Support Center | ☎︎ Call us: (845) 440-5000 | info@vjnetworks.com
Back to Blog

Small Business Ransomware Protection: Why “Too Small to Target” Doesn’t Apply Anymore

Cybersecurity

Ransomware attackers now hit small businesses harder and more often than enterprises, because weak backups and no monitoring make recovery nearly impossible. The businesses that survive an attempt almost always have one thing in common: something caught it before encryption finished. Not after. During.

Ask most owners of a 15-person company why they’d be a target and you get some version of the same answer. Nothing valuable enough. Too small to notice. That logic made sense around 2015. It doesn’t anymore, and the shift happened quietly enough that a lot of small business owners are still operating on the old assumption, right up until the morning a shared drive won’t open.

Small business owner reviewing invoices and paperwork at her office desk

The Math Changed, Not the Target

Verizon’s 2025 Data Breach Investigations Report found extortion malware, ransomware, in 88% of breaches at small and medium businesses, compared to 39% at larger organizations. That gap isn’t close. It’s the difference between occasional risk and the default outcome once someone gets in. Not a fluke. A pattern.

Attackers didn’t develop a sudden interest in 12-person accounting firms and 30-person medical practices. What changed is the economics. Ransomware-as-a-service kits let one operator run dozens of attempts a week with almost no manual effort per target. A large enterprise with a security operations center and a six-figure incident response retainer takes real work to breach and real risk to get caught inside. A small business running unpatched software, no MFA, and one overworked IT contact takes an afternoon. Volume beats precision when the tooling is this cheap. That’s the whole model.

The FBI’s Internet Crime Complaint Center logged 3,611 ransomware complaints in 2025, with reported losses of $32.3 million, up 259% from the year before. That number only counts the ransom and direct losses reported to IC3. It doesn’t count the week of downtime, the client who doesn’t come back, or the insurance premium that triples at renewal. The real bill comes later.

What Makes a Business “Small Enough” to Be a Target

To a ransomware crew running automated scans, a small business is any network with fewer than a few hundred endpoints, no dedicated security staff, and internet-facing services that haven’t been patched recently. VJNetworks’ own client base runs 5 to 60 employees, which sits squarely inside that profile. Nothing exotic about it. That’s part of why every engagement through VJNetworks’ cybersecurity services gets built around prevention rather than cleanup.

Most owners picture an attack as something dramatic. A ransom note, a countdown clock, a demand in Bitcoin. The actual damage is usually quieter and less cinematic. Payroll can’t run. The scheduling system is down. A client asks why their invoice bounced and nobody has an answer yet.

Where the Damage Actually Happens

Four gaps show up again and again, and three of the four trace back to the same root problem.

Entry PointWhy Small Businesses Get HitWhat Actually Closes the Gap
Phishing emailOne click, no MFA prompt to stop what happens nextMFA on every account, especially email and remote access
Unpatched softwareSmall IT teams fall behind on patch cycles without realizing itA managed patch schedule, not “whenever there’s time”
Exposed Remote Desktop ProtocolConvenient for remote work, wide open to brute-force attemptsMFA plus IP restriction, or replacing RDP entirely
No real monitoringNobody notices until the files are already encryptedBehavioral monitoring that acts in minutes, not after the fact

Three of those four causes trace back to the same root problem. Somebody assumed a password was enough. It hasn’t been enough for years. Still isn’t.

New York Adds a Compliance Layer Most Owners Don’t Know About

The New York Department of Financial Services tracked 74 ransomware attacks reported by DFS-regulated companies between January 2020 and May 2021. Seventeen of those companies paid the ransom. DFS’s own guidance names the same three entry vectors nearly every incident traces back to:

  • Phishing emails that trick someone into clicking before thinking. Still the top entry point by volume.
  • Unpatched software. A vulnerability disclosed in March and still open in July isn’t a gap. It’s an invitation.
  • Remote Desktop Protocol left exposed to the open internet with weak or reused passwords.

If your business is DFS-regulated, a successful ransomware deployment has to be reported within 72 hours, full stop. If you’re not DFS-regulated, New York’s SHIELD Act still applies once you’re holding any New York resident’s private information, which describes almost every small business with employees or customers in the state. A lot of owners assume the compliance layer only touches banks and insurers. It doesn’t.

IT consultant reviewing a ransomware protection checklist with a small business client

What Actually Stops It

No single tool stops ransomware. Layered defenses do. The layers themselves aren’t complicated. They’re just usually incomplete.

Multi-factor authentication closes the phishing and RDP gap by itself, in most cases. Endpoint detection and response watches behavior instead of matching known malware signatures, which matters because new ransomware variants show up constantly and traditional antivirus can’t recognize what it’s never seen. Tested, segregated backups mean an encrypted server is an inconvenience instead of a catastrophe, but only if someone has actually restored from them recently, not just confirmed the backup job ran.

Here’s the part that’s hardest to communicate to a business owner who’s never had a scare: none of this shows up as a line item you can point to and say that’s what saved us. Good monitoring is invisible by design. VJNetworks’ response time runs within 15 minutes, and when something in the environment starts behaving like ransomware, the process is to shut it down and roll it back immediately, not flag it for review the next business day. That speed is the entire point. Ransomware usually finishes encrypting a network in under an hour from first execution. Speed decides everything. A monitoring system that reviews alerts once a day is watching the wrong clock.

Locked server cabinet representing layered network security against ransomware

Twenty years of doing this for Rockland, Westchester, and Bergen County businesses teaches you one thing above everything else. The businesses that get hurt aren’t unlucky. They’re unmonitored.

Where to Start This Week

None of this requires a full security overhaul before Monday. It requires picking the biggest open door and closing it first.

  • Turn on MFA everywhere it isn’t already on, starting with email and anything reachable from outside the office.
  • Confirm the last backup restore test, not the last backup job. A job that “completed successfully” and a file that actually opens are two different claims.
  • Ask whoever handles patching how far behind the schedule currently runs. If nobody can answer that immediately, that’s the finding right there.

A free assessment covers all three in about an hour, with a written list of what’s actually open versus what only looks closed.

Straight Talk on Ransomware Risk

Is a 15-person company actually worth a ransomware crew’s time?
Yes, and the numbers back it up. Extortion malware showed up in 88% of small business breaches last year, nearly double the enterprise rate, because automated tooling makes a 15-person target almost as cheap to hit as a 1,500-person one.
What actually happens the moment ransomware lands on a network?
It starts scanning for files to encrypt within minutes. Fast. Quiet. The window between initial execution and full encryption is usually under an hour, which is why detection speed matters more than almost anything else in the defense stack.
Do we really need EDR if we already have antivirus?
Big difference, actually. Antivirus checks files against known threat signatures. EDR watches behavior, so it catches ransomware variants nobody has cataloged yet. Most small businesses running antivirus alone are only defended against attacks that were already identified months ago.
Is New York’s reporting requirement only for banks and insurers?
Only the 72-hour DFS reporting rule is that narrow. The SHIELD Act’s data security requirements reach further, covering any business holding a New York resident’s private information. A lot of owners assume the compliance layer doesn’t apply to them.
How fast should a monitored network actually respond to something suspicious?
Minutes, not hours. VJNetworks’ monitoring responds within 15 minutes, and a genuine anomaly gets terminated and rolled back before it spreads, not flagged for someone to review the next morning.

“Too small to target” was never really true. Not once. It’s just taken this long for the data to catch up to what attackers already knew. See VJNetworks’ managed IT services, read how we recommend evaluating an MSP before you sign anything, or if you’re ready now, a free assessment shows exactly where your gaps are, before anyone else finds them first. Businesses across Rockland County and the wider Tri-State area have relied on that same review for over 20 years.

Further reading: CISA’s #StopRansomware Guide covers the government’s current baseline recommendations in more depth.