One morning everything works. Your team logs in, opens their files, starts the day. By afternoon, nothing opens. Every file on every computer in your office is locked. A message appears on the screen telling you that your data has been encrypted and that you have 72 hours to pay a ransom or it will be deleted permanently.
This is not a scene from a movie about large corporations. This is how an ordinary Tuesday ends for thousands of small businesses every year, including businesses right here in Chicago.
Ransomware is the most disruptive form of cyberattack targeting small businesses today. It is also one of the most preventable. Understanding what it is, how it gets in, and what it costs is the starting point for making sure it does not happen to yours.
What Ransomware Actually Is
Ransomware is a category of malicious software designed to do one thing: lock you out of your own data and demand payment to give it back.
When ransomware executes on your systems, it encrypts your files using a mathematical process that makes them completely unreadable without a specific decryption key. The criminal holds that key. They will sell it back to you, or they will destroy it, depending on whether you pay.
Encryption, in most contexts, is a security tool. Banks use it to protect your account information. Healthcare systems use it to protect patient records. Ransomware criminals weaponize the same technology against the businesses they attack, turning a protective mechanism into a hostage-taking tool.
The name comes from the model: your data is held for ransom. You pay, and you may or may not get it back. You do not pay, and you lose everything the ransomware reached.
How Ransomware Gets Into Your Business
Ransomware does not appear out of nowhere. It arrives through a specific entry point, and in almost every case, that entry point is one your business controls.
Phishing emails
These are the most common delivery method. An employee receives an email that appears to come from a trusted source, clicks a link or opens an attachment, and the ransomware installs itself silently. The employee sees nothing unusual. The ransomware begins its work in the background. By the time anyone notices, it has already spread.
Weak or reused passwords
This is the second most common entry point. Criminals obtain login credentials from previous data breaches, which are sold openly on dark web marketplaces, and use automated tools to test those credentials against business systems. When an employee has reused a password from a compromised personal account on a business system, the criminal walks through the front door using a key they did not have to steal.
Remote access vulnerabilities
These have become increasingly significant as more businesses use remote desktop tools to allow employees to access office systems from home. When these tools are not properly configured or secured, they create a direct pathway into your network that criminals actively scan for.
Unpatched software
This leaves known vulnerabilities open. Software developers regularly release updates that fix security weaknesses. Businesses that delay applying those updates are operating with doors that criminals already have maps to.
In every case, the entry point exists because a standard security control was missing or incomplete. The ransomware did not break through sophisticated defenses. It walked through a gap that should not have been there.
What Happens During an Attack
Understanding the sequence of a ransomware attack matters because the timeline shapes how much damage occurs and what recovery looks like.
The process typically begins weeks before you know anything is wrong. After gaining initial access through one of the entry points described above, sophisticated ransomware criminals do not immediately encrypt your files. They spend time moving through your network, identifying your most valuable data, locating and disabling your backup systems, and expanding their access to as many devices as possible.
This quiet phase, called dwell time, is the period when your security monitoring either catches the intrusion or misses it. Businesses with active behavioral monitoring detect the unusual movement and shut it down. Businesses without it remain unaware while the criminal prepares for maximum damage.
When the criminal is ready, the encryption executes across every device they have reached simultaneously. This is the moment your team notices something is wrong. Files will not open. Systems display error messages or the ransom note directly. Operations stop.
From that moment, the clock on the ransom demand begins. Criminals typically set deadlines of 24 to 72 hours and threaten to publish stolen data publicly, notify your clients, or permanently delete the decryption key if payment is not received within that window.
The average business experiences 21 days of downtime following a ransomware attack. That is three weeks during which operations are disrupted, revenue is lost, and clients are waiting for an explanation.
What Ransomware Actually Costs
The ransom demand is the most visible number, but it is rarely the largest one.
A Chicago accounting firm we have referenced in this series paid $300,000 to recover their encrypted data. That figure made the ransom the single largest expense of the incident. But in the weeks and months that followed, they experienced client departures, legal fees related to the breach notification, the cost of rebuilding systems and restoring data from incomplete backups, and the operational disruption of running a firm on reduced capacity during recovery. The total cost of the incident was substantially higher than the ransom itself.
An HVAC company we have also documented in this series faced a different version of the same story. Ransomware locked their scheduling and dispatch software. For two full days, they could not assign technicians, confirm appointments, or access client records. They missed jobs. They issued refunds. They spent days on the phone explaining to clients why their service calls had not been completed. The ransom amount was modest. The reputational cost took months to repair.
These numbers reflect what research consistently shows. The average cost of a cyberattack against a small business is $200,000 when all direct and indirect costs are included. Sixty percent of small businesses that experience a significant breach close within six months, not always because of the immediate financial loss but because of the compounding effects of client attrition, operational disruption, and the cost of recovery.
The ransom is the number criminals want you focused on. The total cost is the number that determines whether your business survives.
The Decision No Business Owner Should Face
When the ransom note appears, the business owner faces a decision with no good options.
Paying the ransom does not guarantee recovery. Criminal organizations do not have customer service standards. Some pay and receive a working decryption key. Some pay and receive a key that only partially restores their data. Some pay and receive nothing. There is no recourse against a criminal who takes your money and disappears.
Not paying means attempting to recover from backups, assuming backups exist, were not encrypted by the ransomware, and have been tested recently enough to be reliable. Many businesses discover in this moment that their backups were not as current or complete as they believed.
Both paths involve significant cost, significant uncertainty, and significant time. The only position that avoids this decision entirely is not being vulnerable to it in the first place.
What Would Have Stopped It
Every documented ransomware attack against a small business traces back to a gap in one or more of the Essential Eight security layers.
Email security filtering catches the phishing email before it reaches the employee who would have clicked it. Multi-factor authentication blocks the credential-stuffing attack even when a password has been compromised. Endpoint detection and response identifies the ransomware's behavior during the encryption process and stops it before it spreads across the network. Tested, immutable backups stored separately from the primary network make the ransom demand irrelevant because recovery does not depend on the criminal.
No single one of these controls is sufficient on its own. Ransomware criminals know how to work around individual defenses. What they cannot easily overcome is a layered security posture where each gap one control might leave is covered by another.
This is the design of the KIT Framework at Red Door Shield. The Keep layer locks down endpoints and access controls so ransomware has fewer entry points. The Inspect layer monitors behavior continuously so the quiet phase of an attack is detected and shut down before encryption begins. The Trust layer verifies continuously so compromised credentials do not translate into network access. All three working together transform ransomware from a catastrophic risk into a managed one.
The HVAC company referenced above now runs endpoint detection and response on every device in their operation. Their security advisor told them plainly after the incident: modern endpoint protection would have stopped this attack at the gate. It did not exist in their environment when the attack happened. It does now.
Where Your Business Stands
Ransomware is not a threat reserved for businesses that made obvious mistakes. The businesses that get hit are most often the ones that had reasonable defenses in place but left one gap open that an automated attack found.
The question worth answering today is not whether your business could survive a ransomware attack. The question is whether your current security posture would prevent one from succeeding. Those are two very different questions and only one of them leads somewhere useful.
Our free Business Security Assessment covers every layer of your current protection, including your email security, your endpoint defense, your backup integrity, and your access controls. It takes less than 10 minutes and gives you a clear, honest picture of where you stand and what it would take to close the gaps that matter most.
Because the best time to find out you are protected is before the ransom note appears, not after.
Know Where Your Business Stands
Get a clear, honest picture of your current security posture in less than 10 minutes. No jargon, no pressure.
Get My Free Security AssessmentNot sure where your business actually stands?
Take our free Business Security Assessment. In under 10 minutes, you will know exactly where your gaps are and what it would take to close them.
Get My Free Security Assessment

