Ransomware: the three ways in we find in almost every small business
Remote access without two-factor authentication, backups left on the same network, accounts of former staff: the three recurring flaws in small firms.
Why a twenty-person business is worth an attacker’s time
Because it is badly defended, not because it is wealthy. In its Panorama de la cybermenace 2025, ANSSI reports that 48% of the ransomware victims recorded in France are micro, small and mid-sized businesses, against 37% a year earlier — the leading category of victims, ahead of local authorities and healthcare establishments. The agency handled 128 ransomware compromises over the year. A twenty-employee firm in Nice or Sophia Antipolis matches the profile attackers look for exactly: data that has value, a constrained IT budget, no security officer in-house, and often an access route into the systems of a much larger client. Attackers are not targeting you by name: they scan entire ranges of addresses, find a door that was left ajar, and walk in. Chance does the rest. Not one of the businesses we have supported after an incident thought the subject concerned them the day before.
Source: ANSSI, Panorama de la cybermenace 2025 (CERT-FR, in French).
Way in no. 1: remote access left open without two-factor authentication
This is by far the most common. Since remote working became normal, almost every small business has opened some form of remote access — a remote desktop on a server, a VPN, or the administration console of a business application. In most of the estates we audit, that access is protected by a single username and password, often reused elsewhere and sometimes already present in a public breach. The attacker then has nothing to break: they simply log in. The fix comes down to two actions. Turn on two-factor authentication on every access exposed to the internet, email included — a code on a phone is enough to block the overwhelming majority of automated attempts. Close what has no reason to be open: a remote desktop published directly on the internet has no business being there; it should sit behind a VPN. Check your suppliers’ access as well: it is almost always missing from the inventory, and rarely protected to the same standard as your own.
Allow half a day for a firm with twenty workstations, at a cost that is essentially time. It is the best protection-to-effort ratio on the whole list.
Way in no. 2: the backup permanently connected to the same network
Many directors believe they are covered because “there is a backup”. The problem is that ransomware encrypts everything it can reach, and a USB disk plugged into the server or a NAS reachable from the network both sit inside that perimeter. We regularly see backups encrypted at the same time as the data they were meant to protect. Three rules are enough. One disconnected or immutable copy, out of the network’s reach — a disk that gets unplugged, or remote storage that forbids deletion for a fixed period. A genuine restore test, at least twice a year: a backup that has never been restored is not a backup, it is an assumption. Monitoring that alerts you when a backup fails, rather than an automated report that nobody opens. Finally, note the real restore time during the test: it is that duration, not the size of the backup, that will determine how many days your business stands still.
In an audit, this is the point we spend the most time on — because it is the one that decides whether an incident costs a day or six weeks.
Way in no. 3: the accounts that outlive departures
The third hole is administrative, not technical. An employee leaves, a contractor finishes an assignment, a placement student completes their stint: their accounts stay active, often with exactly the rights they had on day one. In firms of thirty people we regularly find active accounts belonging to people who left more than two years ago, sometimes with administrator rights. Nobody is watching those accounts, their passwords have not changed in years, and a login from one of them will raise no suspicion at all. The fix is a procedure, not a piece of software: an up-to-date list of accounts and their rights, systematic deactivation on the day of departure — built into the leaving process, in the same way as handing back the keys — and a review every six months that checks each person holds only the access their role requires. That review takes two hours per half-year in a thirty-person business, and it removes an entire category of risk.
Key points
- Two-factor authentication on everything reachable from the internet, starting with email and remote desktop.
- One disconnected or immutable backup copy, tested with a real restore at least twice a year.
- Accounts deactivated on the day of departure, and rights reviewed every six months.
Where to start on Monday morning
In this order, because it runs from the most profitable to the most costly. Week 1: list the access points open from the internet and switch on two-factor authentication everywhere it already exists at no extra cost — email, VPN, online tools. Week 2: check where your backups are, unplug one of them, and restore a folder at random to confirm that restoring really works. Week 3: pull the list of user accounts, compare it with the list of people actually present, and deactivate the rest. Week 4: write the procedure down — who does what, when, and to whom a suspicious email should be reported. Those four weeks cost nothing but time, and they close the doors through which the great majority of the incidents we handle arrive. Once that first month is behind you, a full audit lets you tackle what needs a budget: network segmentation, monitoring, and email protection.
Does this subject concern your business?
This article belongs to our cybersecurity pillar. The first conversation is free and without obligation, in Nice and the surrounding area.