Layered defenses do. The layers themselves aren’t complicated. They’re just usually incomplete.
Multi-factor authentication closes the phishing and RDP gap by itself, in most cases. Endpoint detection and response watches behavior instead of matching known malware signatures, which matters because new ransomware variants show up constantly and traditional antivirus can’t recognize what it’s never seen. Tested, segregated backups mean an encrypted server is an inconvenience instead of a catastrophe, but only if someone has actually restored from them recently, not just confirmed the backup job ran.
Here’s the part that’s hardest to communicate to a business owner who’s never had a scare: none of this shows up as a line item you can point to and say that’s what saved us. Good monitoring is invisible by design. VJNetworks’ response time runs within 15 minutes, and when something in the environment starts behaving like ransomware, the process is to shut it down and roll it back immediately, not flag it for review the next business day. That speed is the entire point. Ransomware usually finishes encrypting a network in under an hour from first execution. Speed decides everything. A monitoring system that reviews alerts once a day is watching the wrong clock.

Twenty years of doing this for Rockland, Westchester, and Bergen County businesses teaches you one thing above everything else. The businesses that get hurt aren’t unlucky. They’re unmonitored.
Where to Start This Week
None of this requires a full security overhaul before Monday. It requires picking the biggest open door and closing it first.
- Turn on MFA everywhere it isn’t already on, starting with email and anything reachable from outside the office.
- Confirm the last backup restore test, not the last backup job. A job that “completed successfully” and a file that actually opens are two different claims.
- Ask whoever handles patching how far behind the schedule currently runs. If nobody can answer that immediately, that’s the finding right there.
A free assessment covers all three in about an hour, with a written list of what’s actually open versus what only looks closed.
Straight Talk on Ransomware Risk
Is a 15-person company actually worth a ransomware crew’s time?
What actually happens the moment ransomware lands on a network?
Do we really need EDR if we already have antivirus?
Is New York’s reporting requirement only for banks and insurers?
How fast should a monitored network actually respond to something suspicious?
“Too small to target” was never really true. Not once. It’s just taken this long for the data to catch up to what attackers already knew. See VJNetworks’ managed IT services, read how we recommend evaluating an MSP before you sign anything, or if you’re ready now, a free assessment shows exactly where your gaps are, before anyone else finds them first. Businesses across Rockland County and the wider Tri-State area have relied on that same review for over 20 years.
Further reading: CISA’s #StopRansomware Guide covers the government’s current baseline recommendations in more depth.
