Download our free Small Business IT Guide to learn what to look for in a reliable IT partner and make a more confident decision for your business.

How to Combat Ransomware if Your Business Is Targeted

It may not be news to you that ransomware is on the rise, but the numbers may leave you shocked. In 2020 alone, there were close to 300 million ransomware attacks worldwide. The cost of ransom payments demanded by hackers are also increasing in tandem with the increase in attacks. According to a recent projection, the global annual cost of ransomware attacks will touch $20 billion by the end of 2021. Is your business ready to combat ransomware?

Offerings like ransomware-as-a-service have made it easier for criminals with little technical knowledge to become threat actors. These attackers are less predictable and seem to lack a code of ethics. For example, groups in the past had lists of organizations they wouldn’t attack, such as cancer treatment facilities. That’s often not the case anymore.

A ransomware attack can affect any organization, regardless of size or industry. However, small and medium sized businesses (SMBs) are the most vulnerable since cyber criminals count on these businesses to lack the resources to battle cyber crime, combat ransomware, or the IT teams to frequently evaluate cybersecurity measures. Even though SMBs continue to be disproportionately affected by these nefarious attacks, reporting and notifications rarely make the news unless a huge corporation experiences a breach.

With ransomware expected to hit businesses every 8 seconds, always remember that it isn’t a question of IF but rather WHEN your business will come under attack. Keep in mind that with the right security solutions and measures in place, your business won’t have to experience a devastating breach.  But first, there are a few things you should know if you experience a ransomware attack.

Before Reacting to a Ransomware Attack, Remember:

  • The FBI advises against paying a ransom because spending money does not guarantee the hackers will share the keys to decrypt your data. While the FBI is an American organization, they raise a good point for businesses all across the globe.

It doesn’t make any sense to place your trust in cyber criminals who have already demonstrated that they aren’t afraid to break the law and take advantage of you for financial gain. However, many businesses find themselves in this situation because they had the midset “that only happens to the other guy”, “my business is too small to be hacked”, or they don’t have sufficient security, backup, or compliance measures, and are desperate to get their data back.

Keep in mind that another reason the FBI advises against giving in to ransomware demands is that you are encouraging criminals to conduct further attacks. If nobody ever paid ransom, it’s likely there wouldn’t be as many ransomware attacks. Criminals would have to find new ways to make money and would disregard ransomware as a viable venture.

  • In case you fall victim to a ransomware attack and have no option other than paying, “ransomware negotiators” are available for hire.

In ransomware negotiations, the most crucial moment occurs long before the victim and hackers discuss the ransom. This is because by the time both sides start to discuss, hackers have already gained considerable control over the organization’s network by encrypting access to sensitive business data and other digital assets. The more data they encrypt, the greater the negotiating power they have.

So, even before you begin negotiations, you need to know how much data has been compromised and what negotiating methods have been employed in the past by the criminals. Professional ransomware negotiators can help at this stage. Although a ransomware negotiation rarely results in a ransom demand being totally withdrawn, it can significantly bring down the asking price.

Victims of ransomware should expect the following:

  • The data will not be erased in a trustworthy manner. It will be sold, improperly handled, or stored for future extortion attempts.
  • Multiple parties would have handled the exfiltrated data, making it insecure. Even if the hacker deletes a large portion of the data once the ransom is paid, other parties who had access to it may have made duplicates to make payment demands later.
  • Before a victim can respond to an extortion attempt, the data may get leaked either intentionally or inadvertently.
  • Even if the threat actor explicitly promises to release the encrypted data after payment, they may not keep their word.

The Best Time to Prepare for Ransomware Is Before It Happens

When a ransomware attack occurs, every decision matters. Organizations that have documented response procedures, clearly defined responsibilities, reliable backups, and established communication plans are often able to recover more effectively and reduce the overall impact of an incident.

Ransomware preparedness is not just about preventing attacks. It is about ensuring your business can respond quickly, contain the damage, restore operations, and maintain confidence among customers, employees, and stakeholders. The organizations that recover most successfully are usually the ones that planned their response before an attack occurred.

A well-prepared organization understands who to contact, what systems are most critical, how recovery will occur, and what actions should be taken during the first hours of an incident.

Preparation does not eliminate risk, but it can significantly reduce the disruption caused when ransomware strikes.

Would Your Team Know What to Do During a Ransomware Attack?

Many businesses invest in cybersecurity tools but never develop a documented plan for responding to a ransomware incident. If you’re unsure whether your organization is prepared to detect, contain, recover from, and communicate during a ransomware event, schedule a free consultation with ITNS Consulting.

We’ll help evaluate your current readiness, identify response gaps, and develop a practical strategy that strengthens your ransomware preparedness, business continuity, and recovery capabilities.

Does Your Organization Have a Plan for the Next Cyber Incident?

When ransomware strikes, confusion and delays can make an already difficult situation worse.

Download our Incident Response Plan Template to establish clear roles, responsibilities, communication procedures, escalation paths, and recovery actions that help your organization respond effectively when a ransomware or cybersecurity incident occurs.

🚨 Incident Response Quick Start Plan — Free Download

React Fast. Minimize Damage. Restore Operations With Confidence.

This plan breaks incident response into clear, actionable steps that help you contain threats, protect critical systems and data, preserve evidence, and communicate confidently.

It also guides secure system recovery and documentation of findings to reduce risk and prevent similar incidents from happening again.

Perfect for:

✔️ Small and mid-size businesses without a formal IR plan

✔️ Teams evaluating their current provider’s response capabilities

✔️ Organizations preparing for cyber‑insurance renewal

✔️ Leaders wanting basic readiness before adopting full IR playbooks

✔️ Anyone who wants to reduce panic and confusion during an incident

More Bits, Bytes, and Insights

<< See All Posts