Ransomware Attack Sequence Against a Small Business
Attackers automate ransomware campaigns to hit small businesses hard and fast.

Ransomware against small businesses isn't random bad luck anymore. It follows a predictable sequence, built on a business model that specifically rewards attackers for targeting companies without dedicated security staff.
Ransomware-as-a-Service is the engine behind this shift. Developers build the toolkit once, then license it to affiliates who run the actual attacks, splitting whatever ransom comes in. Under that model, a mid-five-figure payout from a 30-employee company is a better use of an affiliate's time than a months-long siege against a hardened enterprise with a security operations center watching every login. Volume beats difficulty, and small businesses are where the volume is.
Targeting itself has stopped being a human decision. Automated tools scan the internet around the clock, looking for unpatched software, weak passwords, and remote-access ports left open to the world. No one reviews a company's revenue or industry before the scan flags it. The tools select for a specific set of conditions: no patching schedule, no security operations center, no incident response plan that's ever been tested. Those conditions describe most small businesses by default, not by exception.
The numbers back up how central this has become. Ransomware accounted for 44% of all recorded data breaches in the Verizon Data Breach Investigations Report. Generative AI is compressing the attacker's timeline further, automating script generation and attack templating so a campaign that once took real planning now takes a fraction of the effort. The result shows up in the clock: the median time from initial access to encryption in 2025 was five days. A business with no detection tools in place has almost no chance of noticing an intruder inside that window, which pushes response efforts to start only after the damage is already done.
Phase 1 (Initial access): the three doors attackers use most against small businesses
Encryption is the last step in a ransomware attack, not the first. Before any file gets locked, the attacker needs a way in, and small businesses tend to leave the same three doors unlocked.
Compromised credentials are the most direct route. Passwords, session cookies, and access tokens get stolen through infostealers, phishing campaigns, or earlier breaches the business never even knew about, and once an attacker has them, they log in as a legitimate user. No malware gets installed, and there's no signature for a security tool to catch.
Exploited vulnerabilities used to be the single biggest root cause of ransomware attacks, holding that position for three straight years according to Sophos's State of Ransomware report. The 2026 edition found that email-based attacks have overtaken them, with malicious email and phishing now ranking as the top two vectors. Vulnerabilities still matter enormously for small businesses: without a regular patching schedule, a known flaw can sit exposed for weeks or months after a fix is already available.
Phishing and infostealers often work together. Generative AI lets attackers write messages that sound personal and plausible, far more convincing than the generic scam emails of a few years ago. Once a target clicks, infostealer malware harvests credentials, cookies, and tokens straight from the device, and that initial foothold is nearly invisible from the outside.
Exposed edge devices round out the list. VPNs, firewalls, and remote access tools sit on the internet by design, acting as the central gateway into a company's systems, but they don't always get patched as quickly as laptops and desktops do. A known, unpatched flaw on a VPN gateway can stay exploitable for months after the vendor ships a fix, simply because no one assigned the job of updating it.
Each of these doors has a lock that fits it. Multi-factor authentication makes stolen credentials useless even when they're already circulating on dark web marketplaces. Prompt patching closes off exploitable vulnerabilities before automated scanners find them. Email filtering, paired with security awareness training, catches phishing at the server level and at the point where an employee decides whether to click. Getting through the door is only the beginning of the attack, not the end of it.
Phase 2 (Quiet reconnaissance): what the attacker learns while no one is watching
Once inside, an attacker doesn't start encrypting files right away. The goal shifts to mapping the network, finding administrator credentials, and locating backups, all while staying quiet enough to avoid triggering any alarm.
This is the phase that decides the outcome of the whole attack. The median time from initial access to encryption in 2025 was five days, and within that window, key milestones happen fast: compromise of Active Directory, the system that controls user permissions across the network, can occur within hours of the initial break-in. Defenders have days, sometimes less, to catch the intrusion before the attacker locks in persistent access.
During this stretch, the attacker is working through the network using tools that are already installed and already trusted, like PowerShell and remote monitoring and management (RMM) software. They map out connected systems, hunt for administrative credentials that unlock more of the network, identify where backups live, and often start quietly copying data off the network for later use. None of this requires custom malware, and it looks, on the surface, like routine IT activity, so it's easy for a business without monitoring tools to miss.
A business owner running payroll or talking to a customer that week has no reason to suspect anything. Meanwhile, the attacker is reading internal files, noting where sensitive records are stored, and building a plan for what to lock and what to steal. Individual signs of this activity often look normal in isolation: an administrator login at an odd hour, a PowerShell script running on a file server, a spike in outbound data. Put together and read in context, though, those same signals reveal reconnaissance, persistence, and lateral movement building toward a full-scale attack. A business without endpoint detection has no way to connect those dots before it's too late.
The window for catching this is shrinking fast. Palo Alto Networks' 2026 Unit 42 Global Incident Response Report found that the fastest attacks in 2025 reached data exfiltration in just 72 minutes, a dramatic drop from the year before. Reconnaissance that once took days can now be compressed into little more than an hour. The margin for manual detection is disappearing right along with it.
Phase 3 (Lateral movement): how a single compromised account becomes a network-wide crisis
Once the attacker understands the layout of the network, the next move is expansion: turning a single foothold into control over as much of the environment as possible. From whatever device was first compromised, the attacker works to steal additional credentials, escalate privileges, bypass security controls, and reach servers, hypervisors, backup systems, and, where they exist, operational technology environments that run physical equipment.
Most small business networks make this easy because they're flat. There's no segmentation separating workstations from file servers from backup infrastructure, so a single compromised employee laptop can become a direct path to every other asset the business owns. One phishing click on one machine can, within hours, put the entire network at risk.
Trust relationships widen the blast radius further. A single intrusion into an IT vendor, a managed service provider, or a shared software platform can hand an attacker access across every organization connected to that vendor through existing trust relationships. This kind of supply chain compromise isn't the main story for most small businesses, but it exists as an amplifier, especially for companies that rely heavily on outside IT support.
Two controls interrupt this phase directly. Limiting admin access means that a compromised standard user account, one without administrative rights, can't escalate to domain administrator and can't reach backup systems without finding a second exploit, which takes time and increases the odds of detection. Network segmentation does the structural work: separating workstations, servers, and backup infrastructure into distinct zones forces the attacker to breach each boundary on its own, and every boundary breached buys the business more time to notice something is wrong.
Phase 4 (Backup destruction): why the obvious recovery path is the first thing attackers eliminate
This is the phase most small business owners never see coming, and it's the one that turns a bad incident into a company-ending one. Once the attacker has broad access across the network, the priority shifts to destroying or encrypting backups before deploying ransomware. Removing the recovery option is what converts simple encryption into real leverage, because a business that can restore its own files has no reason to pay.
Backup targeting isn't an accident or a side effect of the attack. Cybercriminals actively hunt down backup and recovery systems during the reconnaissance phase specifically to prevent straightforward restoration, because a business that can't recover on its own has only one option left on the table.
A case reported by The Register shows what this looks like in practice. One small business kept its entire backup on a single external drive connected to the same server that ran its main systems. When the attack hit, that drive was encrypted right along with everything else. The business couldn't pay its employees and had no way to tell who owed it money. It had been operating for years. It closed within months.
The defense here has to be built into the architecture ahead of time, not improvised after the fact. The 3-2-1 backup rule calls for three copies of data, stored on two different types of media, with at least one copy kept off-site. When a backup is genuinely disconnected, physically or logically, from the network an attacker controls, the malware simply can't reach it or overwrite it. Cloud backups that sync continuously and network-attached drives that stay mounted around the clock don't meet that bar. Both stay exposed to a compromised account with elevated privileges, which turns them into targets. An immutable or truly offline backup is the only kind that holds up at this stage of the attack.
Phase 5 (Double extortion): what happens when encryption is only the first demand
Encrypting files is where a modern ransomware attack's negotiation begins, not where it ends. Data theft happens earlier, during reconnaissance, so even a business with clean, well-protected backups still faces a second threat after restoring its systems: the attacker already has a copy of everything sensitive, and that copy becomes its own form of leverage.
Double extortion is the standard model now. Attackers copy sensitive files before encrypting anything. If the business restores from backup and refuses to pay, the attacker threatens to publish or sell the stolen data anyway. Some attacks go further, adding a third stage: triple extortion involves stealing sensitive data first, locking files second, and then directly threatening the business's customers or suppliers if payment still doesn't come through, which multiplies the reputational and legal fallout well beyond the original victim.
Employee records are often the most valuable files an attacker walks away with. Payroll systems hold Social Security numbers. Benefits platforms hold dependent information and banking credentials. HR files hold home addresses and dates of birth. That data doesn't lose its value once the breach is over. It can be used for fraud years down the line, and stolen credentials can appear in fraudulent tax filings or new account applications well after any post-breach credit monitoring offer has expired. A business owner's obligation to employees doesn't end when the systems come back online.
Restoring from backup fixes the operational disruption: locked files get unlocked, systems come back up, and the business can function again. It does nothing to address the second or third extortion lever, because the stolen data is already out of the business's hands by the time encryption even happens. Good backups solve one problem. They don't solve the other one.
Controls that interrupt the ransomware sequence, phase by phase
The attack sequence runs in a consistent order: initial access, quiet reconnaissance, lateral movement, backup destruction, then encryption and extortion. That consistency is useful, because it means each phase has a specific, known control that interrupts it, and a lean team without a dedicated security staff can deploy those controls in the same order the attack would exploit them.
Initial access gets blocked by multi-factor authentication, consistent patching, and email filtering paired with staff training, closing off credential theft, known vulnerabilities, and phishing at the same time. Quiet reconnaissance gets caught by endpoint detection tools capable of correlating activity that looks normal in isolation, like an odd-hour login or a PowerShell script, but suspicious in combination. Lateral movement gets slowed by limiting administrative access and segmenting the network, so a single compromised laptop doesn't become a direct path to every server and backup system on-site. Backup destruction gets defeated by the 3-2-1 rule, with at least one copy kept immutable or fully offline, out of reach of anything the attacker controls. Double extortion doesn't have a clean technical fix once data is already stolen. The controls earlier in the sequence carry so much weight because stopping the attacker before reconnaissance even starts is the only way to keep that stolen data off the table.
A small business doesn't need an enterprise-sized security budget to apply this. It needs to understand that the attack is not a single event but a sequence, and that every phase in that sequence is an opportunity to stop it before the next one begins.


