Blog / Threats
Threats
The First 72 Hours of a Ransomware Attack on a Small Business, Hour by Hour
What a ransomware attack on a small business looks like in the first 72 hours, what the 2026 numbers say about paying, and five moves that decide recovery.
Monday, 6:40 a.m., and the dispatch board is a ransom note
The dispatcher at a 35-person HVAC contractor gets in early on Mondays because the crews start calling from their trucks at seven. She unlocks the office, wakes the scheduling screen, and instead of the day's jobs she gets a black window with white text and a countdown. The second monitor shows the same thing. So does the front-desk machine.
By 7:10 the phones are going. Four crews want to know where they are supposed to be. The service manager tries the cloud accounting login and it works, which feels like good news until he realizes the customer list, the open estimates and every signed maintenance agreement lived on the office server, the one now showing a note in broken English and a link to a chat page.
The owner arrives at 7:30. His first question is the one everybody asks: "Can we just restore from backup?" The IT guy, one contractor shared with three other businesses, says he will check. He calls back at 9:15. The backup drive was plugged into the same server. It is encrypted too.
Nothing has been decided yet, and the most expensive part of the week has already happened. It happened Thursday night, when the first login came through a remote support tool nobody remembered installing.
What the heck does this mean
Ransomware is a program that scrambles your files so only the attacker can unscramble them, then charges you for the key. That is the short version. The 2026 version has more moving parts.
Initial access is the way in. Usually a stolen password, a phishing email or an unpatched box that faces the internet. Rarely anything from a movie.
Dwell time is the gap between the attacker getting in and you noticing. They spend it finding your backups, mapping your network and copying the data they will later threaten to publish.
Encryption is the loud part. It usually starts at night or on a weekend, when nobody is watching, and it is the last step, not the first.
Double extortion means they encrypt and they steal. A working backup fixes half the problem. The other half is your customer list on a leak site with your company name on it.
Here is the part most owners miss. By the time you see the note, the attacker has been inside for days. The 72 hours after discovery are about containment and hard decisions. The 72 hours before it are where the outcome was decided.
The numbers that matter
Ransomware was present in 48% of breaches in the Verizon 2026 Data Breach Investigations Report, the median ransom payment was $139,875, and 69% of victims did not pay. Read that median again. It is a number that ends a lot of 35-person companies.
Only 34% of organizations with 100 to 250 employees stopped the attack before encryption, according to the Sophos State of Ransomware 2026 survey. Two out of three found out the way our dispatcher did.
Initial ransom demands rose 47% year over year while 86% of policyholders refused to pay, per the Coalition 2026 Cyber Claims Report. The attackers are asking for more. The insured are paying less, because their insurers have a plan for the week and the attacker does not get to set the pace.
What to do this week
- Test a restore, not a backup. Pick one server, pick one folder, and have your IT person bring it back on a clean machine while you time it. A backup you have never restored is a hope, not a control. (CIS 11 Data Recovery)
- Put one copy of your backups where the server cannot reach it: an offline drive that leaves the building, or cloud storage set to immutable so nobody, including you, can delete it for 30 days. (CIS 11 Data Recovery)
- Replace plain antivirus with endpoint detection on every computer, including the owner's laptop and the one in the warehouse. Antivirus looks for known bad files. Detection looks for bad behavior, like a program encrypting 4,000 files in a minute. (CIS 10 Malware Defenses)
- Write the one-page "bad Monday" plan and print it, because the plan on the server is now encrypted. Who calls the insurer, which cables get pulled first, where the paper list of customer phone numbers lives. (CIS 17 Incident Response Management)
- Decide the payment question now, in a calm room, with your insurer and your lawyer. Nobody makes a good six-figure decision at 3 a.m. under a countdown clock. (CIS 17 Incident Response Management)
- Turn on multi-factor authentication for every remote way into the network, then remove the remote tools you cannot name. That Thursday-night login should have failed. (CIS 6 Access Control Management)
Where AccuSights fits
Our assessment finds the Thursday-night problem before it becomes the Monday-morning one: the remote tool nobody installed, the backup drive on the same power strip as the server, the admin password from 2019. Start with the Cyber Hygiene Test, three minutes, no sales call attached. If the result bothers you, book 15 minutes with an engineer and bring the backup question.
Questions people ask
How long does it take to recover from ransomware? It depends almost entirely on one thing: whether you have a backup the attacker could not reach, and whether you have ever restored from it. With a tested offline copy, a small business is usually working again in days. Without one, recovery is measured in weeks, and some records never come back at all.
Should a small business pay the ransom? Most do not. The Verizon 2026 DBIR found 69% of victims did not pay, and Coalition reported 86% of its policyholders refused in 2026. Paying buys a decryption key that may not work, invites a second visit, and does nothing about the copy of your data the attacker already took. Decide the question before the attack, with your insurer and your lawyer in the room.
Does cyber insurance cover ransomware payments? Many policies include extortion coverage, but it usually comes with a sublimit, a requirement that the insurer approves any payment first, and a sanctions check on who is being paid. The practical rule is to call the insurer's hotline before you touch the attacker's chat page. Contacting the attacker first can void the coverage you were counting on.
The ransom note is not the attack. It is the receipt. Spend your attention on the week before, and you will never have to read one.
Questions people ask
How long does it take to recover from ransomware?
It depends almost entirely on one thing: whether you have a backup the attacker could not reach, and whether you have ever restored from it. With a tested offline copy, a small business is usually working again in days. Without one, recovery is measured in weeks, and some records never come back at all.
Should a small business pay the ransom?
Most do not. The Verizon 2026 DBIR found 69% of victims did not pay, and Coalition reported 86% of its policyholders refused in 2026. Paying buys a decryption key that may not work, invites a second visit, and does nothing about the copy of your data the attacker already took. Decide the question before the attack, with your insurer and your lawyer in the room.
Does cyber insurance cover ransomware payments?
Many policies include extortion coverage, but it usually comes with a sublimit, a requirement that the insurer approves any payment first, and a sanctions check on who is being paid. The practical rule is to call the insurer's hotline before you touch the attacker's chat page. Contacting the attacker first can void the coverage you were counting on.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
Ransomware in a Clinic: What Nine Days Without the EHR Really Looks Like
Healthcare ransomware stops refills, referrals and the front desk, not just files. What nine days of EHR downtime looks like, and how a small practice prepares.
ThreatsData Extortion Without Encryption: They Did Not Lock Anything. They Just Took It.
A data extortion attack skips encryption and goes straight to the threat: pay or your customer files go public. How it works, and what to do in the first hour.
ThreatsDeepfake Voice and Video Fraud: When the Managing Director on the Phone Is Not the Managing Director
Deepfake fraud against a business starts with a cloned voice and an urgent payment. What changed in 2026, what did not, and the callback rule that beats both.
