For years ransomware made the news through large organizations: hospitals, airlines, public administrations. The 2026 data tells a different story. When Verizon analyzed 22,000 confirmed breaches for its annual report, ransomware was present in 48% of all of them, and 96% of the victims were SMBs. In Spain, INCIBE handled 122,223 incidents in 2025, up 26% on the previous year: six out of ten hit SMBs and sole traders, and ransomware cases doubled in a single year, from 176 to 392. The hardest-hit sectors are not tech companies: retail, hospitality, professional firms and clinics.

Why an SMB

Not because someone picked it. Because it was open. Attackers no longer select interesting companies: they select doors. The two most common, according to the same report, are stolen credentials (38% of attacks) and unpatched edge devices (29%): the firewall, the VPN or the mail server facing the internet. A large company has a team dedicated to closing those doors. An SMB almost never does.

The attacker's business model has adapted too: fewer million-dollar ransoms from one multinational, more mid-sized ransoms from hundreds of companies that cannot afford to stop for a week.

The damage is no longer just downtime

Today's attack adds a layer: before encrypting your systems, attackers copy your data and threaten to publish it or to contact your customers directly. Restoring backups no longer closes the incident: what they took is still out there, and with it the conversation with customers, employees and the data protection authority.

What actually reduces the risk

It is not a big project or a list of twenty tools. In the data, four things separate the companies that have a bad day from the ones that have a bad quarter:

  1. A second factor on every remote access and on email. Stolen credentials are the number one way in, and a second factor closes that door almost every time.
  2. Backups kept off the network and tested. Not "backups are running": someone has restored one and knows how long it takes. It is the difference between paying and not paying.
  3. Patches on whatever faces the internet. VPN, firewall and mail get updated in days, not months. That is where one in three attacks gets in.
  4. Knowing what you have. An inventory of systems and of who can access what. You cannot protect what you do not know exists.

Only 31% of victims paid last year, and the median payment dropped below $140,000: more and more companies are able to say no. You say no with backups that work.

What I would do this month

Three afternoons, not a quarter. First: ask who can get into your systems from outside and whether every one of those accesses requires a second factor. Second: ask for the date and result of the last backup restoration test; if the answer is that "backups run on their own", there is no test. Third: a list of your internet-facing devices with the date of their last update.

With those three answers on the table you will know more about your real exposure than any generic threat report can tell you. And if you want to see how a real incident reads from start to finish, and what it demands of whoever reviews it, we did exactly that with the Hugging Face breach.