In 2026, ransomware remains the top cyber threat facing French and Luxembourg SMBs. ANSSI reports continued growth of incidents hitting the 50-250 employee segment, considered a preferred target by structured criminal groups. This guide summarises what executives need to understand, measure and decide.
State of the ransomware threat in 2026
The ransomware landscape has changed profoundly since 2022. Three trends define 2026: widespread double extortion (encryption + data leak), professionalisation of groups via the RaaS (Ransomware-as-a-Service) model, and mass targeting of SMBs seen as easy prey.
Active 2026 groups — LockBit (variant 5.0), BlackCat, Royal, Play, Akira, RansomHub — operate as structured criminal businesses with affiliate programmes, victim support and professional negotiators. Affiliate entry has dropped below $1,000 on certain RaaS platforms, democratising the activity.
In France, the CERT-FR 2025 report identifies the 50-250 employee SMB segment as the preferred target (38% of reported incidents), ahead of local authorities (27%) and mid-caps (19%). Grand Est is among the most affected regions with a high number of reported incidents in 2025.
Anatomy of a modern ransomware attack
The era of "click an attachment → instant encryption" is over. A 2026 attack typically follows a 7-phase timeline over 7 to 45 days.
- Reconnaissance — LinkedIn OSINT, executive mapping, IT-provider mapping, exposed-port scanning.
- Initial access — targeted phishing (60%), VPN/RDP vulnerability exploitation (22%), purchase from an Initial Access Broker (15%), stolen account (3%).
- Persistent foothold — Cobalt Strike deployment, hidden AnyDesk, hidden admin accounts. Average dwell time before detection: around 21 days.
- Privilege escalation — Active Directory exploitation, LSASS dump, Kerberoasting, Zerologon or PrintNightmare exploits if unpatched.
- Exfiltration — copying 50 to 500 GB to Mega.nz, RClone to S3, HTTPS transfers to evade IDS.
- Backup sabotage — systematic hunt for Veeam, Synology, Acronis. Attempted deletion via compromised admin accounts.
- Trigger — nighttime encryption (often Friday evening), ransom note drop, leak countdown start.
Real cost of an attack for an SMB
The direct cost of the ransom is only part of the bill. An 80-employee SMB hit in 2025 documented with BISPRO the full 90-day post-incident cost breakdown.
- 12-day business interruption — around €98,000
- Incident response and forensic — €42,000
- Infrastructure rebuild — €38,000
- Legal advice and CNIL filings — €22,000
- Cyber-insurance premium increase over 3 years — €18,000
- Crisis communication — €12,000
- Overtime salary surcharge — €11,000
- Customer losses identified at 6 months — €9,000
- Total observed (ransom NOT paid) — around €250,000
7 technical measures that block 95% of attacks
Analysis of 200+ public incident reports (ANSSI, CERT-FR, Verizon DBIR 2025) shows that the vast majority of compromises exploit a limited set of recurring weaknesses. The seven measures below, deployed together, statistically block nearly all attempts.
1. MFA everywhere, no exception
Strong authentication (ideally FIDO2 keys like YubiKey) on all remote access: VPN, RDP, Microsoft 365, Google Workspace, admin accounts. Blocks roughly 99% of credential-stuffing attacks.
2. Next-generation EDR/XDR
Endpoint Detection & Response (Stormshield SES Evolution, SentinelOne, CrowdStrike Falcon, Microsoft Defender for Business). Behavioural detection and automatic isolation of compromised endpoints in seconds.
3. Disciplined monthly patch management
Monthly Windows Update and third-party patches (Chrome, Firefox, Adobe). Maximum 14-day delay on critical patches. Vulnerabilities older than 30 days represent a dominant share of initial accesses.
4. Network segmentation
Distinct VLANs for users, servers, IoT, guests, OT/SCADA. Inter-interface filtering. Prevents lateral movement after an initial compromise.
5. Email filtering with sandbox
Anti-phishing solution with attachment sandboxing (Mailcleaner, Vade, Proofpoint, Microsoft Defender for Office 365 P2). Blocks a large majority of malicious emails before they reach the user.
6. Recurring user awareness
Structured programme combining two annual sessions, monthly phishing simulations and new-joiner onboarding. Phishing click-rate reduction can reach 70-80% over 12 months.
7. Tested immutable backup
See the dedicated 3-2-1-1-0 section below. Immutable, tested backup is the last safety net: if everything else fails, it guarantees recovery without paying a ransom.
The 3-2-1-1-0 immutable backup rule
The historic 3-2-1 rule no longer suffices against modern ransomware which actively targets backups. The new Veeam reference is 3-2-1-1-0:
- 3 copies of each data set
- 2 different media types
- 1 off-site copy
- 1 offline or immutable copy (air-gap or S3 Object Lock)
- 0 errors on the last restoration test
Immutable storage (S3 Object Lock, removed LTO tapes, WORM snapshots) guarantees that no action — including administrative — can delete data during the retention window. It is the ultimate safeguard against an attacker who has obtained domain admin rights.
8-step incident response plan
When an incident hits, improvisation is costly. A written response plan, tested annually, divides return-to-normal time by 3 to 5 on average.
- Detection and qualification — incident confirmation, initial scope.
- Crisis team activation — CEO, IT director, legal, communications, cyber provider.
- Containment — network isolation, VPN shutdown, suspicious account disabling.
- Regulatory notification — CNIL if personal data, ANSSI if NIS2, cyber-insurance.
- Forensic and eradication — attack-chain analysis, removal of every backdoor.
- Restore from backup — clean rebuild, restoration ordered by business priority.
- Return to normal — gradual reopening, reinforced monitoring for 90 days.
- Lessons learned — update plan, retrain teams.
Should you pay the ransom?
Official ANSSI, FBI and CERT-EU position: no. Three main reasons.
- Funding the criminal ecosystem and the next victim.
- No recovery guarantee: according to the Sophos 2024 study, around 28% of SMBs that paid did not recover their full data.
- Marking the business as a "paying" target — re-attack risk within 18 months for nearly 38% of victims.
Legally in France, payment is not forbidden but the LOPMI law conditions any cyber-insurance reimbursement on a prior police filing and compliance with a 72-hour notification window.

