New Paragraph

The Cost of Ransomware Attacks to Businesses

December 8, 2020


As technology innovates, more small businesses are leveraging tools and software that help with processes. Unfortunately, it’s these same investments that are leaving organizations of all sizes open to bad actors. The truth is that cybercriminals will always manage to find a back door and make it their job to be one step ahead of you as a business owner.


Ransomware attacks are just one example of a threat to your business — they’re common and they can be incredibly costly and eat away at your profit margins. In fact, the average cost of a ransomware attack on a business was $713,000 between the loss of business due to downtime and the harm to its reputation. Many businesses also report that it can be anywhere from three to five days before any digital files can be accessed.


What Is Ransomware?


Ransomware is malicious software (malware) that is deployed through your IT infrastructure and quite literally holds your data hostage. There are two very common approaches to ransomware that cybercriminals choose; encryption and screen lockers. Encryptors “jumble” data in your system, asking for a ransom in return for a key that will allow for decryption. Screen lockers will simply block you from accessing data with a screen that will only be unlocked with the payment of ransom.


Part of what makes ransomware so common is that it’s easily disguised in email links or attachments and then will spread quickly. Poorly protected business networks are also a prime target for ransomware, which is essentially an automated process that doesn’t take much (if any) technical skill to deploy and manage. Employees can easily be fooled into downloading programs that may seem like work-related tools but in fact “worm” their way through the network looking for holes to burrow in. This makes regular training and continuing education about ransomware a necessity.

How Do I Protect Against Ransomware Attacks?


Having a robust ransomware protection plan in place should be an on-going process that takes top priority. This plan needs to cover everything, from employee training for ransomware prevention to actionable tips that help maintain business continuity should an attack occur. There should also be a clear chain of communication to help navigate through a ransomware emergency, and the plan should be regularly reviewed.


Your business also needs to shore up IT infrastructure and best practices. Data backup should be performed consistently and firewalls should be put in place to close up vulnerabilities that cybercriminals can slip through. Restrict the software that employees can download to your business network, and patch the approved tools regularly to fix any security bugs that often go missed during development. It’s important to create a culture of safety for everyone, from top to bottom. 

Should I Pay The Ransom?


Even with prevention and detection in place, ransomware attacks can still happen. There’s no guarantee that businesses will get the data back if they do pay the ransom, but those that do decide to make the payment face less downtime. Ransomware payments generally involve cryptocurrencies like bitcoin, which is nearly impossible to track — great for criminals, but not great for those who need to make sure the payment was completed.


Also, the US Treasury Department has imposed sanctions on individuals and groups that have been found guilty of deploying ransomware attacks, effectively making it illegal for businesses to pay the ransom. The consequences can be staggering:


“A number of those sanctioned have been closely tied with ransomware and malware attacks, including the North Korean Lazarus Group; two Iranians thought to be tied to the SamSam ransomware attacks; Evgeniy Bogachev, the developer of Cryptolocker; and Evil Corp, a Russian cybercriminal syndicate that has used malware to extract more than $100 million from victim businesses.


Those that run afoul of OFAC sanctions without a special dispensation or ‘license’ from Treasury can face several legal repercussions, including fines of up to $20 million.”


If you haven’t done so already, it’s time to complete an audit of what kind of safety net you currently have in place. A third-party coach or consultant can help take the results of that audit and turn them into action items, helping to create a new plan, training systems for employees, and even connect you with insurance providers that offer specific cybersecurity and business continuity protection.


Getting a third-party perspective is as easy as reaching out to our team. With The Alexander Group, you can rest assured that you are working with a business coach who has sat in your chair. We’ve faced everything you face as a business owner — including ransomware.

May 20, 2025
It doesn't seem that long ago, in 2021, when the job market was ripe with opportunities for white-collar workers. The flood of government money during the COVID-19 pandemic and a tight labor market created a demand for workers in almost every sector of the economy. At that time, the market pendulum swung deeply in favor of the employee, and lucky candidates had their pick of positions and options for benefits. As we emerged out of the pandemic, and the labor market remained tight, many employees decided they preferred WFH over working in the office. The tight labor market at the time put leverage on the side of the workers, and in many cases, their demand to continue WFH was met. With current market volatility, economic question marks, and changing expectations, the job market has swung back in favor of employers rather than their staff. Meanwhile, many business owners and CEOs have come to realize the downsides of a remote or even hybrid work environment. Many companies are also following in the footsteps of the Trump administration and Elon Musk's DOGE team to trim the unnecessary fat of their companies and opt for efficiency. At the same time, AI has emerged as a significant opportunity to streamline operations and improve efficiency. Let's examine how current dynamics are changing the workforce, re-examine the relationship between employees and employers, and discuss how small business owners can take advantage of this moment. The Realities of Remote Work The COVID-19 pandemic drowned the whole world in change to start this new decade. Work, health, education, entertainment, politics, and everyday life changed in unexpected ways. Five years on from those tumultuous days in March 2020, lingering attitudes remain. Many employees are unhappy with RTO (return to office) mandates from CEOs. A large majority of CEOs agree that creating a positive work culture with remote employees is essentially impossible. While there may be occasional times when remote work can be helpful (such as during sickness or family emergencies), many business leaders believe that it should not be the standard. Accountability, productivity, and creativity are much easier to foster in an in-person office environment. With the pendulum swinging back in favor of employers, employees will need to adjust their expectations.
March 14, 2025
Small business owners must not give in to fear or panic. Rather, we should step back and look at the larger geopolitical picture.
By Maria Heuring January 14, 2025
Whether you try a version of Microsoft Copilot or choose a different AI product, we hope small business owners can take advantage of AI's benefits.
More Posts