What’s the best way to protect against ransomware? If we knew the answer we’d be billionaires living on a sunny beach with a coconut in hand. So let’s talk about resilience instead — resilience to attacks, resilience to ransomware. As with everything in security, you need a multi-layered approach that fits the needs of your business.
Let’s ask the right questions first:
- Are you focusing on detecting? What are you hunting for in your IOCs?
- From a technological and human perspective, can you deal with the threat after you detect it?
- If you focus on preventing it, are you blindly trusting that everything is up to date with the latest evasion techniques?
- Backups seem great — but how about the reputational damage that may occur?
The impact on SMBs
Some figures: 1 in 5 businesses that suffer a major cyberattack are forced to cease operations. It’s not just operations that are affected, but reputation too. The supply chain is under more scrutiny than ever — if you want to be in the chain of an enterprise, you need to show your resilience. Attacks will happen; showing you’ve done your due diligence means you’ve thought about the security of your business and customers. [source: Mastercard’s 2025 Global SMB Study]
According to Verizon’s DBIR, ransomware is present in 88% of breaches in SMBs. Ransomware-as-a-service is ever increasing, and SMBs usually lack the multi-layered approach that large enterprises can afford. Since the cost of launching attacks keeps falling, attackers can afford a wide variety of targets. [source: Verizon’s DBIR]
We were excited to work with QuellSecure from early stages to help validate and improve their approach. A low-cost, hands-off approach is exactly what SMBs should aim for — they usually can’t afford huge teams to deal with attacks. As QuellSecure’s solution is an addition rather than a replacement, it tackles the resilience aspect SMBs typically lack. It focuses on what happens when the usual layers fail: users will inevitably click on something they shouldn’t; credentials will leak. It targets ransomware once it actually starts encrypting your files.
Our testing focused on measuring the impact of ransomware on target organisations, and how a product helps the organisation stay resilient. The approach is simple at heart but complex in practice: get real ransomware against real environments and measure how many files are lost. Our targets held thousands of files — a mix of typical office, editing and development formats.
Rather than asking whether ransomware can be stopped entirely, the more meaningful questions are whether your business has enough protections in place, and how well it sustains itself when ransomware passes through.
Read more about ransomware, our testing and the full results in the QuellSecure report.
