forumNew topic

What exactly is ransomware, and is a 5-person small business really at risk?

ÜÜmit K***Member
Job title
Operations manager
Sector
Jewelry
Organization type
a company within a holding
Joined
May 2022
Message
406
#1

My wife and I run a 5-person medical supplies distribution company in Bordeaux. Last week at a seminar hosted by the local chamber of commerce, people kept talking about the threat of ransomware and how vulnerable French TPEs (small businesses) are. One attendee mentioned that a logistics firm in the next town over had all their accounting and inventory records locked up, with attackers demanding a 30.000 EUR ransom.

Honestly, until now, whenever we heard "virus," we just thought of simple programs that slow your computer down. We don't have massive turnover or proprietary tech; just our invoices, client lists, and order history. Other than basic office software and a standard antivirus, we don't have any security measures on our PCs.

What exactly is ransomware and how does it work? Would a small business like ours actually be targeted by cybercriminals, or is this strictly a problem for big conglomerates? What are the top three basic steps we could take starting tomorrow to protect ourselves?

İİlker B***MemberCommunity member
Joined
Jan 2024
Message
400
Most Helpful#2

Short answer: Ransomware is malicious software that, once inside your system locks all your files, databases, and network-accessible backups using unbreakable encryption, then demands cryptocurrency to unlock them. Cybercriminals don't look at revenue when picking targets; they look for security vulnerabilities. That makes small businesses an easy target, putting them directly in the crosshairs.

While massive conglomerates usually face tailored, targeted attacks, small businesses get swept up by automated bots scanning the internet. Attackers sneak in through an open, unsecured port or via a fake invoice email (phishing) sent to your staff. Once files are locked down, you can't issue invoices, track inventory, or fulfill client orders.

Here are the three key steps you should implement right away:

1) Switch to the 3-2-1 backup rule: keep at least 3 copies of your data across 2 different media types, with 1 copy strictly disconnected from the main network (like an external drive plugged in once a week and then unplugged). Attackers will encrypt network-attached cloud folders and local backups too; an offline copy is your only real safety net. 2) Enforce two-factor authentication (2FA) across email and business apps without exception. 3) Train all employees never to open email attachments (especially fake delivery notices or suspicious invoice files) without verifying them first.

These three steps alone will stop the vast majority of ransomware attacks targeting small businesses right at the door.

ZZerrin C***Member
Job title
Supply chain manager
Sector
Healthcare services
Organization type
workshop
Joined
Jan 2024
Message
10
#3

We went through this two years ago at our 7-person wholesale food office in Toulouse. An employee opened a fake shipping tracking attachment sent to accounting, and within half an hour our entire server was encrypted. They demanded a 15.000 EUR ransom; we didn't pay, but since our network-connected backups were wiped out too, we had to re-enter 3 years of records from scratch.

CCerenMember
Job title
QA Tester
Joined
Mar 2024
Message
178
#4

Don't ever fall into the trap of thinking "I'll just pay the ransom and get my files back." Authorities and law enforcement in France strongly advise against paying. There are plenty of criminal gangs that take the money and never send the decryption key or send an incomplete one that leaves your system completely trashed.

UUğur Ö***Member
Job title
Sales Manager
Sector
IT services
Organization type
regional distributor
Joined
Jan 2024
Message
5

Doki · Brand identity · 2026

#5

Set aside a 100-150 EUR budget tomorrow and buy two external portable hard drives. Copy your accounting and customer database to one, unplug the cable as soon as it's done and lock it in the safe. No ransomware can encrypt a drive that isn't plugged into a computer.

DDamla Y***MemberCommunity member
Joined
Sep 2022
Message
131
#6

They don't just lock files anymore; they use double extortion. They copy your files to their own servers before encrypting them. If you don't pay up, they threaten to leak your medical client records online and report you so you get hit with data protection fines.

SSenaMember
Job title
Graphic Designer
Organization type
two-branch business
Joined
Jul 2024
Message
86
#7

thinking "we're a small business nobody cares about us" is super dangerous. attackers dont hand-pick companies automated scripts just hit every open ip address they find. if u get caught unprotected, company size doesnt matter.

SSerkan Z***Member
Job title
Regional Manager
Sector
Security services
Organization type
8-person team
Joined
Aug 2023
Message
231
#8

As a business operating in France, if customer data is stolen, you may be legally required to report the breach to regulatory authorities and affected data subjects. Because of this, offline backups and system security are just as much a legal requirement as an operational one.

MMehmet Y***Member
Job title
IT manager
Sector
Packaging
Organization type
40-person manufacturing company
Joined
Oct 2024
Message
4
#9

Does your standard antivirus only scan for known legacy signatures, or does it feature modern endpoint protection capabilities that heuristically block abnormal encryption activity in real time? Have you had your IT provider check what your license actually covers?

OOnatMember
Job title
Tour Operator
Organization type
medium-sized business
Joined
Mar 2024
Message
112
#10

I'm curious too.

TTaner E***Member
Job title
Purchasing manager
Sector
Leather
Organization type
early-stage startup
Joined
Jun 2023
Message
132
#11

I agree with this. When making decisions write down the worst-case scenario too not just the best.

If you have questions write them; I'll answer as best I can.

EEmre K***Member
Job title
Courier coordinator
Sector
Law
Organization type
cooperative
Joined
Feb 2025
Message
1
#12

Following.

MMeryem A***Expert
Job title
Store Manager
Sector
Media and publishing
Organization type
boutique agency
Joined
Dec 2025
Message
99

Doki · Brand identity · 2026

#13

Following. Processes without records never improve, because you don't know what to fix.

If I were you, I'd go this route.

NNuri Ç***Veteran
Job title
Site Manager
Sector
Software
Organization type
cooperative
Joined
Jan 2026
Message
20
#14

There's a trap here, let me mention it. Security isn't absolute; it's about making attacks not worth the effort.

Taking measures without an inventory leaves doors you haven't seen open. Good luck with that.

DDilara Ş***Member
Job title
Warehouse Manager
Sector
Seafood
Organization type
sole proprietorship
Joined
Dec 2022
Message
151
#15

I agree, and I'd like to emphasize that. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

If you have questions, write them; I'll answer as best I can.

SSelin K***Member
Job title
Human Resources Specialist
Sector
E-commerce
Organization type
workshop
Joined
Sep 2024
Message
42
#16

We experienced almost the exact same thing last year. Everything goes well for the first three months; problems arise in the fourth.

When making decisions, write down the worst-case scenario too, not just the best. Hope this helps.

İİremNew member
Job title
Intern · marketing
Joined
Jan 2025
Message
30
#17

i'm a small business, let me expllain from my side and when we decide without measuring we always end up in the same place.

if you have questions, write them; Ill answer as best I can.

OOrhan Z***MemberCommunity member
Joined
May 2023
Message
254
#18

I went through the same thing two years ago. Trying to do this alone is the most expensive way.

If you post the result here, it will help others too.

TTaner O***ExpertCommunity member
Joined
Sep 2022
Message
105
#19

This thread is archived.

PPerihan K***MemberCommunity member
Joined
Jan 2023
Message
152
#20

Let me summarize what's been said so far. If you scold false alarms, nobody will report again.

Proven by experience.

Reply