Ransomware in 2026: why SMEs are the favourite target
Ransomware — the malware that encrypts a company's data and demands a ransom — keeps growing. Attacks rose about 34% in 2025, and small and medium businesses take the brunt: an estimated 88% of incidents involve SMEs.
Why SMEs?
Attackers see SMEs as easy targets: weaker defences, unpatched systems, no dedicated security team and reliance on third parties for IT. It isn't about being "important" — it's about being vulnerable.
Crime as a service
Many of these attacks no longer require technical skill. The ransomware-as-a-service model lets criminals rent tools, stolen credentials and extortion services, widening the pool of attackers. Larger groups even form alliances to share data and pressure victims.
Five measures that make a difference
- Multi-factor authentication (MFA) on every important login.
- Backups that are secure and tested (see the 3-2-1 rule).
- Team training to recognise phishing, the main entry point.
- Regular updates of systems and applications.
- An incident response plan — knowing what to do before it happens.
No single measure solves everything, but together they cut risk dramatically. If you are not sure where to start, an assessment helps you prioritise.
Sources
Pergunte sobre este artigo
O nosso assistente responde com base neste artigo.
As conversas são registadas para melhorar o serviço. Ao enviar, aceita a Política de Privacidade.