Protection against ransomware for small businesses in Nice and on the Côte d'Azur
Protecting yourself from ransomware comes down to six measures, not to one miracle product: two-factor authentication on remote access and on email, an offline backup whose restore has actually been tested, monitored anti-virus, updates that are tracked, unused accounts removed and a segmented network. MZ Informatique deploys them across small businesses in Nice and the Alpes-Maritimes, and comes out at short notice when the attack has already landed.
Why are small businesses the first target for ransomware?
Because they are the least well defended, not because they are the wealthiest. In its Panorama de la cybermenace 2025, France's national cybersecurity agency ANSSI reports that 48% of the ransomware victims recorded in France are micro, small and mid-sized businesses, against 37% a year earlier — the largest category of victims, ahead of local authorities and healthcare organisations. The agency handled 128 ransomware compromises over the year.
A twenty-strong firm in Nice or Sophia Antipolis fits the profile attackers look for exactly: data that has value — quotations, payroll, client files — a tight IT budget, no security officer in-house, and often access to the systems of a larger customer. Attackers are not targeting you by name: they scan, they find a badly protected way in, and they walk through it.
Source: ANSSI, Panorama de la cybermenace 2025 (CERT-FR), published on 11 March 2026.
02
How does ransomware get into a small business?
Through three doors, and nearly always the same three. Remote access open to the internet without two-factor authentication — remote desktop, a badly configured VPN, an admin interface left exposed. A reused password, found in a public breach and tried automatically against your email. An attachment or a link opened by somebody in a hurry, which installs the initial payload.
The encryption never happens on day one. The attacker first explores the network, locates the backups, escalates their rights, exfiltrates data to apply pressure, and only then pulls the trigger. It is that delay that makes monitoring worthwhile: it turns a catastrophe into an incident.
03
Which protections do we put in place?
Six measures that cover most of the risk, in the order in which they pay off best. They are rolled out gradually, without stopping your business, and each one is verifiable: we show you the result rather than asking you to take our word for it.
Two-factor authentication on remote access and on email.
An offline or offsite backup whose restore is genuinely tested.
Monitored anti-virus on workstations and servers, with alerts raised to us.
Updates applied and tracked, on workstations as well as on network equipment.
Unused accounts removed and administrator rights reviewed.
Network segmentation, so that one compromised machine does not open everything.
Monitoring is charged as a monthly fee per workstation: monitored anti-virus, offsite backup, updates and support. You know what you are paying, and for how many machines.
04
What should you do during an attack?
Act in this order, and do not improvise. One: isolate — unplug the network cable and turn off Wi-Fi on the affected machines, but do not shut them down: the memory holds traces that the analysis depends on. Two: protect the backups by physically disconnecting the disks and cutting access to remote storage. Three: call a professional before restoring anything: a restore started too early reinfects the network. Four: do not pay the ransom — payment guarantees neither the key nor that your data will stay unpublished. Five: report it — a complaint to the police or the gendarmerie, and notification to the CNIL within 72 hours if personal data is involved.
Note the time of the first signs, the messages displayed and the machines affected: these details speed up the analysis and determine how good the restore will be. Say nothing publicly until you have measured the real extent of the incident.
Attack under way? Call us straight away — we come out across Nice and the Alpes-Maritimes.
It is costed in advance and does not move along the way. For a small business in the Alpes-Maritimes with ten to thirty workstations: initial remediation, a one-off engagement that closes the weaknesses identified and puts the backups back on a proper footing; protection and monitoring on a monthly fee, per workstation per month, covering monitored anti-virus, offsite backup, updates and support.
For scale, these amounts bear no comparison with the cost of a business shutdown lasting several days. We do not do three-year lock-ins, and we do not do surprise invoices.
The figures
What the threat looks like, sources included
48%
of the ransomware victims recorded in France are micro, small and mid-sized businesses, against 37% the previous year.
ANSSI — Panorama de la cybermenace 2025
128
ransomware compromises handled by the French national agency in 2025 alone.
ANSSI — Panorama de la cybermenace 2025
72 h
the legal deadline for notifying the CNIL after a personal data breach.
GDPR, article 33
What goes with it
The two pieces of work that cut the risk most
Protection without a tested backup and without an alert team stays protection in name only.
No. Payment guarantees neither a working decryption key nor that data already exfiltrated will stay unpublished, and it marks your company out as one that pays. The only real way out is a clean, offline, tested backup: which is why we always start there.
Is our anti-virus not enough?
It is necessary, but not sufficient. Anti-virus does not stop a stolen credential used on a legitimate remote access, nor an administrator whose password has leaked. It is the combination of two-factor authentication, an offline backup and monitoring that makes the difference, not the product installed on the machines.
How long does it take to restore after an attack?
That depends entirely on the state of your backups when the incident happened, on the volume of data and on the number of servers to rebuild. It is precisely what the disaster recovery plan is there to settle in advance, rather than discover on the day. We define that time with you, in writing.
Do you come out at short notice across Nice and the Alpes-Maritimes?
Yes. We take the call as a priority and talk you through the isolation steps immediately, before we even set off. We then handle containment, the analysis of how the intrusion started, the restore from a clean backup and a staged return to service, and we support you through the police report and the CNIL notification.
Would you know how to restart after ransomware?
A free audit, with no obligation, answers that question in writing, on site in Nice, Sophia Antipolis, Cannes or Monaco.