Resources & News

The New World of Ransomware

Ransomware Protection

The New World of Ransomware

According to recent results by Axis Intelligence Research:

  • 48% of all confirmed data breaches are some form of ransomware.
  • The most common source of ransomware attacks was phishing, followed by fake software and bogus browser updates.
  • 96% of the targeted victim companies are small- to medium-sized organizations.

And a recent ransomware attack at Fairlife Dairy in July 2026 is revealing a dangerous new trend in ransomware that all businesses need to understand.

The anatomy of new ransomware

The revenue split. The providers of this new form of ransomware created the malware as a service. Commonly known as Ransomware as a Service (RaaS), the writer of the code gets affiliates to deliver the code on their behalf. The affiliates use the malware and split the ransom. The stated split is generous, with 80% going to the affiliate and 20% going back to the source code organization.

But there are other profit centers:

  • selling stolen files: 60/40 split
  • brokering back door access to files: 50/50 split

The process. Typically the ransomware starts with a phishing email where an unsuspecting employee opens an infected attachment or clicks on a malicious link. Once in your network, the thieves move laterally, elevating their privileges and mapping your network. They find and erase recovery tools and look for shadow copies of data like attached backups. Once ready to strike, they encrypt your data and send a ransom note. You are then directed to a secure chat to communicate with them, and your payments are often in untraceable cryptocurrency.

What is new. Ransomware software now often has a new feature called a wiper function. This new threat automatically deletes files, including any backups it finds. This creates added pressure to pay the ransom, and if your backups are automatic and linked to your main network, they are held hostage as well. So even if you DO pay the ransom, you may not have any recoverable files, as they have already been deleted!

What your business can do

Awareness is CRITICAL. Ransomware looks for and exploits your company's weakest link. So the first place to start is making sure everyone in your organization is aware of the problem.

Here are some other suggestions:

Equip your employees. Create an ongoing program for your employees to learn about cybersecurity and ransomware. Require mandatory participation in regular cybersecurity training. This should be done more than once per year. With most ransomware attacks originating from phishing emails, have specific training on email security as well as other training programs.

Create an evergreen written information security plan. Have a plan in place in case your business does experience a ransomware attack. Require all employees and vendors to review your plan and acknowledge this review. These plans, often called WISPs, are mandatory for many organizations, but realistically every business should have one.

Encrypt your data. It is one thing to have your data held hostage; it is worse if they can use it to do future damage. So encrypt all your files, backups, and every employee's computer.

Multi-factor authentication security

Require multi-factor access, even within your network if appropriate. If they get into your network, make it hard to get into sensitive systems.

Not all in one basket. There is a current trend to move software off your computers and onto servers on the internet. It is sold as a more secure option. However, as long as someone is logging into a system, it actually may make matters worse! This is because once someone is in, they can now see ALL your software. To combat this risk, do not put all your eggs in one basket. Have your WISP in a separate off-site location as well as your disaster recovery plan.

Good and segregated backups. Include frequent backups of all company data and the ability to quickly restore the backup data in the event of an attack so your business can continue operating. But ensure your backups are physically separated from your primary network and systems, otherwise a corrupted file will quickly corrupt your backups as well.

Test your security. Whether it's hiring a full-time employee or outsourcing to a contractor, consider making the investment to partner with a reputable cybersecurity expert. Send your own simulated phishing emails and see if any employees fall for the trap. Conduct penetration tests, and other security tests as appropriate.

Make someone accountable. Make one person in your business responsible for security preparedness and note this in your WISP. Then designate a separate person as the point of contact for reporting anything suspicious. Train these two people to take swift action if there is any suspicious activity.

Ransomware is no longer just an IT problem. It is a serious business risk that can disrupt operations, compromise sensitive information, and threaten your company's financial stability. As ransomware tactics continue to evolve, small and midsize businesses need to be proactive rather than wait for an attack to happen. By educating employees, strengthening access controls, maintaining secure and segregated backups, regularly testing your defenses, and keeping your security plan current, you can significantly reduce your exposure. Ransomware protection for small businesses starts with preparation today, because the best time to strengthen your defenses is before an attacker finds a weakness.

Ready to Get Compliant?

Create your IRS WISP in minutes with WISP Builder's all-in-one compliance tool.

View Plans