Small businesses don’t get targeted by ransomware because they’re interesting. They get targeted because they’re profitable and poorly defended, and attackers do the math the same way any business does.
I’ve said this to clients for years, and I still watch the same disbelief cross their faces. Nobody wants to think a fifty-person accounting firm in Southern California is worth an attacker’s time. The numbers say otherwise, and they’ve been saying so for a while now.
The Numbers Behind Small Business Ransomware Protection
80% of small and midsize business breaches now involve ransomware, compared to 39% at large enterprises, according to Verizon’s 2025 Data Breach Investigations Report. That difference isn’t random. Larger companies have dedicated security staff, segmented networks, and faster patching. Most small firms have neither the headcount nor the budget for either one, and attackers know it.
Professional services firms specifically, law offices, accounting practices, and consulting firms, became one of the most heavily targeted sectors in ransomware data from the recovery firm Coveware. That tracks with what I see. These firms hold exactly what a ransomware operator wants: clients’ financial records, case files, personal data, and businesses that can’t afford to stay offline during tax season or a court deadline.
It’s Not Personal, and That’s the Point
I tell clients it used to feel personal. Some kid in a basement decides to mess with your business specifically. That’s mostly gone. Now it’s closer to pollution. It’s always pressing in from the outside, looking for a weak point, with no interest in who you are specifically. It just needs one person to click one link, because sending a million emails costs almost nothing and only one has to land.
That shift matters because it changes what “not a target” truly means. Nobody is deciding your firm doesn’t matter enough to attack. Nobody is deciding anything about your firm at all until the attack already worked.
I’ve had clients tell me their business is too boring to bother with, that they don’t have anything a criminal would want. I remind them that a ransomware operator doesn’t care what the business does. They care whether the firm can pay to retrieve its files and whether its defenses are weak enough to be worth the effort. A fifty-person accounting firm during tax season checks both boxes better than almost any target I can think of.
What Reduces Risk
Multi-factor authentication on every account, not just email, closes the door that stolen credentials alone used to open. It’s the single control I push hardest on, because it stops the most common way attackers get in with the least disruption to how your team works.
Endpoint security solutions that actively monitor and respond, not just antivirus software that scans on a schedule, catch the behavior of an attack in progress instead of waiting to recognize a known virus signature. The difference matters because most modern ransomware doesn’t look like the viruses that older antivirus tools were built to catch.
Backups that are tested, not just scheduled, are the difference between a bad week and a business-ending event. I’ve seen firms discover their backups had been silently failing for months, and they only found out during the one week they actually needed to restore something.
Incident response support, meaning an actual written plan for the first hour after something goes wrong, matters more than most firms expect. The firms that recover fastest aren’t the ones with the most expensive tools. They’re the ones who already know who to call, what to shut down first, and who’s authorized to make that call at two in the morning.
What This Costs vs. What an Attack Costs
Every one of these measures costs money and a little bit of friction for your staff. I won’t pretend MFA prompts are fun or that anyone enjoys a tabletop exercise for an incident that hasn’t happened yet.
Weigh that against a ransomware event that takes your firm offline during a filing deadline, a court date, or tax season, and the math stops being close. Most firms that get hit spend more recovering from a single incident than they would have spent on prevention for several years.
If you don’t know where your firm currently stands on any of this, that’s the actual starting point, not buying more software. Start with an honest look at your multi-factor authentication coverage, your backup testing, and whether anyone in your office could answer “what do we do first” if a ransomware alert went off tomorrow.




