If you think your company is too small for a ransomware gang to care about, that’s exactly why you’re a target. Attackers no longer hand-pick their victims: they scan the internet, try stolen credentials and get in wherever the door gives way. And SMEs are the door that puts up the least resistance.
The pattern is always the same: they get in through an email or a password, move around your network without anyone noticing, encrypt your data and your backups too, and on top of that walk off with a copy to threaten you with publishing it if you don’t pay. Double extortion. The good news: a ransomware attack can be stopped with concrete, proven measures. Here’s which ones, and what to do if it’s already on top of you.
Why SMEs are the favourite target
Ransomware stopped being an attack aimed at large corporations years ago. Today it’s an industrialised business that runs on volume, and the SME ticks every box: valuable data, modest defences and a rush to get back to invoicing. The attacker knows that a company of 20 or 50 people rarely has a security team, that its backups are usually on the same network, and that, with the business at a standstill, every hour hurts enough to make paying tempting.
Then there’s the supply chain. Many SMEs are suppliers to larger companies, and compromising the small one is the easy route to reaching the big one. Your access to a client’s systems or your shared credentials turn you into a springboard, not just an end victim.
And then there’s the enemy within: “it won’t happen to me”. That phrase is the excuse behind the expired antivirus, the 2019 passwords and the backups nobody has ever tested restoring. Ransomware doesn’t punish bad luck; it punishes a lack of preparation. The difference between a scare and a two-week shutdown is decided before the attack, not during it.
How ransomware really gets in
Forget the genius hacker cracking impossible encryption. The reality is more boring, and that’s precisely why it’s more dangerous: they almost always walk in through the front door using the right key. These are the real ways in, in order of frequency.
- Email phishing. A message that looks legitimate —an invoice, a delivery notice, a supposed colleague— with an attachment or a link. One click and there’s already a foot in the door. It remains the number one way in.
- Stolen or weak credentials. Passwords leaked in earlier breaches, reused across services or so simple they’re brute-forced. With a valid username and password, the attacker doesn’t “hack”: they simply log in.
- RDP and VPN exposed to the internet. Remote desktop or VPN access left open without extra protection is a magnet. Attackers sweep the internet looking for these ports around the clock.
- Unpatched software. Servers, firewalls or applications with known, public vulnerabilities that nobody updated. The exploit is already written; all it takes is finding the forgotten system.
Once inside, the attack doesn’t encrypt straight away. The attacker moves laterally for hours or days, hunts for the administrator accounts and, above all, locates your backups to disable them before striking. By the time they finally launch the encryption, it’s already too late. The defence is won by detecting that silent movement, not the final encryption.
The defences that actually stop an attack
There’s no silver bullet, but there is a set of measures that, combined, turn your company into a target too expensive for the attacker. These are the ones that genuinely make the difference:
- EDR on every device. An antivirus detects the known; an EDR detects suspicious behaviour —lateral movement, mass encryption— and cuts it off in real time. It’s seeing the attack instead of finding out when nothing will boot up any more.
- Immutable, isolated backups. If your backup is on the same network and accessible, the ransomware encrypts it along with everything else. You need immutable backups (that can’t be modified or deleted) and one outside your environment. It’s your last card when everything else has failed.
- MFA on every access point. Two-factor on email, VPN, remote access and critical applications. A stolen password stops working if a second factor is required. It’s the measure that blocks the most attacks for the least effort.
- Patches up to date. A real process for updating operating systems, servers and applications. Closing known vulnerabilities before they’re used against you isn’t optional, it’s basic hygiene.
- Network segmentation. So an infected device can’t reach the entire company. Separating networks and applying least privilege contains the fire in one room instead of letting it tear through the building.
- Team training. Your people are the first firewall. A team that recognises a phishing attempt and knows who to alert stops an attack faster than any technology. Short, practical, repeated training.
- Incident response plan. Knowing in advance who isolates, who decides, who gets called and how you restore. Improvising during the attack costs days; having the plan rehearsed costs hours.
A backup you’ve never tested restoring isn’t a backup: it’s an assumption. And assumptions don’t survive a ransomware attack.
The key isn’t having one of these measures, but having them all working at once and supervised. This is where managed cybersecurity separates the companies that survive from the ones that don’t.
What to do in the first hour if it happens to you
If you see files with strange extensions, ransom notes or devices dropping one after another, it’s already happening. The first hour decides the size of the disaster. Act like this:
- Isolate, don’t shut down. Disconnect the affected devices from the network —cable, wifi, VPN— to halt the spread, but avoid powering them off cold: you can lose evidence and data useful for recovery.
- Don’t pay blindly. Paying doesn’t guarantee getting the data back, it marks you as someone who pays and it funds the next attack. Before deciding anything, assess the real scope and your restore options with someone who knows.
- Activate the response plan. Call in whoever decides, alert your security provider and document what has happened. An attack in progress is not the time to decide who does what; it’s the time to execute what was already decided.
- Restore from a clean backup. Before recovering, make sure the backup isn’t compromised and that you’ve closed the way in. Restoring onto a still-infected system restarts the nightmare.
- Comply with the regulations. Depending on which data was affected, there may be an obligation to report the breach. Plan for it so you don’t add a fine to the disaster.
The MagicBoxDesk offer: managed cybersecurity and ransomware-proof backup
Setting up and maintaining all of the above takes time, tools and judgement that most SMEs aren’t better off keeping in-house. That’s why at MagicBoxDesk we offer it as a managed service on a monthly fee, with no surprises: we provide the technology, the monitoring and the expertise, and you forget about the problem. It’s outsourcing your IT with security and backups included, not as an extra that gets billed once it’s already too late.
- Managed EDR on all your devices, with detection and response to suspicious behaviour.
- Backup with immutable, isolated copies, with restores tested on a regular basis.
- MFA and access control on email, VPN, remote desktop and critical applications.
- Patch and update management continuously across servers, workstations and the perimeter.
- Segmentation and hardening of the network to contain any compromised device.
- Monitoring and incident response, with a defined action plan and someone on the other end when you need it.
- Training and phishing simulations so your team stops being the weak link.
What you gain comes down to this: peace of mind, compliance and zero downtime. That job of watching out for dodgy emails, old passwords and untested backups moves to a team that does it every day. We provide remote and on-site support across Spain, with a visit to your office when it’s needed.
Protect your company before it’s too late
Ransomware gives no warning, but it does spare those who are prepared. The decision isn’t whether to invest in ransomware protection for your company, but whether you’d rather do it now, at a fixed fee, or later, with the business at a standstill and at any price. The first option always works out cheaper.
At MagicBoxDesk we set up and maintain this whole defence for you so you can get on with running your business. Request a no-obligation quote and we’ll tell you exactly what you need to sleep easy. If you’d rather tell us about your situation first, write or call us and we’ll take a look.



