Plenty of small-business owners assume the same thing: "nobody would waste time attacking us." It's an understandable belief — and a wrong one. Ransomware, the data hijack where a program scrambles a company's files and demands payment to unscramble them, doesn't pick a victim by hand. It's automated: it scans the internet for an open access door and a weak password, and it strikes wherever it finds both. That combination is exactly where small businesses tend to live.
According to the most recent Data Breach Investigations Report (DBIR) from Verizon, ransomware showed up in 88% of breaches suffered by small and mid-size businesses — versus 39% among larger organizations. Sophos, a security vendor that serves this exact audience, measured a similar pattern from the incident-response side: in 2024, ransomware accounted for 70% of the cases it handled among clients with up to 500 employees, and more than 90% among mid-size clients, those with 500 to 5,000 employees.
For whoever signs off on the IT budget at a small company, that number changes the question worth asking. It's no longer "could this happen to us?" — it's "where would it get in, if it happened tomorrow?"
Why the small door gets found
The attack isn't a person researching a company before acting. It's a program continuously scanning millions of internet addresses looking for an exposed remote-access service, an outdated network device, or a password reused across more than one system. Wherever it finds one, it strikes — it doesn't matter whether that's a 40-employee factory or a national retail chain.
In Sophos's research covering small and mid-size businesses, about a quarter of confirmed initial compromises tracked through telemetry started with an exposed network device — the kind of access point teams use to reach the company network from outside. Known, unpatched security flaws showed up in 14.53% of the intrusion cases the team investigated. Neither entry point requires a skilled attacker; both only require an outdated system nobody remembered to close, and that's exactly what tends to pile up at a company with no one dedicated to watching it every day.
The same research shows how large a share of the workload this represents for whoever supports these businesses: data theft and ransomware together accounted for roughly 30% of all the security incidents Sophos handled among small and mid-size businesses in 2024.
In Brazil, the national picture doesn't look better. Kaspersky recorded 105 organizations hit by ransomware in 2024, up 69% from 62 the year before — the study doesn't break the figure down by company size, but it shows the country is still squarely on attackers' radar. Healthcare, financial services and retail accounted for most of the cases.
Sophos's own size cutoff for this data is telling: up to 500 employees still counts as a small business in that research, and even at that size the ransomware rate already outpaces much larger organizations. In other words, the size most Brazilian owners would call "too small to matter" already sits inside the range attackers hit most.
Why the usual approach doesn't work

The usual approach at a small company is reactive: call someone only when something breaks, trust a backup copy that's never been tested, leave the subject to whoever "knows more about computers" on the team — with no dedicated time, no formal responsibility, and no defined routine for handling it every day.
The trouble is that an automated attack doesn't announce itself first. It doesn't send a test run. The first sign is usually the ransom message on the screen, on a Monday morning, with the files already scrambled. By then, the question "who's in charge of this at our company?" should have had an answer months earlier.
Buying one more protection tool with no one to configure it, keep it updated, and read its alerts every day produces the same outcome as buying nothing: the software sits installed, and nobody reads what it's warning about until it's too late.
CERT.br, Brazil's national center that gathers and handles security incident reports, published a guide on this exact topic in 2025 precisely because the pattern keeps repeating. Most of its recommendations don't call for buying anything new — they call for routine: fixing a known flaw, limiting who can access what, and keeping a copy isolated from the main network. It's a guide written for whoever doesn't have a dedicated security team, not for a large company with one.
What has to be in place
Closing that door doesn't depend on a single product. It depends on a small set of routines, kept up by someone responsible for them every day — not only once something has already gone wrong.
Every remote-access door exposed to the internet, either closed or protected by a second confirmation step beyond the password. It's the most common entry point in automated attacks: if it isn't open, the program scanning the internet moves on to the next target.
A unique, strong password on every system, never reused between them. A password leaked from some unrelated service can't be the same one that unlocks the company's server.
A critical security warning turning into an update applied within days, not shelved for the next project. That's the difference between closing the flaw before or after someone exploits it.
A copy of the files kept out of reach of anyone who already got into the network — disconnected from the main network or impossible to alter from outside. Ransomware also targets the connected copy; if it sits alongside everything else, it gets scrambled too.
Someone watching how the network behaves, not just the antivirus on each computer. Ransomware often gives itself away before scrambling everything: unusual traffic, access at odd hours, files being copied in bulk. Catching that in time is the difference between a warning and a crisis.
A written agreement on who decides what on the day of an attack — who disconnects the network, who tells leadership, who calls insurance or legal counsel. Deciding that in the middle of the fire costs time the company doesn't have.
This is how Skills IT works: access doors closed by default, security updates applied as soon as they're released, and backup copies kept out of reach of anyone trying to get in.
The payoff for the business

Closing these doors isn't a promise of never being attacked — nobody can guarantee that. It's about reducing the odds an attack finds a clear path and, if it does find one, having an intact copy to restart from without having to negotiate with whoever hijacked the data.
There's a cost few businesses account for until they need to: negotiating with whoever hijacked the data isn't fast, isn't cheap, and doesn't guarantee the files come back complete. Having an intact copy changes that whole conversation — the company decides to recover on its own, instead of depending on the attacker's goodwill.
On the financial side, the math is easy to explain to whoever approves the budget: the cost of keeping these routines running is predictable and monthly. The cost of having none of them only shows up after the attack, and it arrives bigger, with no warning and no installments.
On the operational side, the payoff is the business staying open while the rest gets sorted out: orders going out, staff working, customers being served — instead of everyone standing still waiting for someone to "fix the computer."
A starting checklist
Before the next meeting about the IT budget, it's worth bringing these questions ready to go:
- Which of the company's remote-access doors are open to the internet today, and why? If nobody can answer, that's the first gap to close.
- Is there a backup copy kept out of reach of anyone who breaks into the main network? If the answer is "it's all in the same place," the risk is bigger than it looks.
- Who in the company decides what to do in the first minute of an attack? Without that person defined, the decision stalls exactly when speed matters most.
- Are security updates on critical systems current, or "in the queue"? A known, unpatched flaw is the easiest door of all.
- Is anyone watching how the network behaves, or just the antivirus on each computer? That difference separates catching an attack starting from only finding out once it's over.





