Skip to content
BISPRO

Cybersecurity · 16 min read

Ransomware for SMBs 2026: the complete protection guide

Understand the modern ransomware threat, measure the risk, deploy the right defences and know how to react. Expert guide for SMB and public-sector leaders across Grand Est and Luxembourg.

Cybersecurity 16 min

In 2026, ransomware remains the top cyber threat facing French and Luxembourg SMBs. ANSSI reports continued growth of incidents hitting the 50-250 employee segment, considered a preferred target by structured criminal groups. This guide summarises what executives need to understand, measure and decide.

State of the ransomware threat in 2026

The ransomware landscape has changed profoundly since 2022. Three trends define 2026: widespread double extortion (encryption + data leak), professionalisation of groups via the RaaS (Ransomware-as-a-Service) model, and mass targeting of SMBs seen as easy prey.

Active 2026 groups — LockBit (variant 5.0), BlackCat, Royal, Play, Akira, RansomHub — operate as structured criminal businesses with affiliate programmes, victim support and professional negotiators. Affiliate entry has dropped below $1,000 on certain RaaS platforms, democratising the activity.

In France, the CERT-FR 2025 report identifies the 50-250 employee SMB segment as the preferred target (38% of reported incidents), ahead of local authorities (27%) and mid-caps (19%). Grand Est is among the most affected regions with a high number of reported incidents in 2025.

Anatomy of a modern ransomware attack

The era of "click an attachment → instant encryption" is over. A 2026 attack typically follows a 7-phase timeline over 7 to 45 days.

  • Reconnaissance — LinkedIn OSINT, executive mapping, IT-provider mapping, exposed-port scanning.
  • Initial access — targeted phishing (60%), VPN/RDP vulnerability exploitation (22%), purchase from an Initial Access Broker (15%), stolen account (3%).
  • Persistent foothold — Cobalt Strike deployment, hidden AnyDesk, hidden admin accounts. Average dwell time before detection: around 21 days.
  • Privilege escalation — Active Directory exploitation, LSASS dump, Kerberoasting, Zerologon or PrintNightmare exploits if unpatched.
  • Exfiltration — copying 50 to 500 GB to Mega.nz, RClone to S3, HTTPS transfers to evade IDS.
  • Backup sabotage — systematic hunt for Veeam, Synology, Acronis. Attempted deletion via compromised admin accounts.
  • Trigger — nighttime encryption (often Friday evening), ransom note drop, leak countdown start.

Real cost of an attack for an SMB

The direct cost of the ransom is only part of the bill. An 80-employee SMB hit in 2025 documented with BISPRO the full 90-day post-incident cost breakdown.

  • 12-day business interruption — around €98,000
  • Incident response and forensic — €42,000
  • Infrastructure rebuild — €38,000
  • Legal advice and CNIL filings — €22,000
  • Cyber-insurance premium increase over 3 years — €18,000
  • Crisis communication — €12,000
  • Overtime salary surcharge — €11,000
  • Customer losses identified at 6 months — €9,000
  • Total observed (ransom NOT paid) — around €250,000

7 technical measures that block 95% of attacks

Analysis of 200+ public incident reports (ANSSI, CERT-FR, Verizon DBIR 2025) shows that the vast majority of compromises exploit a limited set of recurring weaknesses. The seven measures below, deployed together, statistically block nearly all attempts.

1. MFA everywhere, no exception

Strong authentication (ideally FIDO2 keys like YubiKey) on all remote access: VPN, RDP, Microsoft 365, Google Workspace, admin accounts. Blocks roughly 99% of credential-stuffing attacks.

2. Next-generation EDR/XDR

Endpoint Detection & Response (Stormshield SES Evolution, SentinelOne, CrowdStrike Falcon, Microsoft Defender for Business). Behavioural detection and automatic isolation of compromised endpoints in seconds.

3. Disciplined monthly patch management

Monthly Windows Update and third-party patches (Chrome, Firefox, Adobe). Maximum 14-day delay on critical patches. Vulnerabilities older than 30 days represent a dominant share of initial accesses.

4. Network segmentation

Distinct VLANs for users, servers, IoT, guests, OT/SCADA. Inter-interface filtering. Prevents lateral movement after an initial compromise.

5. Email filtering with sandbox

Anti-phishing solution with attachment sandboxing (Mailcleaner, Vade, Proofpoint, Microsoft Defender for Office 365 P2). Blocks a large majority of malicious emails before they reach the user.

6. Recurring user awareness

Structured programme combining two annual sessions, monthly phishing simulations and new-joiner onboarding. Phishing click-rate reduction can reach 70-80% over 12 months.

7. Tested immutable backup

See the dedicated 3-2-1-1-0 section below. Immutable, tested backup is the last safety net: if everything else fails, it guarantees recovery without paying a ransom.

The 3-2-1-1-0 immutable backup rule

The historic 3-2-1 rule no longer suffices against modern ransomware which actively targets backups. The new Veeam reference is 3-2-1-1-0:

  • 3 copies of each data set
  • 2 different media types
  • 1 off-site copy
  • 1 offline or immutable copy (air-gap or S3 Object Lock)
  • 0 errors on the last restoration test

Immutable storage (S3 Object Lock, removed LTO tapes, WORM snapshots) guarantees that no action — including administrative — can delete data during the retention window. It is the ultimate safeguard against an attacker who has obtained domain admin rights.

8-step incident response plan

When an incident hits, improvisation is costly. A written response plan, tested annually, divides return-to-normal time by 3 to 5 on average.

  • Detection and qualification — incident confirmation, initial scope.
  • Crisis team activation — CEO, IT director, legal, communications, cyber provider.
  • Containment — network isolation, VPN shutdown, suspicious account disabling.
  • Regulatory notification — CNIL if personal data, ANSSI if NIS2, cyber-insurance.
  • Forensic and eradication — attack-chain analysis, removal of every backdoor.
  • Restore from backup — clean rebuild, restoration ordered by business priority.
  • Return to normal — gradual reopening, reinforced monitoring for 90 days.
  • Lessons learned — update plan, retrain teams.

Should you pay the ransom?

Official ANSSI, FBI and CERT-EU position: no. Three main reasons.

  • Funding the criminal ecosystem and the next victim.
  • No recovery guarantee: according to the Sophos 2024 study, around 28% of SMBs that paid did not recover their full data.
  • Marking the business as a "paying" target — re-attack risk within 18 months for nearly 38% of victims.

Legally in France, payment is not forbidden but the LOPMI law conditions any cyber-insurance reimbursement on a prior police filing and compliance with a 72-hour notification window.

By Nicolas Bourcier · Published on

Read next

Free audit

A question
on this topic?

30 minutes by video call. Clear assessment, quantified recommendations, quote in 48h*. No commitment. (* except complex studies)

Financing up to 63 months available* — *subject to approval

Ransomware for SMBs 2026: the complete protection guide — BISPRO Blog