Ransomware isn’t just a problem for large corporations. In fact, small businesses are among the most common targets because they often have valuable data but fewer security resources. Understanding how a ransomware attack unfolds can help you identify weaknesses before cybercriminals do.
Many business owners assume hackers only target large organisations.
The reality is quite different.
Small businesses are often seen as the ideal target—they have valuable customer data, financial information and operational systems, but usually lack a dedicated cybersecurity team.
The good news is that most ransomware attacks follow a familiar pattern. Understanding that pattern makes it much easier to break the attack chain before any damage is done.
Step 1: Choosing the Target
Modern ransomware attacks rarely begin with sophisticated hacking.
Instead, attackers gather publicly available information about your business.
They’ll research:
- Your company website
- LinkedIn profiles
- Social media
- Public business records
- Supplier information
From just a few searches they can often identify:
- Who manages payments
- Who has access to Microsoft 365
- Who is likely to approve invoices
- Who is most likely to click an email while juggling a busy workload
The more information available publicly, the easier it becomes to build a convincing phishing attack.
Step 2: Finding a Way In
Once a target has been identified, attackers look for an easy entry point.
That could be:
- A reused password exposed in a previous data breach
- Credentials stolen by malware on a personal device
- A convincing phishing email
- Social engineering over the phone
Even if your business uses Multi-Factor Authentication (MFA), attackers increasingly use Adversary-in-the-Middle (AiTM) phishing attacks to steal active login sessions rather than passwords.
Instead of breaking MFA, they simply wait until the user successfully signs in and then hijack the authenticated session.
Step 3: Staying Hidden
Once inside, attackers don’t usually launch ransomware immediately.
Instead, they spend time learning about your business.
They may:
- Read emails
- Review financial information
- Identify backup systems
- Find customer databases
- Discover cyber insurance details
- Learn who has the authority to approve payments
The longer they remain unnoticed, the more damage they can potentially cause.
Step 4: Deploying the Ransomware
Only after gathering enough information will the attacker launch the ransomware.
Typically this happens outside normal business hours or just before weekends, when staff are less likely to notice suspicious activity quickly.
Files become encrypted, systems stop working and every minute of downtime increases pressure on the business to pay the ransom.
By this point, recovery becomes significantly more difficult and far more expensive.
Five Ways to Break the Attack Chain
The encouraging news is that most ransomware attacks can be stopped long before encryption begins.
Here are five areas every business should review.
1. Use Strong, Unique Passwords
Reused passwords remain one of the easiest ways for attackers to gain access.
Using a password manager and enforcing unique passwords across every account dramatically reduces this risk.
Checking company email addresses against known breach databases can also help identify compromised credentials before attackers exploit them.
2. Upgrade Beyond Standard MFA
MFA is essential—but it isn’t the finish line.
Phishing-resistant authentication methods such as passkeys, FIDO2 security keys, or Windows Hello for Business provide much stronger protection against modern phishing attacks.
These methods make it significantly harder for attackers to hijack login sessions.
3. Block External Email Forwarding
Attackers often create hidden email forwarding rules so they can monitor communications without anyone noticing.
Blocking external forwarding at the Microsoft 365 tenant level helps prevent this tactic and limits the information attackers can quietly collect.
4. Monitor Security Alerts
Many businesses already pay for security tools that generate alerts when suspicious activity occurs.
The problem is that nobody is reviewing them.
Alerts for unusual logins, new inbox rules or suspicious account activity should always be monitored and investigated promptly.
Early detection can stop an attack before ransomware is ever deployed.
5. Reduce Public Information
You can’t remove your business from public records, but you can be mindful about the information your team shares online.
Avoid publishing unnecessary details about:
- Financial responsibilities
- Internal systems
- Suppliers
- Approval processes
Small pieces of information can help attackers build highly convincing phishing campaigns.
Three Questions to Ask Your IT Provider
If you’re unsure how well protected your business is, start by asking your IT provider these three questions:
- Are we using phishing-resistant authentication for key staff?
- Is external email forwarding blocked across our Microsoft 365 environment?
- Who reviews our security alerts, and how quickly are suspicious events investigated?
If they can’t answer confidently, it’s worth reviewing your current security posture.
Prevention Is Far Cheaper Than Recovery
Ransomware attacks don’t usually rely on advanced hacking techniques.
More often, they exploit weak passwords, outdated security settings, phishing emails and unnoticed suspicious activity.
The good news is that many of the protections needed to stop these attacks are already included in Microsoft 365 Business Premium and other business security solutions.
The challenge isn’t buying more technology—it’s making sure the tools you already have are configured properly.
Concerned about your ransomware risk? Novo IT Ltd can review your Microsoft 365 security, identify potential weaknesses and help put the right protections in place before attackers find them. Find out more!
Article used with permission from The Technology Press.

Comments are closed