Home / Blog / Building resilience using a layered approach to combat ransomware
Research · Ransomware

Building resilience using a layered approach to combat ransomware

Rather than asking whether ransomware can be stopped entirely, the more meaningful questions are whether your business has enough protections in place — and how well it sustains itself when ransomware passes through.

March 22, 2026Ransomware5 min read
Building resilience using a layered approach to combat ransomware

What’s the best way to protect against ransomware? If we knew the answer we’d be billionaires living on a sunny beach with a coconut in hand. So let’s talk about resilience instead — resilience to attacks, resilience to ransomware. As with everything in security, you need a multi-layered approach that fits the needs of your business.

Let’s ask the right questions first:

The impact on SMBs

Some figures: 1 in 5 businesses that suffer a major cyberattack are forced to cease operations. It’s not just operations that are affected, but reputation too. The supply chain is under more scrutiny than ever — if you want to be in the chain of an enterprise, you need to show your resilience. Attacks will happen; showing you’ve done your due diligence means you’ve thought about the security of your business and customers. [source: Mastercard’s 2025 Global SMB Study]

According to Verizon’s DBIR, ransomware is present in 88% of breaches in SMBs. Ransomware-as-a-service is ever increasing, and SMBs usually lack the multi-layered approach that large enterprises can afford. Since the cost of launching attacks keeps falling, attackers can afford a wide variety of targets. [source: Verizon’s DBIR]

We were excited to work with QuellSecure from early stages to help validate and improve their approach. A low-cost, hands-off approach is exactly what SMBs should aim for — they usually can’t afford huge teams to deal with attacks. As QuellSecure’s solution is an addition rather than a replacement, it tackles the resilience aspect SMBs typically lack. It focuses on what happens when the usual layers fail: users will inevitably click on something they shouldn’t; credentials will leak. It targets ransomware once it actually starts encrypting your files.

Our testing focused on measuring the impact of ransomware on target organisations, and how a product helps the organisation stay resilient. The approach is simple at heart but complex in practice: get real ransomware against real environments and measure how many files are lost. Our targets held thousands of files — a mix of typical office, editing and development formats.

Rather than asking whether ransomware can be stopped entirely, the more meaningful questions are whether your business has enough protections in place, and how well it sustains itself when ransomware passes through.

Read more about ransomware, our testing and the full results in the QuellSecure report.

All posts Request a test
Transparency Innovation Partnership Full chain, pre-encryption to recovery