The Day the Systems Go Down
A mid-market distributor gets a call on a Tuesday. The screens are frozen, a message is demanding payment, and until it is paid, nothing ships. No orders, no invoices, no shop floor. That is not a rare story anymore. It is close to the median one.
Owners tend to assume attackers chase the big names. The data says otherwise about who actually gets hit. Verizon's 2025 Data Breach Investigations Report found that ransomware showed up in 88 percent of breaches at small and mid-sized businesses, against 39 percent at large ones. Criminals are not picking you for your size. They are picking you because you are reachable, and because a smaller company is far less likely to have the basics in place that would turn a disaster into an inconvenience.
The odds are worse the smaller you are
The reachability is the whole point. Large firms have security teams. You have a couple of people wearing several hats, an email system everyone logs into, and, very likely, a backup nobody has tested. That last one is where a bad Tuesday becomes a bad quarter.
The trend is moving the wrong way, too. Broader breach research found ransomware was a factor in 44 percent of incidents in 2025, up from 32 percent the year before. Whatever protected you by luck last year is a thinner shield this year.
The outage costs more than the attack
When people picture a cyber incident they picture the ransom. The ransom is rarely the expensive part. The expensive part is the days you cannot operate.
Estimates for small organizations put the cost of downtime somewhere between 8,000 and 25,000 dollars an hour once you count idle staff, stalled orders, and customers who go elsewhere. Verizon's data pegs the realistic total for most smaller companies between roughly $120,000 and $1.24 million per incident, depending on how bad it gets and how ready you were. Readiness is the variable you actually control. And yet the same reporting that measures these costs keeps finding that more than half of companies test their recovery plan once a year or never, which means most of them will discover their backup does not work at the exact moment they need it.
What basic actually looks like
You don't need an enterprise security program. You need the equivalent of locking the doors and knowing where the fire exits are, and most of it is cheap or free.
Turn on multi-factor authentication everywhere, starting with email, because a stolen password stops being a crisis the moment a second step stands behind it. Keep software patched, since most breaches walk in through a hole that had a fix available for months. Cut access down to what each person actually needs, and pull it the day they leave. Then the one that matters most: keep a backup that lives somewhere separate from your systems, and prove you can restore from it. A backup you have never restored is a rumor.
Finally, write down what happens on the bad day before it arrives. Who gets called, in what order, who can authorize what, how you keep serving customers while the systems come back. One page is enough. Companies that plan and rehearse spend far less per incident than the ones improvising at two in the morning, roughly half as much by some estimates.
None of this is glamorous, and none of it shows up in a good quarter. It shows up in the bad one, which was always the only quarter that would test it. The distributor with the frozen screens either had a tested backup and a phone list, in which case Tuesday cost them a rough afternoon, or it did not, in which case Tuesday cost them a number with a lot of zeros. You decide which version you are today, for far less than the outage would cost you once.