July 21, 2026
88% of Small Business Breaches Now Include Ransomware — Here’s What That Means for You
Here’s a number that should reshape how you think about business security: 88% of small business breaches now include a ransomware…

By Stanley A.
4 min read
Here's a number that should reshape how you think about business security: 88% of small business breaches now include a ransomware component.
That's not a typo. It's from Verizon's 2025 Data Breach Investigations Report — compared to just 39% of breaches at larger organisations, meaning SMBs are hit at more than double the rate.
Meanwhile, 47% of businesses with fewer than 50 employees allocate zero budget to cybersecurity.
If you run a small business, manage a website, or operate any online presence, this post explains what that 88% actually means for you — and the three things you can do about it today.
Why Small Businesses Are the Target
There's a persistent myth that ransomware groups go after large enterprises. The data says otherwise.
Small and mid-sized businesses are disproportionately represented in data breaches — multiple industry reports put SMBs at roughly 3× more likely to be targeted than larger firms, and some analyses suggest they account for a majority of all confirmed breaches. Exact figures vary by report and methodology, but the direction is consistent: SMBs are not flying under the radar.
The reasons are straightforward:
- Lower defences. Most small businesses don't have a dedicated security team, network monitoring, or even basic access controls. Attackers know this.
- Higher willingness to pay. 40% of SMBs say a cyberattack costing $100,000 or less could put them out of business. That desperation makes them more likely to pay the ransom quickly — which is exactly what attackers want.
- Supply chain leverage. A small business that handles customer data, processes payments, or provides services to larger clients becomes a gateway. Attackers compromise the small supplier to reach the bigger fish.
The average cost of a data breach globally has risen to $4.88 million — a 10% year-on-year increase, according to IBM. That figure is an average across organisations of all sizes, so it's not a direct prediction for what a small business would lose — SMB breach costs are typically much smaller in absolute dollars. But relative to revenue, the impact on a small business is often far heavier, which is why 40% of SMBs say an attack costing $100,000 or less could put them out of business entirely.
What "88% Include Ransomware" Actually Means
When we say a breach "includes ransomware," we don't just mean a pop-up demanding Bitcoin. The modern ransomware playbook is more layered:
Stage 1: Getting In
Attackers get in through phishing emails (now AI-written and grammar-perfect), unpatched software, weak passwords, or exposed admin panels.
Stage 2: Mapping Your Network
Once inside, they spend days or weeks finding your critical data, backups, and most valuable systems. Most businesses never detect this phase.
Stage 3: Stealing Your Data
Before encrypting anything, modern ransomware groups steal your data first. This gives them leverage: "Pay up, or we publish your customer database."
Stage 4: Locking Everything
Only after exfiltration does the encryption happen. Your files, databases, and backups are locked.
Stage 5: The Real Damage
Even if you pay, you face an average of 21 days of downtime, customer notification requirements, regulatory fines, and reputational damage that takes months to rebuild.
The 88% figure tells you this isn't a rare event. It's the dominant breach pattern for small businesses right now.
The Full Picture
Here are the numbers that matter:
Note: SMB-share-of-breaches figures vary noticeably across reports depending on methodology and sample — treat any single "X% of all breaches are SMBs" number as directional rather than precise.
The pattern is clear: attackers are getting smarter, cheaper, and more automated — while most small businesses are doing the same thing they did five years ago.
Why "We Use Cloudflare" Isn't Enough
If your website sits behind Cloudflare, you're in better shape than most. But a WAF protects your network edge — not everything behind it.
The breaches that lead to ransomware typically start with something the WAF can't see: a misconfigured admin panel, an unpatched WordPress plugin, or a developer credential left in a public repository.
A WAF is a seatbelt. Essential, but it doesn't prevent the crash.
Three Things You Can Do This Week
1. Check Your Backup Strategy (Today)
Ransomware's power comes from one thing: you can't recover without the data. If your backups are on the same server, never tested, or only local — they won't save you.
The test: Can you restore a critical file or database from backup right now, without touching production? If the answer isn't a confident yes, fix that before anything else.
2. Run a Free Security Scan (5 Minutes)
Before you invest in anything, know your baseline. A free automated scan checks your website across 40+ categories — SSL, security headers, email authentication, CMS version detection — and gives you an instant score.
It won't find everything, but it tells you if your basics are covered. Run a free scan →
3. Close the Three Most Common Entry Points
- Unpatched software. WordPress shipped an emergency security release (7.0.2) on July 17, 2026, fixing a critical, pre-authentication remote-code-execution chain — an attacker needs no login and no plugin to exploit it. If you haven't updated, you're exposed right now.
- Weak or absent MFA. Enable multi-factor authentication on every admin account, hosting panel, and email account. This single step blocks the majority of credential-based attacks.
- Exposed admin panels. Check if
/wp-adminor any management interface is accessible from the public internet. If it is, restrict it.
These aren't theoretical improvements. They're the exact gaps that ransomware groups scan for when choosing their next target.
The Cost of Doing Nothing
- Average breach cost: $4.88 million globally across organisations of all sizes (IBM 2025) — a useful benchmark of scale, even if your own exposure is smaller
- Average ransomware downtime: 21 days for SMBs
- 40% of SMBs say a $100K attack would put them out of business
The question isn't "Can I afford to invest in security?" It's "Can I afford not to?"
Originally published at WardenBit. WardenBit helps small businesses find and fix security gaps before they become breaches. Run a free scan →