Ransomware and Small Business: The Real Numbers

Les pièces de théâtre sont disponibles dans la langue que vous lisez. Touchez n'importe quel paragraphe pour commencer.

You have almost certainly read that 60% of small businesses close within six months of a cyberattack.

It appears everywhere. News outlets, vendor pages, government talks, conference slides.

There is one problem with it.

It is not true, and the organisation usually credited with it has publicly said so.

The National Cybersecurity Alliance issued a statement confirming the figure did not come from their research and that they cannot verify its source (National Cybersecurity Alliance, 2026).

So let us look at what the real numbers say instead. 🛡️

🎁 Compare Backup and Security Trials →

🧾 Principaux résultats en bref

Mesure Chiffre Source
The famous “60% close” figure Unverified, disavowed National Cybersecurity Alliance (2026)
SMBs going out of business after an attack About 19% Mastercard survey, cited 2026
Cyberattacks aimed at SMBs About 43% Astra (2026)
Ransomware present in SMB breaches 88% Rapport d'impact de Verizon (2025)
Same figure at large organisations 39% Rapport d'impact de Verizon (2025)
Average ransomware downtime About 24 days Huntress (2026)
Recovery cost, excluding ransom $1.53 million average Huntress (2026)
Typical small business range $120,000 to $1.24 million SQ Magazine (2026)

Ransomware and Small Business: The Real Numbers

🧟 The Statistic That Refuses to Die

This deserves proper attention, because it shapes how people think about the whole topic.

The 60% claim first appeared around 2011.

It has been repeated for roughly fifteen years without anyone producing the underlying study.

What the NCSA actually said

The National Cybersecurity Alliance is the body most often credited with the figure.

They published a statement noting the statistic was not generated from their research.

They also confirmed they cannot verify its original source.

They stopped using it in their own materials.

Why it spread so effectively

It is memorable, alarming and useful to anyone selling security products.

Each retelling cited the previous one rather than any primary source.

After enough repetitions, it looked like established fact.

📊 The myth against the measured figure

60% Widely repeated claim unverified 19% Measured in survey 5,000+ owners Sources: National Cybersecurity Alliance (2026) disavowal; Mastercard survey, cited 2026.

What the real number appears to be

A Mastercard survey covered more than 5,000 small business owners. Almost one in five who suffered an attack went out of business.

That is roughly 19%, not 60%.

Still serious. Still a fifth of affected businesses. But a third of the claim.

Why the correction matters

Inflated statistics do not make people safer.

They make the problem feel unsurvivable, which encourages fatalism rather than action.

And when someone discovers one figure was invented, they discount the accurate ones too.

🔎 Try Backup Tools Free →

🎯 Why Small Businesses Are Targeted

The genuine finding here is stark, and better evidenced than the myth.

Ransomware was present in 88% of breaches at small and mid-sized businesses (Verizon, 2025).

At large organisations the figure was 39%.

More than double the rate.

📊 Ransomware present in breaches, by organisation size

88% Small and mid-sized 39% Large organisations Source: Verizon Data Breach Investigations Report (2025).

Why the gap exists

Large organisations have security teams, tested backups and incident plans.

They still get attacked, but ransomware succeeds less often.

Small businesses are not attacked more because they are chosen. They are attacked more because attacks succeed.

The automation point

Most ransomware is not targeted at a specific company.

Automated tools scan for known weaknesses across the whole internet.

Being small does not make you invisible. It often makes you easier.

⏱️ What an Attack Actually Costs

The financial figures are wide, and the reason is worth knowing.

Cost element Typical scale
Downtime Around 24 days on average
Recovery excluding ransom $1.53 million average
Small business range $120,000 to $1.24 million
Ransom itself Highly variable, often not the largest cost
Lost customers Runs long after recovery

Note that the ransom is rarely the biggest line.

Twenty-four days of downtime destroys more value than most ransom demands.

Why downtime dominates

A business that cannot invoice, deliver or answer customers for three weeks is in serious trouble.

Staff still get paid. Rent still falls due.

Revenue stops while costs continue, and that gap is what closes companies.

The range tells you something

$120,000 to $1.24 million is an enormous spread.

The difference is almost entirely preparation.

Businesses with tested backups recover in days. Those without recover in weeks or never.

📊 Where the Money Actually Goes

Splitting the cost shows why preparation changes the outcome so much.

🥧 Typical ransomware cost breakdown

total cost Downtime and lost revenue Recovery and IT work Legal, notification, advice Ransom, where paid Indicative split. Downtime dominates (Huntress, 2026).

Notice how small the ransom slice is.

Most of the damage happens while the business cannot operate.

Why that changes what to spend on

If downtime is the main cost, the main defence is fast recovery.

That means tested backups, not just more prevention tools.

A business that restores in two days avoids most of the loss (SQ Magazine, 2026).

The sectors that suffer longest

Recovery times vary widely by industry.

Manufacturing tends to be slowest, because physical processes stop.

Financial firms recover fastest, largely because they rehearse it (Huntress, 2026).

💾 Why Backups Are the Whole Game

Ransomware works by making your data unavailable.

A working backup makes that threat far weaker.

But most backup setups fail at the moment they are needed.

Common failure Why it happens
Backup was never tested Nobody tried restoring
Backup drive was connected Encrypted along with everything else
Backup stopped months ago Failure alerts ignored
Only some data covered Nobody audited what was included
Restore takes too long Technically works, practically useless

The second row catches many businesses.

A backup drive left plugged in gets encrypted with the rest.

The rule that works

Keep at least one backup copy disconnected or immutable.

Cloud backups with versioning handle this well, since older versions survive.

The principle is simple: ransomware should not be able to reach every copy.

Test the restore, not the backup

This is the step nearly everyone skips.

A backup that runs successfully is not proof you can recover.

Restore a few real files, quarterly. It takes fifteen minutes.

Keep one backup off the domain

Attackers who gain administrator access often target backup systems first.

A backup managed by the same credentials as everything else can be deleted with everything else.

At least one copy should be outside that control, with separate credentials.

Know your restore time

Ask how long a full restore would actually take.

If the answer is a week, that is a week of downtime you have already accepted.

Notre analyse des coûts de violation covers why time dominates every cost calculation.

🚪 How Ransomware Gets In

The entry routes are unglamorous and mostly preventable.

Itinéraire Prévention
Stolen or reused credentials Multi-factor sign-in
Phishing email Staff awareness, email filtering
Unpatched software Automatic updates
Exposed remote access Close it or put it behind MFA
Compromised supplier Harder — ask about their security

Four of five are addressable without much budget.

Notre password research shows MFA cut account compromise by over 99%.

Remote access is the quiet one

Many small businesses expose remote desktop access to the internet.

It is convenient, and automated scanners find it within hours.

If you need remote access, it should sit behind MFA at minimum.

Updates matter more than antivirus

Most successful attacks use weaknesses that were already patched.

The patch existed. Nobody applied it.

Automatic updates are free and prevent more than most paid products.

💸 The Ransom Question

If it happens, should you pay? The honest answer is layered.

Law enforcement generally advises against it.

Payment funds further attacks and marks you as willing to pay.

What payment does not buy

It buys a decryption tool, from a criminal, with no guarantee.

Recovery after payment is often partial and slow.

And modern attacks steal data before encrypting, so payment does not prevent publication.

Why that last point changed everything

Ransomware used to be about locking files.

Now a large share of attacks also threaten to publish stolen data.

Backups solve the encryption problem but not the publication problem.

L'implication pratique

La prévention compte plus qu'auparavant, car la guérison est moins efficace qu'avant.

A perfect backup no longer makes you immune, only resilient.

🧾 Which Small Businesses Get Hit Hardest

Exposure is not evenly spread, and the pattern is predictable.

Facteur Raises risk? Pourquoi
Holding customer payment data Oui Higher value to attackers
Remote access exposed online Oui Found by automated scanners
Older unsupported software Yes, strongly Known weaknesses never patched
Supplier to larger firms Oui A route into bigger targets
No dedicated IT support Oui Nobody watching for signs
Regulated sector Cost, not likelihood Fines and notification duties

The supplier row deserves attention, because it surprises people.

A small firm can be attacked as a route into its largest customer.

That is why big companies increasingly ask suppliers about their security.

The unsupported software problem

Software past end of life stops receiving fixes entirely.

Every weakness found after that date stays open permanently.

Automated scanners specifically look for these versions (Astra, 2026).

Being a supplier changes your obligations

Larger customers may require evidence of controls before renewing contracts.

That turns security from a cost into a condition of trading.

Many small firms first take it seriously when a customer asks.

📋 What a Small Business Should Actually Do

Ranked by protection per pound spent.

Action Coût Effet
MFA on email and remote access Gratuit Blocks the most common entry
Automatic updates everywhere Gratuit Closes known weaknesses
One offline or immutable backup Faible Survives encryption
Quarterly restore test 15 minutes Proves the backup works
Close unused remote access Gratuit Removes a scanned target
Plan d'intervention d'une page An hour Saves days of confusion

Four of six cost nothing at all.

The gap between prepared and unprepared businesses is mostly attention, not budget.

Le plan d'intervention que personne ne rédige

Three questions on one page. Who decides? Who calls the insurer or lawyer? Who tells customers?

Deciding that during an incident costs days.

Deciding it in advance costs an hour.

Train staff on one thing, not everything

Security awareness training often tries to cover too much and lands nowhere.

Pick the single behaviour that matters most: report anything suspicious immediately, without blame.

Most incidents are noticed by an ordinary employee before any system flags them.

If people fear being blamed, they stay quiet, and hours are lost.

Cyber insurance, briefly

Policies increasingly require MFA and tested backups before paying out.

Read those conditions before assuming you are covered.

An insurer can decline if the required controls were not in place.

🚨 The First Hour, If It Happens

Most damage in the early stage comes from panic rather than the attack itself.

Knowing the sequence in advance is worth more than any single tool.

Order Action Pourquoi
1 Disconnect affected machines from the network Stops spread
2 Do not power them off Preserves evidence in memory
3 Check whether backups are reachable Determines your options
4 Notify insurer and legal contact Policies often require early notice
5 Start a written timeline Regulators will ask
6 Decide who speaks to customers Prevents mixed messages

Row two is counterintuitive and frequently got wrong.

Powering a machine off destroys evidence that helps investigators understand what happened.

Why the insurer comes early

Many policies require notification within a short window.

Some also require you to use their approved responders.

Calling your own specialist first can jeopardise the claim.

The notification clock

If personal data was involved, regulators often require reporting within 72 hours of discovery.

That clock starts when you find out, not when you finish investigating.

Notre analyse des coûts de violation covers how that timing drives cost.

Write it down as you go

Memory degrades fast during an incident.

A simple timestamped log answers most later questions from insurers and regulators.

It costs nothing and is almost never done.

🔬 How Reliable Is This Data?

Source Force Mise en garde
DBIR de Verizon Long-running, consistent method Incidents signalés uniquement
Mastercard SMB survey 5,000+ owners Self-reported
Security vendor statistics Practical detail They sell the solution
The 60% closure claim Aucun Disavowed by NCSA

That bottom row is the lesson of this article.

How to check a scary statistic

Trace it back until you reach an organisation that collected data.

If every citation points to another article, you have found a rumour.

A statistic with no primary source is not a statistic.

Why undercounting is likely too

Many small businesses never report attacks.

They pay quietly, or recover without telling anyone.

So real attack rates are probably higher than reported figures, even as closure rates are lower than claimed.

🧯 Why “We Are Too Small to Target” Is Wrong

This belief is the single most common reason small businesses do nothing.

It rests on a misunderstanding of how attacks actually work.

Nobody chose you

Most ransomware arrives through automated scanning, not selection.

Tools sweep the internet looking for exposed services and known weaknesses.

The attacker often learns who you are only after getting in.

Small does not mean cheap to attack

Automation removed the cost of trying.

Scanning a million addresses costs barely more than scanning a hundred.

So there is no economic reason to skip small targets.

What actually deters an automated attack

Not obscurity. Just being harder than the next result on the list.

Patched software, MFA and no exposed remote access are usually enough.

These attacks pursue the easiest available target, not the most valuable one.

The 43% figure in context

Around 43% of cyberattacks are aimed at small and mid-sized businesses (Astra, 2026).

That is close to half of all attacks hitting the segment least prepared for them.

Obscurity has not protected anyone for at least a decade.

🚫 Ce que ces données ne vous disent pas

It does not predict your risk. Sector and exposure vary enormously.

Survey data is self-reported. Owners may misremember causes.

Unreported attacks are invisible. The true rate is likely higher.

Cost ranges are extremely wide. Preparation drives most of the difference.

Much research is vendor-published. Fear supports sales.

🏁 La version courte

The famous claim that 60% of small businesses close after an attack has no verifiable source. The organisation credited with it has said so (National Cybersecurity Alliance, 2026).

The measured figure is closer to 19%, from a survey of over 5,000 owners.

The genuine finding is that ransomware appears in 88% of SMB breaches, against 39% at large organisations (Verizon, 2025).

Small businesses are not targeted more. Attacks against them succeed more.

Average downtime runs around 24 days, and downtime costs more than most ransoms.

Four of the six most effective protections are free: MFA, updates, closing remote access, and a written plan.

The fifth is one backup copy ransomware cannot reach. Test restoring it.

And treat the myth at the top of this article as a lesson in itself.

A frightening number repeated for fifteen years turned out to have no study behind it.

Before acting on any alarming statistic, trace it back to whoever collected the data.

If every citation points to another article, you have found a rumour rather than a finding. 🛡️

🚀 Browse Backup and Security Trials →

❓ Questions fréquemment posées

Do 60% of small businesses really close after a cyberattack?

No. The National Cybersecurity Alliance has stated the figure did not come from their research and cannot be verified. Survey data puts it nearer 19%.

Why is that number everywhere then?

It is memorable, alarming and useful to anyone selling security products. Each retelling cited the previous one rather than a study.

Are small businesses really targeted more?

Ransomware appears in 88% of SMB breaches against 39% at large organisations. The difference is that attacks succeed more often, not that attackers choose them.

How long does recovery take?

Average ransomware downtime is around 24 days, though prepared businesses recover far faster.

What does an attack cost a small business?

Typically $120,000 to $1.24 million. Downtime usually costs more than the ransom itself.

Should we pay the ransom?

Law enforcement advises against it. Payment buys a tool from a criminal with no guarantee, and does not stop stolen data being published.

What is the cheapest effective protection?

Multi-factor sign-in on email and remote access. It is free and blocks the most common entry route.

Why do backups fail when needed?

Usually because nobody tested a restore, or the backup drive was connected and got encrypted too.

Are we too small to be a target?

No. Most ransomware arrives through automated scanning rather than selection, and around 43% of attacks hit small and mid-sized businesses (Astra, 2026).

What should we do in the first hour?

Disconnect affected machines from the network but do not power them off, since that destroys evidence. Then check backups and notify your insurer.

Why does downtime cost more than the ransom?

Average downtime runs around 24 days. Revenue stops while wages and rent continue, and that gap is what closes businesses.

Does being a supplier increase our risk?

Yes. Small firms are attacked as a route into larger customers, which is why big companies now ask suppliers about their security.

Does cyber insurance cover this?

Increasingly only if you had MFA and tested backups in place. Read the conditions before assuming cover.

📚 Références

National Cybersecurity Alliance. (2026). Statement regarding incorrect small business statisticConsulté le 8 août 2026 sur https://www.staysafeonline.org/press/national-cyber-security-alliance-statement-regarding-incorrect-small-business-statistic

Verizon. (2025). rapport d'enquête sur les violations de données, cited in Huntress ransomware statistics. Retrieved August 8, 2026, from https://www.huntress.com/ransomware-guide/ransomware-attack-statistics

Astra. (2026). Small business cyber attack statisticsConsulté le 8 août 2026 sur https://www.getastra.com/blog/security-audit/small-business-cyber-attack-statistics/

SQ Magazine. (2026). Small business cybersecurity statistics: threats and costsConsulté le 8 août 2026 sur https://sqmagazine.co.uk/small-business-cybersecurity-statistics/

SC World. (2026). Most small businesses survive data breachesConsulté le 8 août 2026 sur https://www.scworld.com/news/most-small-businesses-survive-data-breaches-heres-how-to-make-sure-yours-does-too

Lectures complémentaires sur ce site

Notre password and MFA research covers the most common entry route in detail. See also our analyse des coûts de violation for what follows an incident, and the Répertoire des essais gratuits for backup and security trials.

À propos de cette analyse

This article corrects a statistic repeated across most competing coverage, using the disavowal published by the organisation usually credited with it. Where accurate figures exist they are used instead, with their sources named. Much research in this category is published by security vendors, where fear supports sales, and that is stated rather than hidden. Figures were checked on August 8, 2026.

Yam Bahadur Upkaroti

Laisser un commentaire

Retour en haut

Ne manquez jamais une offre

Nouveaux avis, baisses de prix et guides d’achat – de quelqu’un qui a réellement payé pour les outils.

Partenaire Moz