All Resources
Cybersecurity

Why Small Businesses Are Targets for Ransomware

"We're too small to be a target" is one of the most common things small business owners say before an incident, and it is one of the fastest to unravel afterward. Understanding why ransomware groups operate the way they do explains why size offers almost no protection on its own.

Published August 9, 2026 Updated August 9, 2026 7 min read By Joshua Arimoro Greater Sudbury & Ontario
The short answer

Small businesses are targeted for ransomware because most attacks are automated and opportunistic rather than hand-picked, driven by ransomware-as-a-service affiliates and initial access brokers who scan the internet for exposed remote desktop, VPN, and unpatched systems regardless of company size. A business does not need to be large or high-profile to be found; it only needs an exposed, unpatched entry point.

Ransomware is a business model, not a targeted campaign

Most ransomware today is delivered through a ransomware-as-a-service model, where a core group develops the encryption software and negotiation infrastructure, then rents it out to affiliates who carry out the actual attacks in exchange for a cut of any ransom paid. This turns ransomware into a volume business, where affiliates are incentivised to compromise as many organisations as possible, not to carefully select a handful of prestigious victims.

The Canadian Centre for Cyber Security has described ransomware as one of the most disruptive threats facing Canadian organisations of all sizes, precisely because of this scalable, affiliate-driven model.

Initial access brokers do the scouting

A separate criminal specialty has emerged around simply finding and selling access. Initial access brokers scan the internet for exposed remote desktop protocol, unpatched VPN appliances, and other easy entry points, then sell that access on criminal marketplaces to whoever is willing to pay, often ransomware affiliates.

This means the business that gets compromised is frequently chosen by an automated scan that found a vulnerability, not by a person who researched the company and decided it was worth attacking. Being small, low-profile, or non-newsworthy provides no protection against a scanner.

Exposed RDP and VPN are still common entry points

Remote desktop protocol left open directly to the internet, often set up years ago for a legitimate remote work need and never revisited, remains one of the most consistently abused entry points. The same applies to VPN appliances running outdated firmware with known vulnerabilities.

Small businesses are statistically more likely than large enterprises to have this kind of legacy exposure, simply because they are less likely to have a dedicated security team reviewing what is internet-facing.

Wondering what an attacker's automated scan would find on your network?

A risk assessment identifies exposed remote access and unpatched systems before a scanner does.

Request a Cybersecurity Risk Assessment

Unpatched edge devices widen the door

Firewalls, VPN gateways, and other internet-facing appliances occasionally have serious vulnerabilities disclosed, and attackers move quickly once a vulnerability becomes public, sometimes within days. An unpatched edge device does not need a human attacker to notice it, it needs an automated scanner running the same exploit against thousands of IP addresses.

This is why patch management is not just an IT hygiene issue but a direct ransomware prevention control, covered in more depth in how to protect your business from ransomware.

Why 'we are too small' does not hold up

The reasoning behind "we're too small" usually assumes a human attacker deciding whether a target is worth the effort. Ransomware-as-a-service affiliates and initial access brokers do not work that way. Their tools do not know or care how many employees a business has; they care whether a system is reachable and vulnerable.

Small businesses can also be attractive precisely because they often have fewer defensive layers than a large enterprise, and because a smaller ransom demand is still more likely to be paid quickly to avoid extended downtime, which keeps the model profitable at scale.

What actually reduces the odds

Since most of this activity is automated scanning rather than targeted selection, the goal is to not be the easy result the scan finds. Closing exposed remote access, keeping edge devices patched, enforcing MFA, and maintaining tested offline backups all address the specific mechanics described above rather than a vague notion of "being more secure." Our cybersecurity checklist for small businesses and most common cybersecurity threats articles go further into prioritisation.

Sources and further reading

Frequently asked questions

Are small businesses really targeted by ransomware or just large companies?

Both, because most ransomware attacks are delivered through automated scanning and affiliate programs that do not filter by company size, only by whether a system is exposed and vulnerable.

What is ransomware-as-a-service?

It is a model where developers build ransomware and negotiation infrastructure, then rent it to affiliates who carry out attacks for a share of any ransom paid, scaling attacks well beyond what a single group could do alone.

What is an initial access broker?

An initial access broker is a criminal specialist who finds and sells access to compromised networks, often to ransomware affiliates, rather than carrying out the ransomware attack themselves.

Is exposed RDP still a common ransomware entry point?

Yes, remote desktop protocol left open directly to the internet remains a commonly abused entry point, particularly on systems set up for remote access years ago and never revisited.

Does paying a smaller ransom make small businesses more attractive targets?

It can, because attackers running a volume-based business model may see faster, more predictable payment from smaller demands, which keeps the overall model profitable even at lower individual payouts.

What is the single most effective step to reduce ransomware risk?

There is no single step, but closing exposed remote access and enforcing MFA address two of the most common initial entry paths described by the Canadian Centre for Cyber Security.

About the author

Joshua Arimoro

Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.

More about our team

Ready to find and close your exposed entry points?

We review internet-facing systems, remote access configuration, and patch status as part of a straightforward assessment.

Keep exploring

Related services, locations, and resources

Related services

Related resources