Austin Buonasera
 • 
July 30, 2025
 • 
5
 Minute read

What Ransomware Really Costs a Small Business

For a small business, ransomware is a recovery problem, not just a ransom bill. What it really costs, and the controls that keep you running.

Quick Summary

  • Ransomware showed up in 44% of breaches in Verizon's 2025 report, and in 88% of breaches at small and mid-sized businesses. It isn't a big-company problem.
  • The ransom is the smallest line item. Downtime, recovery, and lost trust cost far more — Sophos put average recovery at $1.53 million in 2025.
  • Paying doesn't reliably get your data back, and most victims (64%) now refuse.
  • Tested, offline backups are what actually get you running again. If you've never restored from them, you don't have backups — you have hope.
  • The controls that stop most attacks are ordinary: MFA, patching, endpoint detection, trained staff, and a plan you've practiced.
Sunset over foggy mountains with dark silhouettes and a cloudy sky.

Ransomware sounds like a big-company problem until it happens to you. It isn't. In Verizon's 2025 Data Breach Investigations Report, ransomware showed up in 44% of all breaches — and in 88% of breaches at small and mid-sized businesses. Attackers go after smaller businesses precisely because the payoff is real and the defenses usually aren't.

Here's the part most coverage gets wrong: the ransom is the smallest number in the story.

What it actually costs

When people picture a ransomware attack, they picture the ransom demand. That's the headline figure. It's rarely the expensive part.

Downtime. Every hour your systems are locked is an hour you can't invoice, ship, schedule, or serve a client. For most businesses, that lost operating time dwarfs the ransom itself.

Recovery. Rebuilding systems, restoring data, bringing in outside help, and proving the attacker is actually gone takes time and money. Sophos put the average recovery cost at $1.53 million in 2025 — and that's on top of any ransom, not counting it.

Lost trust. Clients in regulated or high-trust industries — accounting, legal, healthcare, energy — remember which vendor lost their data. Some don't come back.

Legal and regulatory fallout. Depending on your industry and the data involved, a breach can trigger notification requirements, regulatory questions, and legal exposure long after the systems are back up.

Paying doesn't fix it

The instinct under pressure is to pay and make it stop. The data says that's a bad bet. In Sophos's 2025 survey, the median ransom payment was $1 million — and paying buys you a decryption key from a criminal, not a guarantee. Files come back corrupted. Some don't come back at all. And a business known to have paid is a business worth hitting again.

That's why most victims have stopped paying. In Verizon's 2025 report, 64% of ransomware victims refused the ransom — because they had a better option ready.

What actually gets you back

The businesses that recover fast have one thing in common: they can restore from backups they've actually tested.

That last part matters. A backup you've never restored from isn't a backup — it's a guess. We've seen "backups" that hadn't run in months, backups sitting on the same network the ransomware encrypted, and backups nobody knew how to restore under pressure. The time to find that out is not during an incident.

Here's where we'd start:

  • Keep offline, tested backups. At least one copy ransomware on your network can't reach, and a restore you've actually practiced.
  • Turn on MFA everywhere. Most ransomware starts with a stolen password. Multi-factor authentication closes that door — email, remote access, and admin accounts first.
  • Patch promptly. Exploited vulnerabilities were the single most common way in, three years running. Retire software that's no longer supported.
  • Run managed endpoint detection. On every device that touches your systems, so an intrusion gets caught before it spreads.
  • Train the people who get targeted. A phishing email is still the most common opening move; staff who can spot one are a real defense.
  • Have an incident response plan. Written down, with names and phone numbers, so the first hour isn't spent deciding who to call.

None of this requires an enterprise budget. It requires owning the controls and keeping them current — which is exactly what our managed cybersecurity work is built around: find the exposure, lock down what matters, and maintain it.

If you're not sure where your gaps are — especially whether your backups would actually hold up — that's the place to start.

See what's exposed. Answer a few questions about backups, email, devices, and access, and get a clear picture of where you stand. It takes about three minutes.

Check your exposure · Book a consultation

Cards showing CPA firms scored 3/8 on client-data protection risks with notes on regulatory penalties and breaches.
3 minutes or less

Not sure what's exposed? Start here.

Answer a short set of questions about email, devices, vendors, backups, and access. No passwords, no system details — just the questions an attacker has already answered about you.
Get Your Risk Assessment