The annual data breach investigations report published in May found that 96% of ransomware victims were small and medium-sized businesses, with a 60% increase in incidents originating with third parties.
The first number contradicts the perception built by press coverage, which naturally highlights attacks on large, well-known companies. The real distribution is the opposite: those hit most are those with the least security staff.
The reason is economic. Automated attacks sweep the internet looking for exposed systems, without choosing targets by size, and small companies tend to have outdated systems, reused passwords and no monitoring.
The second number, the 60% rise in third-party incidents, explains much of the rest. Small companies depend on suppliers for everything, and each integration is a door they neither control nor can audit.
The accessible defence requires no dedicated team and fits in four items: two-step authentication everywhere, automatic updates enabled, backups actually tested, and an inventory of what each connected supplier can see.
