Home Cybersecurity Ransomware and Small Businesses: How Attacks Happen and How to Protect Yours
Cybersecurity

Ransomware and Small Businesses: How Attacks Happen and How to Protect Yours

Share
Share

In June 2023, a criminal group called Akira got into the systems of KNP Logistics, a British trucking firm with more than 500 lorries and roughly 750 staff. According to reporting by Motor Transport on a BBC investigation, the attackers got in by guessing one employee’s weak password. They encrypted the company’s data and destroyed its servers and backups. By September, the business, whose roots went back 158 years, was in administration.

Stories like that tend to get filed under “big company problems.” They shouldn’t be. KNP was a mid-sized haulage company, not a bank. And in Canada, the numbers suggest ransomware is something every owner-operator with a laptop and a customer list should think about.

This piece looks at how a typical attack unfolds, what Canadian government data says about the threat, a few real incidents, and a practical defensive checklist. It’s deliberately focused on protection. Nothing here is a substitute for advice from a qualified IT security provider or your lawyer, and we’d encourage any business that handles personal data to talk to both.

What the Canadian data says

The Canadian Centre for Cyber Security, part of the Communications Security Establishment, publishes a National Cyber Threat Assessment every two years. The 2025–2026 edition, released in October 2024, states plainly that “ransomware is the top cybercrime threat facing Canada’s critical infrastructure.” It also reports that the average ransom paid in Canada in 2023 was $1.13 million, an increase of almost 150 per cent in two years, and judges that ransomware actors will “almost certainly” escalate their extortion tactics over the following two years.

The Cyber Centre followed that with a dedicated Ransomware Threat Outlook 2025–2027. A few of its findings matter directly for smaller firms:

  • Ransomware incidents known to the Cyber Centre grew by an average of 26 per cent a year from 2021 to 2024.
  • The actors targeting Canada are judged to be “almost certainly opportunistic and financially motivated.” In plain terms, they go where the door is open, not just where the money is biggest.
  • The groups it flagged as most active against Canadian targets in 2024 were Akira, Play and Medusa.
  • Common ways in include unpatched software, stolen or weak credentials, phishing and exposed Remote Desktop Protocol connections.
  • Generative AI is very likely helping criminals write more convincing phishing lures and speed up their operations.

Statistics Canada adds the business-level view. Its survey of cyber security and cybercrime for 2023 found about one in six Canadian businesses were affected by a cyber incident that year. Among them, 13 per cent identified ransomware. Most victims (88 per cent) did not pay, and of those who did, 84 per cent paid less than $10,000. Recovery costs across Canadian businesses hit $1.2 billion in 2023, roughly double the 2021 figure. Only about one in eight affected businesses reported the incident to police, so the real numbers are almost certainly higher.

That small-ransom detail is telling. Big-name attacks with seven-figure demands grab headlines, but many victims are small firms paying (or refusing to pay) amounts that are survivable for a bank yet ruinous for a dental office.

Small firms are hit disproportionately

International data points the same way. Verizon’s 2025 Data Breach Investigations Report, as summarized by The Record, found ransomware present in 88 per cent of breaches at small and medium businesses, against 39 per cent at larger organizations. The median ransom paid fell to US$115,000, and 64 per cent of victims refused to pay, up from 50 per cent two years earlier.

How an attack usually unfolds

You don’t need to understand the technical details to defend against ransomware, but it helps to know the broad shape of an incident, because each stage is a chance to stop it.

  1. Getting in. Attackers rarely break through anything exotic. They log in with a stolen or guessed password, exploit a known flaw in an internet-facing device that hasn’t been updated, or trick someone into opening a malicious attachment.
  2. Looking around. Once inside, they spend time mapping the network, finding the file server, the accounting system and, crucially, the backups.
  3. Taking data. Many groups now copy sensitive files before doing anything visible. This sets up “double extortion”: pay or we publish your customer records.
  4. Locking things up. They encrypt systems, often timed for a weekend or holiday, and try to wipe or encrypt backups so recovery is impossible.
  5. The demand. A ransom note appears with a deadline. The Cyber Centre’s threat assessment notes that groups increasingly use countdown timers, contact victims’ clients directly, and publicly shame organizations to raise the pressure.

Notice how much depends on steps one and four. If attackers can’t get in easily, and if your backups survive, the whole business model weakens.

Ransomware and Small Businesses: How Attacks Happen and How to Protect Yours
Photo: Backup Stacks by Jaymis via Flickr, CC BY 2.0

Real incidents worth learning from

London Drugs, 2024

In late April 2024, the B.C.-based retailer London Drugs temporarily closed its stores across Western Canada after what it first called an operational issue. The LockBit group later claimed responsibility and, according to TechRadar’s reporting, demanded $25 million. London Drugs said it was “unwilling and unable” to pay, confirmed that corporate files and some employee information were taken, and offered affected staff two years of credit monitoring. It’s not a small business, but the story shows how an attack spills over: closed pharmacies, worried employees, weeks of disruption.

A Toronto dental clinic, 2019

Closer to the scale of most Canadian businesses is the case reported by the Canadian Internet Registration Authority: a Toronto dental clinic where Ryuk ransomware encrypted 19 of 22 computers. The attackers demanded $165,000. The owner said he might have stretched to around $20,000, which CIRA noted was roughly half a dental assistant’s salary. The ransom was simply out of reach.

KNP Logistics, 2023

The KNP case from our introduction is the most sobering because of how ordinary the entry point was. One weak password and backups that the attackers could reach. Neither problem requires a big budget to fix.

A defensive checklist for small businesses

The Cyber Centre’s Baseline Cyber Security Controls for Small and Medium Organizations, aimed at organizations with fewer than 499 employees, explicitly takes an 80/20 approach: get most of the protection from a small set of habits. Combined with the U.S. #StopRansomware Guide from CISA, the FBI and partners, here’s what we’d prioritize.

1. Backups that attackers can’t touch

This is the single most important item. The Cyber Centre’s ransomware playbook recommends two or more backups stored offline and inaccessible from your network, kept in more than one location.

  • Keep at least one copy disconnected or immutable, meaning it can’t be changed or deleted from your regular network or admin accounts.
  • Back up what actually runs the business: accounting files, customer records, scheduling data, not just shared folders.
  • Test restoring. A backup you’ve never restored is a hope, not a plan. The playbook suggests regular restoration drills, ideally monthly.

2. Multi-factor authentication everywhere it counts

Turn on MFA for email, remote access (VPN or remote desktop tools), cloud accounts, banking and any admin accounts. Where possible, use phishing-resistant options such as passkeys or hardware security keys rather than text-message codes.

3. Patch quickly, especially at the edge

  • Turn on automatic updates for operating systems, browsers and office software.
  • Pay particular attention to devices that face the internet: firewalls, VPN appliances, routers and remote access tools. These are frequent entry points.
  • Retire equipment and software that no longer get security updates.

4. Close the doors you’re not using

Don’t expose Remote Desktop directly to the internet. Remove old user accounts when staff leave. Give people only the access they need; your receptionist doesn’t need admin rights.

5. Train people, briefly and often

The Ransomware Threat Outlook notes that only 22 per cent of Canadian businesses gave formal cyber training to non-IT staff. A short session on spotting phishing and a clear rule (“if in doubt, call to check”) costs very little.

6. Write a one-page incident plan

Decide in advance who you’ll call: your IT provider, your cyber insurer if you have one, your lawyer. Keep a printed copy, because your systems may be down. The Cyber Centre’s playbook says the first moves are to isolate infected machines, disconnect remote access and reset credentials.

If the worst happens

The Cyber Centre advises against paying, warning that payment doesn’t guarantee you’ll get your data back and may expose you to further demands. Whether to pay is ultimately a business and legal decision, which is another reason to involve your lawyer and insurer early. Either way, report it. The playbook directs victims to local police, the Canadian Anti-Fraud Centre and the Cyber Centre itself. Reporting matters: the Cyber Centre says it sent 336 pre-ransomware notifications to more than 300 Canadian organizations in 2024, warning them before attackers struck and helping avoid up to $18 million in losses.

The cheap things are the important things

What strikes us, reading through the government reports and the case studies, is how unglamorous the fixes are. KNP didn’t fall to some nation-state super-weapon. It fell to a guessable password and reachable backups. The Cyber Centre’s own conclusion is that basic cyber hygiene works.

If you only do two things after reading this, make them these: set up a backup that lives somewhere your network can’t reach, and test that you can restore from it; then turn on multi-factor authentication for every email and remote access account. Those two steps won’t make a small business invulnerable, but they change ransomware from a company-ending event into a very bad week.

Sources and further reading

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles

Phishing in the Age of Deepfakes: Voice Clones, Fake Video Calls and How to Verify

Early in 2024, a finance employee at the Hong Kong office of...

Passkeys and the End of Passwords: How They Work and How to Switch

In 2024, Microsoft says it was seeing about 7,000 password attacks every...