{"id":5404,"date":"2026-09-12T09:00:00","date_gmt":"2026-09-12T09:00:00","guid":{"rendered":"https:\/\/yamuparkoti.com\/?p=5404"},"modified":"2026-08-21T19:38:26","modified_gmt":"2026-08-21T19:38:26","slug":"ransomware-xiao-qiye-data","status":"publish","type":"post","link":"https:\/\/yamuparkoti.com\/zh\/ransomware-small-business-data\/","title":{"rendered":"Ransomware and Small Business: The Real Numbers"},"content":{"rendered":"<p>You have almost certainly read that <strong>60% of small businesses close within six months of a cyberattack<\/strong>.<\/p>\n<p>It appears everywhere. News outlets, vendor pages, government talks, conference slides.<\/p>\n<p>There is one problem with it.<\/p>\n<p><strong>It is not true, and the organisation usually credited with it has publicly said so.<\/strong><\/p>\n<p>The National Cybersecurity Alliance issued a statement confirming the figure did not come from their research and that they cannot verify its source (National Cybersecurity Alliance, 2026).<\/p>\n<p>So let us look at what the real numbers say instead. \ud83d\udee1\ufe0f<\/p>\n<p style=\"text-align:center;margin:28px 0;\"><a href=\"https:\/\/yamuparkoti.com\/freetrialinsider\/\" style=\"display:inline-block;background:linear-gradient(90deg,#ff8f6b,#ffc46b);color:#0b1219;font-weight:800;padding:16px 40px;border-radius:12px;text-decoration:none;font-size:18px;\">\ud83c\udf81 Compare Backup and Security Trials \u2192<\/a><\/p>\n<h2>\ud83e\uddfe \u4e3b\u8981\u53d1\u73b0\u6982\u89c8<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u63aa\u65bd<\/th>\n<th>\u6570\u5b57<\/th>\n<th>\u6765\u6e90<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>The famous &#8220;60% close&#8221; figure<\/td>\n<td><strong>Unverified, disavowed<\/strong><\/td>\n<td>National Cybersecurity Alliance (2026)<\/td>\n<\/tr>\n<tr>\n<td>SMBs going out of business after an attack<\/td>\n<td><strong>About 19%<\/strong><\/td>\n<td>Mastercard survey, cited 2026<\/td>\n<\/tr>\n<tr>\n<td>Cyberattacks aimed at SMBs<\/td>\n<td>About 43%<\/td>\n<td>Astra (2026)<\/td>\n<\/tr>\n<tr>\n<td>Ransomware present in SMB breaches<\/td>\n<td><strong>88%<\/strong><\/td>\n<td>Verizon DBIR (2025)<\/td>\n<\/tr>\n<tr>\n<td>Same figure at large organisations<\/td>\n<td>39%<\/td>\n<td>Verizon DBIR (2025)<\/td>\n<\/tr>\n<tr>\n<td>Average ransomware downtime<\/td>\n<td>About 24 days<\/td>\n<td>Huntress (2026)<\/td>\n<\/tr>\n<tr>\n<td>Recovery cost, excluding ransom<\/td>\n<td><strong>$1.53 million average<\/strong><\/td>\n<td>Huntress (2026)<\/td>\n<\/tr>\n<tr>\n<td>Typical small business range<\/td>\n<td>$120,000 to $1.24 million<\/td>\n<td>SQ Magazine (2026)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><img decoding=\"async\" src=\"https:\/\/yamuparkoti.com\/wp-content\/uploads\/2026\/08\/ransomware-small-business-data-featured.png\" alt=\"Ransomware and Small Business: The Real Numbers\" \/><\/p>\n<h2>\ud83e\udddf The Statistic That Refuses to Die<\/h2>\n<p>This deserves proper attention, because it shapes how people think about the whole topic.<\/p>\n<p>The 60% claim first appeared around 2011.<\/p>\n<p>It has been repeated for roughly fifteen years without anyone producing the underlying study.<\/p>\n<h3>What the NCSA actually said<\/h3>\n<p>The National Cybersecurity Alliance is the body most often credited with the figure.<\/p>\n<p>They published a statement noting the statistic was not generated from their research.<\/p>\n<p><strong>They also confirmed they cannot verify its original source.<\/strong><\/p>\n<p>They stopped using it in their own materials.<\/p>\n<h3>Why it spread so effectively<\/h3>\n<p>It is memorable, alarming and useful to anyone selling security products.<\/p>\n<p>Each retelling cited the previous one rather than any primary source.<\/p>\n<p>After enough repetitions, it looked like established fact.<\/p>\n<div style=\"background:#0f1720;border-radius:14px;padding:26px;margin:24px 0;\">\n<p style=\"color:#ff8f6b;font-weight:800;font-size:18px;margin-bottom:14px;\">\ud83d\udcca The myth against the measured figure<\/p>\n<p><svg viewbox=\"0 0 640 240\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Bar chart comparing the debunked 60 percent claim with the measured 19 percent\">\n<line x1=\"230\" y1=\"20\" x2=\"230\" y2=\"180\" stroke=\"#31414f\" stroke-width=\"2\"\/>\n<rect x=\"230\" y=\"38\" width=\"330\" height=\"42\" fill=\"#5f7f95\" rx=\"5\"\/>\n<text x=\"572\" y=\"66\" fill=\"#fff\" font-size=\"17\" font-weight=\"bold\">60%<\/text>\n<text x=\"220\" y=\"60\" fill=\"#9fb2c0\" font-size=\"13\" text-anchor=\"end\">Widely repeated claim<\/text>\n<text x=\"220\" y=\"78\" fill=\"#e2795c\" font-size=\"12\" text-anchor=\"end\">unverified<\/text>\n<rect x=\"230\" y=\"106\" width=\"104\" height=\"42\" fill=\"#ff8f6b\" rx=\"5\"\/>\n<text x=\"346\" y=\"134\" fill=\"#fff\" font-size=\"17\" font-weight=\"bold\">19%<\/text>\n<text x=\"220\" y=\"128\" fill=\"#9fb2c0\" font-size=\"13\" text-anchor=\"end\">Measured in survey<\/text>\n<text x=\"220\" y=\"146\" fill=\"#5ad1a5\" font-size=\"12\" text-anchor=\"end\">5,000+ owners<\/text>\n<text x=\"55\" y=\"208\" fill=\"#9fb2c0\" font-size=\"13\">Sources: National Cybersecurity Alliance (2026) disavowal; Mastercard survey, cited 2026.<\/text>\n<\/svg>\n<\/div>\n<h3>What the real number appears to be<\/h3>\n<p>A Mastercard survey covered more than 5,000 small business owners. Almost one in five who suffered an attack went out of business.<\/p>\n<p>That is roughly 19%, not 60%.<\/p>\n<p><strong>Still serious. Still a fifth of affected businesses. But a third of the claim.<\/strong><\/p>\n<h3>Why the correction matters<\/h3>\n<p>Inflated statistics do not make people safer.<\/p>\n<p>They make the problem feel unsurvivable, which encourages fatalism rather than action.<\/p>\n<p>And when someone discovers one figure was invented, they discount the accurate ones too.<\/p>\n<p style=\"text-align:center;margin:28px 0;\"><a href=\"https:\/\/yamuparkoti.com\/freetrialinsider\/\" style=\"display:inline-block;background:linear-gradient(90deg,#ff8f6b,#ffc46b);color:#0b1219;font-weight:800;padding:16px 40px;border-radius:12px;text-decoration:none;font-size:18px;\">\ud83d\udd0e Try Backup Tools Free \u2192<\/a><\/p>\n<h2>\ud83c\udfaf Why Small Businesses Are Targeted<\/h2>\n<p>The genuine finding here is stark, and better evidenced than the myth.<\/p>\n<p><strong>Ransomware was present in 88% of breaches at small and mid-sized businesses<\/strong> (Verizon, 2025).<\/p>\n<p>At large organisations the figure was 39%.<\/p>\n<p>More than double the rate.<\/p>\n<div style=\"background:#0f1720;border-radius:14px;padding:26px;margin:24px 0;\">\n<p style=\"color:#ff8f6b;font-weight:800;font-size:18px;margin-bottom:14px;\">\ud83d\udcca Ransomware present in breaches, by organisation size<\/p>\n<p><svg viewbox=\"0 0 640 230\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Bar chart comparing ransomware presence in SMB and large organisation breaches\">\n<line x1=\"220\" y1=\"20\" x2=\"220\" y2=\"180\" stroke=\"#31414f\" stroke-width=\"2\"\/>\n<rect x=\"220\" y=\"40\" width=\"340\" height=\"42\" fill=\"#e2795c\" rx=\"5\"\/>\n<text x=\"576\" y=\"68\" fill=\"#fff\" font-size=\"17\" font-weight=\"bold\">88%<\/text>\n<text x=\"210\" y=\"68\" fill=\"#9fb2c0\" font-size=\"13\" text-anchor=\"end\">Small and mid-sized<\/text>\n<rect x=\"220\" y=\"106\" width=\"151\" height=\"42\" fill=\"#5ad1a5\" rx=\"5\"\/>\n<text x=\"387\" y=\"134\" fill=\"#fff\" font-size=\"17\" font-weight=\"bold\">39%<\/text>\n<text x=\"210\" y=\"134\" fill=\"#9fb2c0\" font-size=\"13\" text-anchor=\"end\">Large organisations<\/text>\n<text x=\"55\" y=\"206\" fill=\"#9fb2c0\" font-size=\"13\">Source: Verizon Data Breach Investigations Report (2025).<\/text>\n<\/svg>\n<\/div>\n<h3>Why the gap exists<\/h3>\n<p>Large organisations have security teams, tested backups and incident plans.<\/p>\n<p>They still get attacked, but ransomware succeeds less often.<\/p>\n<p><strong>Small businesses are not attacked more because they are chosen. They are attacked more because attacks succeed.<\/strong><\/p>\n<h3>The automation point<\/h3>\n<p>Most ransomware is not targeted at a specific company.<\/p>\n<p>Automated tools scan for known weaknesses across the whole internet.<\/p>\n<p>Being small does not make you invisible. It often makes you easier.<\/p>\n<h2>\u23f1\ufe0f What an Attack Actually Costs<\/h2>\n<p>The financial figures are wide, and the reason is worth knowing.<\/p>\n<table>\n<thead>\n<tr>\n<th>Cost element<\/th>\n<th>Typical scale<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Downtime<\/td>\n<td><strong>Around 24 days on average<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Recovery excluding ransom<\/td>\n<td>$1.53 million average<\/td>\n<\/tr>\n<tr>\n<td>Small business range<\/td>\n<td><strong>$120,000 to $1.24 million<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Ransom itself<\/td>\n<td>Highly variable, often not the largest cost<\/td>\n<\/tr>\n<tr>\n<td>Lost customers<\/td>\n<td>Runs long after recovery<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Note that the ransom is rarely the biggest line.<\/p>\n<p><strong>Twenty-four days of downtime destroys more value than most ransom demands.<\/strong><\/p>\n<h3>Why downtime dominates<\/h3>\n<p>A business that cannot invoice, deliver or answer customers for three weeks is in serious trouble.<\/p>\n<p>Staff still get paid. Rent still falls due.<\/p>\n<p>Revenue stops while costs continue, and that gap is what closes companies.<\/p>\n<h3>The range tells you something<\/h3>\n<p>$120,000 to $1.24 million is an enormous spread.<\/p>\n<p>The difference is almost entirely preparation.<\/p>\n<p>Businesses with tested backups recover in days. Those without recover in weeks or never.<\/p>\n<h2>\ud83d\udcca Where the Money Actually Goes<\/h2>\n<p>Splitting the cost shows why preparation changes the outcome so much.<\/p>\n<div style=\"background:#0f1720;border-radius:14px;padding:26px;margin:24px 0;\">\n<p style=\"color:#ff8f6b;font-weight:800;font-size:18px;margin-bottom:14px;\">\ud83e\udd67 Typical ransomware cost breakdown<\/p>\n<p><svg viewbox=\"0 0 640 250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Pie chart of ransomware cost components\">\n<circle cx=\"150\" cy=\"125\" r=\"88\" fill=\"none\" stroke=\"#e2795c\" stroke-width=\"44\" stroke-dasharray=\"243 553\" transform=\"rotate(-90 150 125)\"\/>\n<circle cx=\"150\" cy=\"125\" r=\"88\" fill=\"none\" stroke=\"#f0b429\" stroke-width=\"44\" stroke-dasharray=\"133 553\" stroke-dashoffset=\"-243\" transform=\"rotate(-90 150 125)\"\/>\n<circle cx=\"150\" cy=\"125\" r=\"88\" fill=\"none\" stroke=\"#6cc7f5\" stroke-width=\"44\" stroke-dasharray=\"94 553\" stroke-dashoffset=\"-376\" transform=\"rotate(-90 150 125)\"\/>\n<circle cx=\"150\" cy=\"125\" r=\"88\" fill=\"none\" stroke=\"#5f7f95\" stroke-width=\"44\" stroke-dasharray=\"83 553\" stroke-dashoffset=\"-470\" transform=\"rotate(-90 150 125)\"\/>\n<text x=\"150\" y=\"132\" fill=\"#fff\" font-size=\"19\" text-anchor=\"middle\" font-weight=\"bold\">total cost<\/text>\n<rect x=\"300\" y=\"50\" width=\"16\" height=\"16\" fill=\"#e2795c\" rx=\"4\"\/><text x=\"326\" y=\"63\" fill=\"#fff\" font-size=\"14\">Downtime and lost revenue<\/text>\n<rect x=\"300\" y=\"86\" width=\"16\" height=\"16\" fill=\"#f0b429\" rx=\"4\"\/><text x=\"326\" y=\"99\" fill=\"#fff\" font-size=\"14\">Recovery and IT work<\/text>\n<rect x=\"300\" y=\"122\" width=\"16\" height=\"16\" fill=\"#6cc7f5\" rx=\"4\"\/><text x=\"326\" y=\"135\" fill=\"#fff\" font-size=\"14\">Legal, notification, advice<\/text>\n<rect x=\"300\" y=\"158\" width=\"16\" height=\"16\" fill=\"#5f7f95\" rx=\"4\"\/><text x=\"326\" y=\"171\" fill=\"#fff\" font-size=\"14\">Ransom, where paid<\/text>\n<text x=\"300\" y=\"208\" fill=\"#9fb2c0\" font-size=\"13\">Indicative split. Downtime dominates (Huntress, 2026).<\/text>\n<\/svg>\n<\/div>\n<p>Notice how small the ransom slice is.<\/p>\n<p><strong>Most of the damage happens while the business cannot operate.<\/strong><\/p>\n<h3>Why that changes what to spend on<\/h3>\n<p>If downtime is the main cost, the main defence is fast recovery.<\/p>\n<p>That means tested backups, not just more prevention tools.<\/p>\n<p>A business that restores in two days avoids most of the loss (SQ Magazine, 2026).<\/p>\n<h3>The sectors that suffer longest<\/h3>\n<p>Recovery times vary widely by industry.<\/p>\n<p>Manufacturing tends to be slowest, because physical processes stop.<\/p>\n<p>Financial firms recover fastest, largely because they rehearse it (Huntress, 2026).<\/p>\n<h2>\ud83d\udcbe Why Backups Are the Whole Game<\/h2>\n<p>Ransomware works by making your data unavailable.<\/p>\n<p>A working backup makes that threat far weaker.<\/p>\n<p>But most backup setups fail at the moment they are needed.<\/p>\n<table>\n<thead>\n<tr>\n<th>Common failure<\/th>\n<th>Why it happens<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Backup was never tested<\/td>\n<td><strong>Nobody tried restoring<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Backup drive was connected<\/td>\n<td>Encrypted along with everything else<\/td>\n<\/tr>\n<tr>\n<td>Backup stopped months ago<\/td>\n<td>Failure alerts ignored<\/td>\n<\/tr>\n<tr>\n<td>Only some data covered<\/td>\n<td>Nobody audited what was included<\/td>\n<\/tr>\n<tr>\n<td>Restore takes too long<\/td>\n<td><strong>Technically works, practically useless<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The second row catches many businesses.<\/p>\n<p><strong>A backup drive left plugged in gets encrypted with the rest.<\/strong><\/p>\n<h3>The rule that works<\/h3>\n<p>Keep at least one backup copy disconnected or immutable.<\/p>\n<p>Cloud backups with versioning handle this well, since older versions survive.<\/p>\n<p>The principle is simple: ransomware should not be able to reach every copy.<\/p>\n<h3>Test the restore, not the backup<\/h3>\n<p>This is the step nearly everyone skips.<\/p>\n<p>A backup that runs successfully is not proof you can recover.<\/p>\n<p>Restore a few real files, quarterly. It takes fifteen minutes.<\/p>\n<h3>Keep one backup off the domain<\/h3>\n<p>Attackers who gain administrator access often target backup systems first.<\/p>\n<p>A backup managed by the same credentials as everything else can be deleted with everything else.<\/p>\n<p><strong>At least one copy should be outside that control, with separate credentials.<\/strong><\/p>\n<h3>Know your restore time<\/h3>\n<p>Ask how long a full restore would actually take.<\/p>\n<p>If the answer is a week, that is a week of downtime you have already accepted.<\/p>\n<p>\u6211\u4eec\u7684 <a href=\"https:\/\/yamuparkoti.com\/data-breach-cost-2026\/\">breach cost analysis<\/a> covers why time dominates every cost calculation.<\/p>\n<h2>\ud83d\udeaa How Ransomware Gets In<\/h2>\n<p>The entry routes are unglamorous and mostly preventable.<\/p>\n<table>\n<thead>\n<tr>\n<th>\u8def\u7ebf<\/th>\n<th>\u9884\u9632<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Stolen or reused credentials<\/td>\n<td><strong>Multi-factor sign-in<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Phishing email<\/td>\n<td>Staff awareness, email filtering<\/td>\n<\/tr>\n<tr>\n<td>Unpatched software<\/td>\n<td>Automatic updates<\/td>\n<\/tr>\n<tr>\n<td>Exposed remote access<\/td>\n<td><strong>Close it or put it behind MFA<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Compromised supplier<\/td>\n<td>Harder \u2014 ask about their security<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Four of five are addressable without much budget.<\/p>\n<p>\u6211\u4eec\u7684 <a href=\"https:\/\/yamuparkoti.com\/password-breach-statistics\/\">password research<\/a> shows MFA cut account compromise by over 99%.<\/p>\n<h3>Remote access is the quiet one<\/h3>\n<p>Many small businesses expose remote desktop access to the internet.<\/p>\n<p>It is convenient, and automated scanners find it within hours.<\/p>\n<p>If you need remote access, it should sit behind MFA at minimum.<\/p>\n<h3>Updates matter more than antivirus<\/h3>\n<p>Most successful attacks use weaknesses that were already patched.<\/p>\n<p>The patch existed. Nobody applied it.<\/p>\n<p><strong>Automatic updates are free and prevent more than most paid products.<\/strong><\/p>\n<h2>\ud83d\udcb8 The Ransom Question<\/h2>\n<p>If it happens, should you pay? The honest answer is layered.<\/p>\n<p>Law enforcement generally advises against it.<\/p>\n<p>Payment funds further attacks and marks you as willing to pay.<\/p>\n<h3>What payment does not buy<\/h3>\n<p>It buys a decryption tool, from a criminal, with no guarantee.<\/p>\n<p>Recovery after payment is often partial and slow.<\/p>\n<p>And modern attacks steal data before encrypting, so payment does not prevent publication.<\/p>\n<h3>Why that last point changed everything<\/h3>\n<p>Ransomware used to be about locking files.<\/p>\n<p>Now a large share of attacks also threaten to publish stolen data.<\/p>\n<p><strong>Backups solve the encryption problem but not the publication problem.<\/strong><\/p>\n<h3>\u5b9e\u9645\u610f\u4e49<\/h3>\n<p>\u9884\u9632\u6bd4\u4ee5\u524d\u66f4\u91cd\u8981\u4e86\uff0c\u56e0\u4e3a\u8865\u6551\u63aa\u65bd\u7684\u4f5c\u7528\u6bd4\u4ee5\u524d\u5c0f\u4e86\u3002<\/p>\n<p>A perfect backup no longer makes you immune, only resilient.<\/p>\n<h2>\ud83e\uddfe Which Small Businesses Get Hit Hardest<\/h2>\n<p>Exposure is not evenly spread, and the pattern is predictable.<\/p>\n<table>\n<thead>\n<tr>\n<th>\u56e0\u7d20<\/th>\n<th>Raises risk?<\/th>\n<th>\u4e3a\u4ec0\u4e48<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Holding customer payment data<\/td>\n<td><strong>\u662f\u7684<\/strong><\/td>\n<td>Higher value to attackers<\/td>\n<\/tr>\n<tr>\n<td>Remote access exposed online<\/td>\n<td>\u662f\u7684<\/td>\n<td>Found by automated scanners<\/td>\n<\/tr>\n<tr>\n<td>Older unsupported software<\/td>\n<td><strong>Yes, strongly<\/strong><\/td>\n<td>Known weaknesses never patched<\/td>\n<\/tr>\n<tr>\n<td>Supplier to larger firms<\/td>\n<td>\u662f\u7684<\/td>\n<td>A route into bigger targets<\/td>\n<\/tr>\n<tr>\n<td>No dedicated IT support<\/td>\n<td>\u662f\u7684<\/td>\n<td>Nobody watching for signs<\/td>\n<\/tr>\n<tr>\n<td>Regulated sector<\/td>\n<td>Cost, not likelihood<\/td>\n<td>Fines and notification duties<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The supplier row deserves attention, because it surprises people.<\/p>\n<p><strong>A small firm can be attacked as a route into its largest customer.<\/strong><\/p>\n<p>That is why big companies increasingly ask suppliers about their security.<\/p>\n<h3>The unsupported software problem<\/h3>\n<p>Software past end of life stops receiving fixes entirely.<\/p>\n<p>Every weakness found after that date stays open permanently.<\/p>\n<p>Automated scanners specifically look for these versions (Astra, 2026).<\/p>\n<h3>Being a supplier changes your obligations<\/h3>\n<p>Larger customers may require evidence of controls before renewing contracts.<\/p>\n<p>That turns security from a cost into a condition of trading.<\/p>\n<p>Many small firms first take it seriously when a customer asks.<\/p>\n<h2>\ud83d\udccb What a Small Business Should Actually Do<\/h2>\n<p>Ranked by protection per pound spent.<\/p>\n<table>\n<thead>\n<tr>\n<th>\u884c\u52a8<\/th>\n<th>\u6210\u672c<\/th>\n<th>Effect<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>MFA on email and remote access<\/td>\n<td><strong>\u81ea\u7531\u7684<\/strong><\/td>\n<td>Blocks the most common entry<\/td>\n<\/tr>\n<tr>\n<td>Automatic updates everywhere<\/td>\n<td>\u81ea\u7531\u7684<\/td>\n<td>Closes known weaknesses<\/td>\n<\/tr>\n<tr>\n<td>One offline or immutable backup<\/td>\n<td>\u4f4e\u7684<\/td>\n<td><strong>Survives encryption<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Quarterly restore test<\/td>\n<td>15\u5206\u949f<\/td>\n<td>Proves the backup works<\/td>\n<\/tr>\n<tr>\n<td>Close unused remote access<\/td>\n<td>\u81ea\u7531\u7684<\/td>\n<td>Removes a scanned target<\/td>\n<\/tr>\n<tr>\n<td>\u5355\u9875\u4e8b\u4ef6\u8ba1\u5212<\/td>\n<td>An hour<\/td>\n<td>Saves days of confusion<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Four of six cost nothing at all.<\/p>\n<p><strong>The gap between prepared and unprepared businesses is mostly attention, not budget.<\/strong><\/p>\n<h3>\u6ca1\u4eba\u5199\u7684\u5e94\u6025\u9884\u6848<\/h3>\n<p>Three questions on one page. Who decides? Who calls the insurer or lawyer? Who tells customers?<\/p>\n<p>Deciding that during an incident costs days.<\/p>\n<p>Deciding it in advance costs an hour.<\/p>\n<h3>Train staff on one thing, not everything<\/h3>\n<p>Security awareness training often tries to cover too much and lands nowhere.<\/p>\n<p>Pick the single behaviour that matters most: report anything suspicious immediately, without blame.<\/p>\n<p><strong>Most incidents are noticed by an ordinary employee before any system flags them.<\/strong><\/p>\n<p>If people fear being blamed, they stay quiet, and hours are lost.<\/p>\n<h3>Cyber insurance, briefly<\/h3>\n<p>Policies increasingly require MFA and tested backups before paying out.<\/p>\n<p>Read those conditions before assuming you are covered.<\/p>\n<p>An insurer can decline if the required controls were not in place.<\/p>\n<h2>\ud83d\udea8 The First Hour, If It Happens<\/h2>\n<p>Most damage in the early stage comes from panic rather than the attack itself.<\/p>\n<p>Knowing the sequence in advance is worth more than any single tool.<\/p>\n<table>\n<thead>\n<tr>\n<th>Order<\/th>\n<th>\u884c\u52a8<\/th>\n<th>\u4e3a\u4ec0\u4e48<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>1<\/td>\n<td><strong>Disconnect affected machines from the network<\/strong><\/td>\n<td>Stops spread<\/td>\n<\/tr>\n<tr>\n<td>2<\/td>\n<td>Do not power them off<\/td>\n<td>Preserves evidence in memory<\/td>\n<\/tr>\n<tr>\n<td>3<\/td>\n<td>Check whether backups are reachable<\/td>\n<td>Determines your options<\/td>\n<\/tr>\n<tr>\n<td>4<\/td>\n<td>Notify insurer and legal contact<\/td>\n<td><strong>Policies often require early notice<\/strong><\/td>\n<\/tr>\n<tr>\n<td>5<\/td>\n<td>Start a written timeline<\/td>\n<td>Regulators will ask<\/td>\n<\/tr>\n<tr>\n<td>6<\/td>\n<td>Decide who speaks to customers<\/td>\n<td>Prevents mixed messages<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Row two is counterintuitive and frequently got wrong.<\/p>\n<p><strong>Powering a machine off destroys evidence that helps investigators understand what happened.<\/strong><\/p>\n<h3>Why the insurer comes early<\/h3>\n<p>Many policies require notification within a short window.<\/p>\n<p>Some also require you to use their approved responders.<\/p>\n<p>Calling your own specialist first can jeopardise the claim.<\/p>\n<h3>The notification clock<\/h3>\n<p>If personal data was involved, regulators often require reporting within 72 hours of discovery.<\/p>\n<p>That clock starts when you find out, not when you finish investigating.<\/p>\n<p>\u6211\u4eec\u7684 <a href=\"https:\/\/yamuparkoti.com\/data-breach-cost-2026\/\">breach cost analysis<\/a> covers how that timing drives cost.<\/p>\n<h3>Write it down as you go<\/h3>\n<p>Memory degrades fast during an incident.<\/p>\n<p>A simple timestamped log answers most later questions from insurers and regulators.<\/p>\n<p>It costs nothing and is almost never done.<\/p>\n<h2>\ud83d\udd2c How Reliable Is This Data?<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u6765\u6e90<\/th>\n<th>\u529b\u91cf<\/th>\n<th>Caveat<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Verizon DBIR<\/td>\n<td><strong>Long-running, consistent method<\/strong><\/td>\n<td>Reported incidents only<\/td>\n<\/tr>\n<tr>\n<td>Mastercard SMB survey<\/td>\n<td>5,000+ owners<\/td>\n<td>Self-reported<\/td>\n<\/tr>\n<tr>\n<td>Security vendor statistics<\/td>\n<td>Practical detail<\/td>\n<td><strong>They sell the solution<\/strong><\/td>\n<\/tr>\n<tr>\n<td>The 60% closure claim<\/td>\n<td>\u6ca1\u6709\u4efb\u4f55<\/td>\n<td><strong>Disavowed by NCSA<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>That bottom row is the lesson of this article.<\/p>\n<h3>How to check a scary statistic<\/h3>\n<p>Trace it back until you reach an organisation that collected data.<\/p>\n<p>If every citation points to another article, you have found a rumour.<\/p>\n<p><strong>A statistic with no primary source is not a statistic.<\/strong><\/p>\n<h3>Why undercounting is likely too<\/h3>\n<p>Many small businesses never report attacks.<\/p>\n<p>They pay quietly, or recover without telling anyone.<\/p>\n<p>So real attack rates are probably higher than reported figures, even as closure rates are lower than claimed.<\/p>\n<h2>\ud83e\uddef Why &#8220;We Are Too Small to Target&#8221; Is Wrong<\/h2>\n<p>This belief is the single most common reason small businesses do nothing.<\/p>\n<p>It rests on a misunderstanding of how attacks actually work.<\/p>\n<h3>Nobody chose you<\/h3>\n<p>Most ransomware arrives through automated scanning, not selection.<\/p>\n<p>Tools sweep the internet looking for exposed services and known weaknesses.<\/p>\n<p><strong>The attacker often learns who you are only after getting in.<\/strong><\/p>\n<h3>Small does not mean cheap to attack<\/h3>\n<p>Automation removed the cost of trying.<\/p>\n<p>Scanning a million addresses costs barely more than scanning a hundred.<\/p>\n<p>So there is no economic reason to skip small targets.<\/p>\n<h3>What actually deters an automated attack<\/h3>\n<p>Not obscurity. Just being harder than the next result on the list.<\/p>\n<p>Patched software, MFA and no exposed remote access are usually enough.<\/p>\n<p>These attacks pursue the easiest available target, not the most valuable one.<\/p>\n<h3>The 43% figure in context<\/h3>\n<p>Around 43% of cyberattacks are aimed at small and mid-sized businesses (Astra, 2026).<\/p>\n<p>That is close to half of all attacks hitting the segment least prepared for them.<\/p>\n<p>Obscurity has not protected anyone for at least a decade.<\/p>\n<h2>\ud83d\udeab \u8fd9\u4e9b\u6570\u636e\u65e0\u6cd5\u544a\u8bc9\u4f60\u4ec0\u4e48<\/h2>\n<p><strong>It does not predict your risk.<\/strong> Sector and exposure vary enormously.<\/p>\n<p><strong>Survey data is self-reported.<\/strong> Owners may misremember causes.<\/p>\n<p><strong>Unreported attacks are invisible.<\/strong> The true rate is likely higher.<\/p>\n<p><strong>Cost ranges are extremely wide.<\/strong> Preparation drives most of the difference.<\/p>\n<p><strong>Much research is vendor-published.<\/strong> Fear supports sales.<\/p>\n<h2>\ud83c\udfc1 \u7b80\u77ed\u7248<\/h2>\n<p>The famous claim that 60% of small businesses close after an attack has no verifiable source. The organisation credited with it has said so (National Cybersecurity Alliance, 2026).<\/p>\n<p>The measured figure is closer to 19%, from a survey of over 5,000 owners.<\/p>\n<p><strong>The genuine finding is that ransomware appears in 88% of SMB breaches, against 39% at large organisations<\/strong> (Verizon, 2025).<\/p>\n<p>Small businesses are not targeted more. Attacks against them succeed more.<\/p>\n<p>Average downtime runs around 24 days, and downtime costs more than most ransoms.<\/p>\n<p>Four of the six most effective protections are free: MFA, updates, closing remote access, and a written plan.<\/p>\n<p>The fifth is one backup copy ransomware cannot reach. Test restoring it.<\/p>\n<p>And treat the myth at the top of this article as a lesson in itself.<\/p>\n<p>A frightening number repeated for fifteen years turned out to have no study behind it.<\/p>\n<p><strong>Before acting on any alarming statistic, trace it back to whoever collected the data.<\/strong><\/p>\n<p>If every citation points to another article, you have found a rumour rather than a finding. \ud83d\udee1\ufe0f<\/p>\n<p style=\"text-align:center;margin:28px 0;\"><a href=\"https:\/\/yamuparkoti.com\/freetrialinsider\/\" style=\"display:inline-block;background:linear-gradient(90deg,#ff8f6b,#ffc46b);color:#0b1219;font-weight:800;padding:16px 40px;border-radius:12px;text-decoration:none;font-size:18px;\">\ud83d\ude80 Browse Backup and Security Trials \u2192<\/a><\/p>\n<h2>\u2753 \u5e38\u89c1\u95ee\u9898<\/h2>\n<h3>Do 60% of small businesses really close after a cyberattack?<\/h3>\n<p>No. The National Cybersecurity Alliance has stated the figure did not come from their research and cannot be verified. Survey data puts it nearer 19%.<\/p>\n<h3>Why is that number everywhere then?<\/h3>\n<p>It is memorable, alarming and useful to anyone selling security products. Each retelling cited the previous one rather than a study.<\/p>\n<h3>Are small businesses really targeted more?<\/h3>\n<p>Ransomware appears in 88% of SMB breaches against 39% at large organisations. The difference is that attacks succeed more often, not that attackers choose them.<\/p>\n<h3>How long does recovery take?<\/h3>\n<p>Average ransomware downtime is around 24 days, though prepared businesses recover far faster.<\/p>\n<h3>What does an attack cost a small business?<\/h3>\n<p>Typically $120,000 to $1.24 million. Downtime usually costs more than the ransom itself.<\/p>\n<h3>Should we pay the ransom?<\/h3>\n<p>Law enforcement advises against it. Payment buys a tool from a criminal with no guarantee, and does not stop stolen data being published.<\/p>\n<h3>What is the cheapest effective protection?<\/h3>\n<p>Multi-factor sign-in on email and remote access. It is free and blocks the most common entry route.<\/p>\n<h3>Why do backups fail when needed?<\/h3>\n<p>Usually because nobody tested a restore, or the backup drive was connected and got encrypted too.<\/p>\n<h3>Are we too small to be a target?<\/h3>\n<p>No. Most ransomware arrives through automated scanning rather than selection, and around 43% of attacks hit small and mid-sized businesses (Astra, 2026).<\/p>\n<h3>What should we do in the first hour?<\/h3>\n<p>Disconnect affected machines from the network but do not power them off, since that destroys evidence. Then check backups and notify your insurer.<\/p>\n<h3>Why does downtime cost more than the ransom?<\/h3>\n<p>Average downtime runs around 24 days. Revenue stops while wages and rent continue, and that gap is what closes businesses.<\/p>\n<h3>Does being a supplier increase our risk?<\/h3>\n<p>Yes. Small firms are attacked as a route into larger customers, which is why big companies now ask suppliers about their security.<\/p>\n<h3>Does cyber insurance cover this?<\/h3>\n<p>Increasingly only if you had MFA and tested backups in place. Read the conditions before assuming cover.<\/p>\n<h2>\ud83d\udcda \u53c2\u8003\u8d44\u6599<\/h2>\n<p>National Cybersecurity Alliance. (2026). <em>Statement regarding incorrect small business statistic<\/em>2026\u5e748\u67088\u65e5\u68c0\u7d22\u81ea <a href=\"https:\/\/www.staysafeonline.org\/press\/national-cyber-security-alliance-statement-regarding-incorrect-small-business-statistic\" rel=\"nofollow noopener\" target=\"_blank\">https:\/\/www.staysafeonline.org\/press\/national-cyber-security-alliance-statement-regarding-incorrect-small-business-statistic<\/a><\/p>\n<p>Verizon. (2025). <em>Data breach investigations report<\/em>, cited in Huntress ransomware statistics. Retrieved August 8, 2026, from <a href=\"https:\/\/www.huntress.com\/ransomware-guide\/ransomware-attack-statistics\" rel=\"nofollow noopener\" target=\"_blank\">https:\/\/www.huntress.com\/ransomware-guide\/ransomware-attack-statistics<\/a><\/p>\n<p>Astra. (2026). <em>Small business cyber attack statistics<\/em>2026\u5e748\u67088\u65e5\u68c0\u7d22\u81ea <a href=\"https:\/\/www.getastra.com\/blog\/security-audit\/small-business-cyber-attack-statistics\/\" rel=\"nofollow noopener\" target=\"_blank\">https:\/\/www.getastra.com\/blog\/security-audit\/small-business-cyber-attack-statistics\/<\/a><\/p>\n<p>SQ Magazine. (2026). <em>Small business cybersecurity statistics: threats and costs<\/em>2026\u5e748\u67088\u65e5\u68c0\u7d22\u81ea <a href=\"https:\/\/sqmagazine.co.uk\/small-business-cybersecurity-statistics\/\" rel=\"nofollow noopener\" target=\"_blank\">https:\/\/sqmagazine.co.uk\/small-business-cybersecurity-statistics\/<\/a><\/p>\n<p>SC World. (2026). <em>Most small businesses survive data breaches<\/em>2026\u5e748\u67088\u65e5\u68c0\u7d22\u81ea <a href=\"https:\/\/www.scworld.com\/news\/most-small-businesses-survive-data-breaches-heres-how-to-make-sure-yours-does-too\" rel=\"nofollow noopener\" target=\"_blank\">https:\/\/www.scworld.com\/news\/most-small-businesses-survive-data-breaches-heres-how-to-make-sure-yours-does-too<\/a><\/p>\n<h3>\u672c\u7ad9\u76f8\u5173\u9605\u8bfb<\/h3>\n<p>\u6211\u4eec\u7684 <a href=\"https:\/\/yamuparkoti.com\/password-breach-statistics\/\">password and MFA research<\/a> covers the most common entry route in detail. See also our <a href=\"https:\/\/yamuparkoti.com\/data-breach-cost-2026\/\">breach cost analysis<\/a> for what follows an incident, and the <a href=\"https:\/\/yamuparkoti.com\/freetrialinsider\/\">\u514d\u8d39\u8bd5\u7528\u4f1a\u5458\u76ee\u5f55<\/a> for backup and security trials.<\/p>\n<h3>\u5173\u4e8e\u672c\u6b21\u5206\u6790<\/h3>\n<p>This article corrects a statistic repeated across most competing coverage, using the disavowal published by the organisation usually credited with it. Where accurate figures exist they are used instead, with their sources named. Much research in this category is published by security vendors, where fear supports sales, and that is stated rather than hidden. Figures were checked on August 8, 2026.<\/p>","protected":false},"excerpt":{"rendered":"<p>You have almost certainly read that 60% of small businesses close within six months of a cyberattack. It appears everywhere. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5403,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_kadence_starter_templates_imported_post":false,"footnotes":""},"categories":[40],"tags":[],"class_list":["post-5404","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ecommerce-reviews"],"_links":{"self":[{"href":"https:\/\/yamuparkoti.com\/zh\/wp-json\/wp\/v2\/posts\/5404","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/yamuparkoti.com\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/yamuparkoti.com\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/yamuparkoti.com\/zh\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/yamuparkoti.com\/zh\/wp-json\/wp\/v2\/comments?post=5404"}],"version-history":[{"count":1,"href":"https:\/\/yamuparkoti.com\/zh\/wp-json\/wp\/v2\/posts\/5404\/revisions"}],"predecessor-version":[{"id":5466,"href":"https:\/\/yamuparkoti.com\/zh\/wp-json\/wp\/v2\/posts\/5404\/revisions\/5466"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/yamuparkoti.com\/zh\/wp-json\/wp\/v2\/media\/5403"}],"wp:attachment":[{"href":"https:\/\/yamuparkoti.com\/zh\/wp-json\/wp\/v2\/media?parent=5404"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/yamuparkoti.com\/zh\/wp-json\/wp\/v2\/categories?post=5404"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/yamuparkoti.com\/zh\/wp-json\/wp\/v2\/tags?post=5404"}],"curies":[{"name":"\u53ef\u6e7f\u6027\u7c89\u5242","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}