Essentials
The SMBs Ransomware Survival Guide: Don't Pay, Do This Instead
Waking up to a screen that says "Your network has been encrypted" is a nightmare for any small business owner. In the past, ransomware gangs targeted massive corporations for multi-million dollar payouts. Today, they…
By SecureBusinessHub Editorial, International cybersecurity desk — · 7 min read
Finding your network encrypted when you open your laptop is one of the worst things that can happen to a small business owner. Ransomware gangs used to target large enterprises for eight-figure payouts. Now they run automated campaigns against SMBs, asking for amounts under $50,000 — small enough that many businesses pay quickly rather than deal with the fallout.
Paying is almost always the wrong call. Here's the hour-by-hour protocol to follow instead. If you want the prevention side — how these attacks work and how to stop them landing in the first place — see our guide to ransomware prevention in 2026.
Hour 0–1: Isolate, don't power off
The reflex when you see a ransom screen is to pull the power cable. Don't. Abruptly shutting down servers corrupts files and wipes the volatile memory that forensic experts can use later. Instead, cut the network connection: unplug ethernet cables and disable Wi-Fi on infected machines immediately. Ransomware moves laterally, so the goal is to stop it spreading to your backups and cloud storage — disconnect your backup server or cloud sync straight away to protect your recovery point.
Hour 1–2: Scope the damage
Before you decide anything, work out what actually happened. Was this just encryption, or was data exfiltrated first? The answer changes everything: a pure encryption event where you have clean backups is a recovery problem, while stolen data means a potential breach notification and extortion regardless of whether you restore. Identify which systems were hit and whether sensitive customer data left the building, because that determines your legal obligations in the next step.
Hour 1–2 (in parallel): Check your offline backups
Ransomware groups know that if you have backups, you won't pay — which is why modern variants actively hunt for connected backup drives and cloud sync folders to encrypt those first. Check your offline backups: the ones sitting in a drawer or in immutable cloud storage. If yesterday's data is safe, you've won the critical part.
Hour 2–3: Call your insurer and legal counsel
Don't negotiate with the attackers on your own. Your first call should be to your cyber insurance provider — they have specialist negotiators and forensic teams on retainer. Your second call is to legal counsel: depending on your jurisdiction, you may have a strict 72-hour window to report the breach if customer data was exposed, under rules such as GDPR, CCPA, or sector-specific requirements.
The myth of the honest thief
Why not just pay? Two reasons. First, in many jurisdictions paying ransomware criminals is legally complicated or outright illegal. Second, nearly 80% of businesses that pay get attacked again, often by the same group, and even when you pay there's roughly a 30% chance the decryption key doesn't fully work. You end up with less money and the same situation. Before contacting attackers or paying anything, use professional negotiators and speak to law enforcement — never reach out to the attackers directly yourself.
Hour 3–4: Preserve evidence and engage law enforcement
Once the immediate threat is contained, resist the urge to wipe and rebuild before you understand how they got in. Preserve log files, capture the memory state of affected machines, and document the malware's entry point; tools like Magnet AXIOM or the open-source Autopsy can help reconstruct the timeline. Then report the attack — to the FBI's IC3 in the US, or the No More Ransom project internationally. This isn't only about catching anyone: law enforcement sometimes holds free decryption tools for specific ransomware strains that aren't publicly available, and your report helps protect the next business in line. The reputational fallout is its own workstream — our guide to the reputational cost of a breach covers managing that side.
Prevent the next breach
Once the immediate situation is contained, close the entry point. For most SMBs, that means enforcing MFA on every account under a written password and MFA policy and disabling external Remote Desktop Protocol access — the two doors ransomware walks through most often. Then work through the wider prevention checklist so the next automated campaign that finds you comes away with nothing.
Related reading
- Incident response plan template: a step-by-step walkthrough with roles and notification rules.
- Business continuity and disaster recovery: the basics: keeping the business running while systems are restored.
- The 3-2-1 backup strategy, explained: what actually makes a backup useful against ransomware.
- How to run a ransomware tabletop exercise: testing your plan before you need it.
- Editable policy template pack: ready-to-use versions of the incident response and business continuity plans referenced above.
NIS2 requirements: the second regime to know about
Data protection law is not the only European regime a business gets asked about. The NIS2 directive sets baseline cybersecurity and incident-reporting obligations for organisations in a defined list of sectors, and it is the source of most of the security questions that now arrive attached to contracts. The two regimes cover different ground: data protection law governs personal data and what people can ask you to do with it, while the NIS2 requirements govern the security and resilience of network and information systems, whether or not personal data is involved. A single incident can engage both, on separate clocks, to separate authorities.
The directive applies to organisations in its listed sectors that are at least medium-sized, meaning broadly fifty or more employees or turnover and balance sheet above ten million euros. That size rule puts most small businesses outside its direct scope, and the honest answer for a ten-person company is usually that the directive does not regulate it. What the size rule does not do is keep the requirements away, because one of them is supply chain security: organisations inside scope are expected to consider the security practices of their direct suppliers, and the way that expectation shows up in the world is as a questionnaire in your inbox.
The measures the directive names are a reasonable checklist for any business, which is why they are worth knowing even when they do not apply to you directly. They cover risk analysis and written security policies, incident handling, business continuity and backups, supply chain security, secure development and vulnerability handling, basic cyber hygiene and training including for management, encryption and access control policies, and multi-factor authentication. Reporting is staged and fast for the organisations it covers: an early warning within twenty-four hours of becoming aware of a significant incident, a fuller notification within seventy-two hours, and a final report within one month.
Because the directive is national law in each member state rather than a single rulebook, the details of scope, thresholds and reporting differ by country. For a fuller explanation of the instrument itself, see our guide to what the NIS2 directive is, and for the supplier side of the supply chain obligation, our walkthrough of vendor risk assessment. The reporting clocks that run alongside data protection deadlines are covered in data breach notification requirements.
Frequently asked questions
Does NIS2 apply to a small business?
NIS2 generally applies to organisations in its listed sectors that are at least medium-sized, meaning broadly fifty or more employees or turnover and balance sheet total above ten million euros. Most smaller businesses fall outside its direct scope, unless a member state has specifically designated them or they sit in one of the size-independent categories such as DNS service providers or trust service providers. Being outside scope does not stop the directive reaching you through customers who are inside it.
What is the difference between GDPR and NIS2?
GDPR governs personal data: what you may collect, why you may hold it, and what rights people have over it. NIS2 governs the security and resilience of network and information systems in specific sectors, whether or not personal data is involved. One incident can engage both regimes at once, on separate reporting clocks and to separate authorities.
How long do you have to report a data breach?
Under the European model, a personal data breach is reported to the supervisory authority without undue delay and, where feasible, within seventy-two hours of becoming aware of it, and affected individuals are told without undue delay where the risk to them is high. Organisations in scope of NIS2 carry a separate obligation: an early warning within twenty-four hours, a fuller notification within seventy-two hours, and a final report within one month.
Does a small business need a data protection officer?
Under GDPR a data protection officer is required where the organisation is a public authority, where its core activities involve regular and systematic monitoring of people on a large scale, or where its core activities involve large-scale processing of special category or criminal offence data. Most small businesses meet none of those tests and are not required to appoint one, though naming someone internally as the contact for privacy questions is worth doing regardless.
What should a small business do when a client's security questionnaire asks about NIS2?
Answer what you actually do rather than what you think the client wants to hear. The questions usually cover written security policies, incident handling and how fast you would notify them, multi-factor authentication, access control when staff join and leave, backup and recovery arrangements, and which of your own subprocessors touch their data. Gaps are common, and disclosing one with a date for closing it lands far better than an answer that does not survive the follow-up question.
Do these rules reach a business based outside the EU?
They can. GDPR reaches organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour, and other regions have their own regimes with their own triggers. NIS2 obligations follow the sectors and the member states that transpose it, but its supply chain expectations travel through contracts, which is how they reach suppliers anywhere in the world.
Related reading
- What is the NIS2 directive? Scope, sectors and deadlines: the instrument itself, who it covers, and how it reaches businesses outside its scope.
- Vendor risk assessment: a practical walkthrough: which suppliers to assess, what to ask them, and how to score the answers.
- Data breach notification requirements: who to tell and when: the audiences, the clocks, and the decisions to make before an incident.
- Privacy policy template for small business: what to include: the sections a policy needs, and the ones a generated template always gets wrong.
- Editable policy template pack: ready-to-adapt versions of the vendor risk questionnaire, incident response playbook and policy documents referenced above.