Why are small businesses the first target of cyberattacks?
Because they are the least well defended, not because they are the wealthiest. In its Cyber threat overview 2025, the French national agency ANSSI reports that 48% of the ransomware victims recorded in France are micro, small and mid-sized businesses, against 37% a year earlier — the largest category of victims, ahead of local authorities and healthcare organisations. The agency handled 128 ransomware compromises over the year. A twenty-employee business in Nice or Sophia Antipolis is exactly the profile attackers look for: data that has real value — quotes, payroll, client files — a constrained IT budget, no security officer in house, and often an access route into the systems of a larger customer. Attackers are not targeting you by name: they scan, find a poorly protected remote access or a reused password, and walk in.
Source: ANSSI, Panorama de la cybermenace 2025 (CERT-FR), published 11 March 2026.The good news fits in one sentence: those entry points are few and they close quickly. In almost every IT estate we audit on the French Riviera, the same three gaps come back — a remote access exposed to the internet without two-factor authentication, backups stored on the same network as the data, and former employees' accounts that were never disabled. None of the three is expensive to fix.

