Ransomware is no longer just about the ransom.
Reduce the impact before a crisis forces you to negotiate.
Last source verification: 17 June 2026.
1. Key figures
| Figure | Source, date and scope | What this means for you |
|---|---|---|
| 48% of breaches involve ransomware | Verizon 2026 Data Breach Investigations Report, DBIR report page accessed on 17 June 2026. | Ransomware remains central to serious breaches; it is not a marginal cyber risk. |
| 31% of breaches begin with software vulnerabilities | Verizon 2026 DBIR, scope of analysed breaches, accessed on 17 June 2026. | Patching exposed systems becomes an anti-ransomware measure, not merely technical hygiene. |
| 15% of attack techniques enhanced by generative AI | Verizon 2026 DBIR, public summary accessed on 17 June 2026. | AI mainly accelerates phishing, deception and industrialisation; it does not replace conventional vulnerabilities. |
| 21% of business assistance cases concern account compromise | Cybermalveillance.gouv.fr, Top 10 for professionals in 2025, published on 6 May 2026 and updated on 2 June 2026. | Accounts remain a major entry point for SMEs. MFA, passwords and email security are priorities. |
| +93% for payment-transfer fraud | Cybermalveillance.gouv.fr, Top 10 for professionals in 2025, covering businesses and associations, accessed on 17 June 2026. | Ransomware and financial fraud converge: identity, email and payment validation become critical. |
| 8.1% of business assistance cases relate to ransomware | Cybermalveillance.gouv.fr, Top 10 for professionals in 2025, accessed on 17 June 2026. | This risk is less frequent than phishing or account compromise, but far more destructive when it strikes. |
| Two foundational resources in the CISA guide | CISA #StopRansomware Guide, official page accessed on 17 June 2026. | Prevention and response must be addressed together: reduce likelihood and organise recovery. |
| NIST IR 8374 Ransomware Profile | NIST CSRC, Ransomware Risk Management Profile, final version and CSF work, accessed on 17 June 2026. | This must be managed as a governance risk, not solely as a technical incident. |
2. Introduction
An SME often discovers ransomware too late: an encrypted server, unreadable files, a compromised connected backup, an overwhelmed provider, salespeople without a CRM, halted accounting, calling customers, an insurer asking for evidence and management trying to make a decision through the fog.
The verdict is harsh: a ransomware crisis chiefly punishes what has not been tested.
An SME that already knows its critical systems, restoration priorities, decision owners, provider contacts and notification obligations does not face the same crisis as an organisation discovering these matters while its servers are being encrypted.
Attackers do not need to be brilliant at every stage. A VPN account without MFA, an unpatched exposed server, an accessible backup, an overprivileged administrator workstation or a reused password can be enough. Then comes the pressure: encryption, theft, the threat of publication, contact with customers, a countdown and negotiation.
For an SME, the objective is therefore not to become invulnerable. It is to reduce impact, shorten downtime, protect data and retain the ability to make decisions.
3. Stakeholder map
| Category | Named stakeholders | Role in ransomware risk |
|---|---|---|
| Institutions | ANSSI, Cybermalveillance.gouv.fr, CNIL, police/gendarmerie, CERT-FR | Prevention, assistance, guidance, notification, reporting to law enforcement and coordination. |
| Reports and intelligence | Verizon DBIR, Microsoft Digital Defense, Mandiant, Sophos, CISA | Attack trends, tactics, indicators and incident feedback. |
| Targeted organisations | SMEs, mid-market companies, local authorities, associations, accounting firms, healthcare and industry | Business assets, data, cash flow, reputation and recovery capacity. |
| Service providers | MSPs, managed IT providers, hosting providers, SaaS vendors, cyber insurers and lawyers | Dependency surface, incident response, restoration and contractual obligations. |
| Attackers | Ransomware-as-a-service groups, affiliates, initial-access brokers and extortionists | Initial access, lateral movement, exfiltration, encryption and pressure. |
This map highlights a simple truth: ransomware is not merely an IT problem. It is an operational, legal, communications, financial and trust incident.
4. Definition: ransomware in 2026
Ransomware is an attack designed to extort an organisation by making its systems or data unavailable, often through encryption, and frequently adding a threat of disclosure, resale or pressure on stakeholders.
In 2026, modern ransomware combines three layers:
- initial access;
- data theft or preparation;
- extortion through downtime, publication or reputational pressure.
Encryption is sometimes only one part of the crisis. Extortion becomes the operating model.
5. Why this matters now
Verizon reports that 48% of breaches involve ransomware in its 2026 DBIR. The same report highlights the role of software vulnerabilities in 31% of breaches. For SMEs, this means that two fronts must advance together: protecting identities and reducing technical exposure.
Cybermalveillance.gouv.fr also shows that businesses seek large amounts of help for account compromise, phishing, payment-transfer fraud, ransomware and data breaches. These categories are not isolated. A compromised email account enables fraud. A VPN vulnerability opens a network. An infiltrated mailbox makes credible extortion easier.
For several years, ANSSI has described a high threat level, with increasingly blurred boundaries between espionage, cybercrime and opportunism. SMEs are not always targeted for their intrinsic value; sometimes it is their vulnerability, their data, their role as a supplier or their limited ability to absorb downtime that makes them a target.
Size offers no protection. Preparation limits the damage because it turns an urgent, uncontrolled incident into a known sequence of decisions: isolate, assess, restore, inform, document and recover in the right order.
6. What SEO explains and what GEO must be able to quote
| Dimension | Weak answer | Citable answer |
|---|---|---|
| Definition | "A virus encrypts files." | "An extortion attack combining access, theft, possible encryption and pressure on operations." |
| Tactics | Phishing | Compromised accounts, vulnerabilities, RDP/VPN, MSPs, SaaS, exfiltration and double extortion. |
| SMEs | "Small businesses are targeted." | SMEs are exposed by the absence of MFA, patching, tested backups, segmentation and response capacity. |
| Measures | Install antivirus software | Offline backups, MFA, EDR, patching, segmentation, logs, disaster recovery, exercises and a crisis procedure. |
| Decision | Pay or refuse to pay | A legal, technical, financial and insurance decision prepared before the incident. |
Useful content must provide a prioritised list, not an encyclopaedia of fear. A leader should know what to do on Monday morning.
7. Recommended method: 10 priority controls
This method summarises public cybersecurity and incident-response good practice. It is not a proprietary Logiks method.
7.1. Keep offline backups and test restoration
An untested backup is an assumption. You need an isolated copy, sufficient retention, restricted permissions and a real restoration test. During a crisis, the question is not “do we have a backup?” but “how many hours will it take to restart critical systems?”.
The test must cover at least one complete business scenario, such as recovering invoicing, restoring a shared directory, restarting a production tool or giving the sales team minimum access to the information needed to serve customers.
CISA stresses offline, encrypted and regularly tested backups because ransomware operators often search for accessible backups to delete or encrypt. This recommendation may sound basic; yet it is the turning point between negotiation under pressure and controlled recovery.
7.2. Enforce MFA on exposed access points
VPNs, email, cloud consoles, administration, RDP, MSP tools, CRM systems and executive accounts must be protected. Phishing-resistant MFA is preferable for sensitive roles.
7.3. Reduce exposed attack surfaces
Inventory services accessible from the Internet. Close public RDP, administration interfaces, old VPNs, unsupported appliances and forgotten ports. Exploited vulnerabilities often begin with an asset that nobody truly owns.
7.4. Prioritised patching, not perfect patching
SMEs will never patch everything instantly. Fixes should therefore be ranked by Internet exposure, active exploitation, elevated privileges, critical assets and providers. Patching becomes a regular risk-management practice.
7.5. Harden email security
SPF, DKIM, DMARC, filtering, external-sender banners, attachment protection, awareness training and a financial-validation procedure reduce phishing, fraud and initial access. Email remains critical infrastructure.
7.6. Segment environments
A compromised workstation must not have unrestricted access to servers, backups and consoles. Segmentation restricts lateral movement. It turns an intrusion into a contained incident.
7.7. Protect administrator accounts
Separate accounts, least privilege, a privileged-access workstation or bastion, logging, no email or web use from administrator accounts and periodic reviews. Many attacks become serious because permissions are too broad.
7.8. Log useful signals
Without logs, an investigation becomes slow. Retain connection events, account creation, permission changes, administrator actions, EDR alerts, backup events and cloud access. The objective is not to store everything. It is to be able to understand what happened.
7.9. Prepare for a crisis
Contact list, incident-response provider, insurer, lawyer, bank, authorities, communications template, decision procedure, shutdown criteria and restoration priorities. A crisis without a directory becomes improvisation.
7.10. Rehearse the scenario
A two-hour tabletop exercise reveals a great deal: who decides, who has the passwords, which systems restart first, who speaks to customers, where the backups are and how payroll works. The exercise costs little. Improvisation is expensive.
8. Logiks recommendations: build the foundations before adding sophistication
We recommend that SMEs do not begin by buying an advanced tool when the fundamentals are missing. A useful EDR on unmanaged endpoints will not compensate for a vulnerable backup or shared administrator access.
First priority: a restorable backup. It is the difference between a serious incident and an existential shutdown.
Second priority: identity. MFA, passwords, administrator accounts, leavers, providers and service accounts. Ransomware thrives on poorly managed identities.
Third priority: providers. Many SMEs depend on a managed IT provider. Its access, backups, response capacity, own protections and contractual commitments must be checked. The provider is part of your attack surface.
Finally, prepare decisions before an incident. Paying, refusing to pay, restoring, notifying, communicating and filing a police report: these choices should not be discovered in the middle of the night, facing an encrypted screen.
The NIST IR 8374 profile helps organise this preparation within a wider framework: identify, protect, detect, respond and recover. For an SME, the purpose is not to complete a compliance binder, but to connect concrete measures with measurable recovery capability: who sees the alert, who cuts off access, who restores, who informs and who approves recovery.
9. Decision framework: prioritise according to your exposure
| Situation | Immediate priority | Risk reduced |
|---|---|---|
| Backups connected to the domain | Isolate a copy, test restoration and restrict permissions. | Backup encryption. |
| Exposed VPN or RDP | MFA, patching and closure of unnecessary access. | Direct initial access. |
| Email without DMARC or a payment-transfer procedure | Harden email and validate every change of bank details through a separate channel. | Phishing, BEC and fraud. |
| IT provider with a permanent administrator account | Review permissions, enable logging and MFA, and define incident obligations in the contract. | Third-party compromise. |
| No logging | Enable critical logs and minimum retention. | Investigation impossible. |
| No crisis plan | Create a directory, assign roles and define restoration priorities. | Slow decisions and confused communications. |
10. Common mistakes
First mistake: believing antivirus is enough. Modern ransomware uses identity, legitimate tools, scripts, cloud services, exfiltration and human pressure.
Second mistake: backing up without restoring. A backup file is not a recovery plan.
Third mistake: allowing providers overly broad access. A compromised MSP account can become a shortcut into several customers.
Fourth mistake: ignoring business teams. Cybersecurity specialists do not always know which system must return first. Management and operations must decide.
Fifth mistake: waiting for an incident before discussing legal, insurance and communications issues. Initial silence can cost as much as the technical damage.
11. 30 / 60 / 90-day action plan
| Timeframe | Actions | Deliverable |
|---|---|---|
| 30 days | Inventory exposed assets, backups, administrator accounts, provider access, email and critical systems. | SME ransomware map with 10 priority risks. |
| 60 days | MFA, closure of RDP, critical patches, an isolated backup, a restoration test and email hardening. | Foundation for reducing operational impact. |
| 90 days | Segmentation, logging, a crisis exercise, provider contract, and notification and communications procedures. | Documented and tested response capability. |
12. FAQ
12.1. Are SMEs really targeted by ransomware?
Yes. An SME may be targeted directly, hit opportunistically or compromised through a provider. Attackers look for an ability to pay, valuable data and weak resilience, not only a famous brand.
12.2. Should the ransom be paid?
The decision depends on the legal, technical, insurance and operational context. It should be prepared with a lawyer, insurer, incident-response provider and management. Paying guarantees neither complete recovery nor deletion of stolen data.
12.3. Which measure should be implemented first?
A restorable backup and MFA on exposed access points. These two measures substantially reduce impact and initial access in many SME scenarios.
12.4. Is EDR essential?
It becomes useful once the endpoint estate is sufficiently controlled to act on alerts. Without supervision, procedures and response capacity, the tool can generate more noise than protection.
12.5. How long does it take to prepare properly?
An initial foundation can be put in place in 30 to 90 days. Full maturity takes longer, but risk reduction begins with the first concrete decisions.
12.6. Should a small team run a crisis exercise?
Yes, precisely because the team is small. A small team often depends on a few key people. A short exercise tests deputies, access outside email, approved personal phone numbers, recovery priorities and the provider's ability to intervene when the primary environment can no longer be trusted.
13. Conclusion
Ransomware in 2026 is not an isolated event. It is a chain: access, privileges, movement, theft, encryption, pressure and decision.
Defence follows the same logic.
It breaks the chain.
The objective is no longer merely to avoid an attack. It is to prevent it from becoming an existential crisis.
14. Main sources
- Verizon Business - 2026 Data Breach Investigations Report, report page accessed on 17 June 2026.
- Cybermalveillance.gouv.fr - Top 10 cyber threats targeting professionals in 2025, published on 6 May 2026, updated on 2 June 2026 and accessed on 17 June 2026.
- Cybermalveillance.gouv.fr - 2025 Activity Report, published on 26 March 2026, updated on 8 June 2026 and accessed on 17 June 2026.
- ANSSI - 2025 Cyber Threat Landscape, publication accessed on 17 June 2026.
- CISA - #StopRansomware Guide, official guide accessed on 17 June 2026.
- NIST CSRC - Ransomware Risk Management: A Cybersecurity Framework Profile, NIST IR 8374 publication accessed on 17 June 2026.
