🇯🇵 日本語 🇬🇧 English 🇨🇳 中文 🇲🇾 Bahasa Melayu

Over 60% of Ransomware Victims Are SMEs: Realistic Strategies for Companies Without Dedicated IT Staff

Over 60% of SMEs Targeted: The Ransomware Threat Is No Longer Someone Else’s Problem

The assumption that “our company is too small to be targeted” no longer holds true.

According to ITmedia reports, over 60% of ransomware victims are small and medium-sized enterprises (SMEs). This is because most SMEs lack the security budgets of larger corporations and often don’t even have a dedicated IT department.

However, this doesn’t mean you’re powerless. In fact, the most effective defense is for business owners to stop leaving IT solely to “the experts” and instead take charge of setting security priorities themselves.

This article outlines smart, practical ransomware countermeasures for understaffed SMEs, complete with specific tools you can use.

Why Are SMEs Targeted? Exploiting the “Human Resource Gap”

From a ransomware attacker’s perspective, SMEs are ideal targets.

Attackers look for organizations with weak security measures. They avoid companies with 24/7 security monitoring or dedicated IT teams, as their attacks are more likely to be detected and blocked quickly.

In contrast, most SMEs have IT staff who also handle general affairs or accounting. Applying patches and checking backups often get pushed aside, and attackers exploit this “human resource gap” to break in.

This situation is a direct result of management failing to define IT’s role. The price of treating security as “the expert’s job” and leaving management uninvolved is now being paid in full.

The Real Issue Isn’t “Lack of Budget” but “Lack of Prioritization”

We often hear, “We don’t have a security budget.” But the real problem isn’t the budget itself; it’s that management hasn’t properly assessed IT risks and set priorities.

Management needs to make decisions on these three points:

1. Which data is irrecoverable?
2. How many days of business downtime can we tolerate?
3. How much are we willing to invest to mitigate that risk?

Without deciding these three things, vaguely thinking “we need security measures” will never secure a budget.

For example, if all customer data and contracts with business partners were lost, business continuity would be impossible. Evaluating that risk and deciding whether to invest a few tens of thousands of yen (a few hundred USD) annually in cloud backup is a true management decision.

Three Smart Countermeasures for Understaffed IT Teams

So, what should you actually do? Here are three measures you can start with, even on a zero budget.

Measure 1: Mandate Multi-Factor Authentication (MFA)

The most cost-effective measure is implementing MFA. Microsoft 365 and Google Workspace come with built-in MFA features at virtually no extra cost.

Many ransomware attacks begin with leaked IDs and passwords. By enforcing MFA, even if a password is compromised, you can prevent unauthorized logins.

The key to implementation is for management to lead by example, setting up MFA for themselves first and then rolling it out company-wide. If management refuses MFA because it’s “too much trouble,” it lowers the entire organization’s security awareness.

Measure 2: Follow the 3-2-1 Backup Rule

It’s not about “having” a backup, but being able to “restore” it. When infected with ransomware, connected drives and NAS devices are also encrypted.

That’s why we recommend the 3-2-1 rule:

・Keep 3 copies of your data (including the original)
・Store them on 2 different types of media
・Keep 1 copy offsite or in the cloud

A practical setup would look like this:

・Daily backup to an on-site NAS
・Weekly backup to cloud storage (like Backblaze or Wasabi)
・Manually copy critical data to an external HDD and store it offline

These services are available for a few thousand yen (tens of USD) per month. They’re easy to automate, so your IT person doesn’t need to check them every night.

Measure 3: Enforce the Principle of Least Privilege

In many SMEs, all employees have administrator privileges. This means that during a ransomware attack, all data can be encrypted instantly.

The principle of least privilege means giving users only the minimum access needed for their job. For example, general staff might only have read access to files, while write and delete permissions are restricted to administrators.

This setting can be changed in minutes from the Microsoft 365 admin console. Once implemented, even if an infection occurs, the damage can be limited to specific folders.

Turning “No IT Staff” into an Advantage: Leveraging External Services

SMEs without dedicated IT staff can actually benefit greatly from external services.

Recently, many MSSPs (Managed Security Service Providers) offer security monitoring for a few thousand yen per month. Examples include:

・”GMO Cybersecurity by Ierae” (from approx. 50,000 yen / ~$350 per month)
・”Security Copilot” (included with Microsoft 365 E5)

Affordable EDR (Endpoint Detection and Response) tools for SMEs are also emerging. For instance, “SentinelOne” and “CrowdStrike Falcon” can be implemented for a few hundred yen (a few USD) per endpoint per month.

The key when using these services is for management to clearly define “what needs to be protected” before signing a contract. Vaguely asking for “security measures” can lead to expensive contracts.

Summary: Management Defining IT Is the Ultimate Defense

The essence of ransomware defense isn’t piling up technical measures. It’s about management properly assessing IT risks, setting priorities, and making necessary investments.

With over 60% of ransomware victims being SMEs, management’s continued attitude of “leaving IT to the experts” is nothing less than ignoring the risk to the company’s survival.

Start with the three measures introduced in this article: implementing MFA, following the 3-2-1 backup rule, and enforcing the principle of least privilege. These are all things you can start doing today, even with zero budget.

Redefining IT as a “management resource” is the only way to protect your company from ransomware.

Comments

Copied title and URL