← Back to Insights
Business ContinuityJune 26, 20269 min read

Ransomware and Small Business: Anatomy of an Attack, Hour by Hour

In this article

Follow a realistic ransomware attack on a small business, from the first phishing email to operational shutdown, and learn where the attack can be stopped.

Ransomware and Small Business: Anatomy of an Attack, Hour by Hour

Key Takeaways

  • Ransomware can shut down an SMB within hours by encrypting files, blocking systems, and sometimes threatening to publish stolen data.
  • An attack often begins with a convincing phishing email, then quietly progresses toward administrator accounts, servers, and backups.
  • Employee awareness, multi-factor authentication, timely updates, and disciplined access management can interrupt the attack at different stages.
  • Isolated, regularly tested, genuinely recoverable backups reduce the pressure to pay a ransom.
  • A prepared incident response plan helps the organization act quickly, limit damage, and restore operations more effectively.

Ransomware is malicious software that makes files or systems unavailable. Criminals then demand payment to restore access and may also threaten to publish information they have stolen.

In Canada, reported ransomware activity remains a significant concern. The Canadian Centre for Cyber Security has documented the continuing threat, while Statistics Canada reported that 13% of Canadian businesses affected by a cyber incident in 2023 experienced ransomware.

This article follows a typical attack on a fictitious Quebec SMB, hour by hour, from the first click to a major operational disruption. The objective is to show what may happen, where costs arise, and when the organization can still interrupt the attack.

Important: The timeline below is an educational reconstruction based on common ransomware techniques documented by the Canadian Centre for Cyber Security, Statistics Canada, and CIRA. It is fictitious. A real intrusion may unfold over hours, days, or weeks.

"That Only Happens to Large Companies"

This is one of the most common assumptions encountered during cybersecurity engagements, and it can be expensive.

Ransomware operators often select targets based on opportunity rather than size. The Canadian Centre for Cyber Security describes many ransomware actors targeting Canada as financially motivated and opportunistic. An 80-person business with limited security resources may present an easier target than a heavily defended multinational.

The public image of an attacker "breaking into" a system in seconds is misleading. A real intrusion can be slower, quieter, more ordinary - and more preventable.

The Attack, Hour by Hour

T+0 - The Email

An accounting employee receives an email that appears to come from a known supplier. The subject reads "Overdue Invoice." The message is professional, uses the right logo, and asks the employee to review a document quickly.

The employee opens the attachment. Nothing visible happens: no black screen, no obvious warning, and no disappearing files. She closes the document and continues her day without realizing that the intrusion has begun.

T+30 Minutes - The Foothold

The click has quietly installed a small program. It has not encrypted anything yet, but it creates a foothold that allows an attacker - or an automated tool - to observe the company's environment.

The intruder looks for accessible folders, stored credentials, reachable servers, and opportunities to move further without attracting attention. The employee continues working normally, and the computer appears unchanged.

This is one point at which a well-prepared organization may detect unusual behaviour and interrupt the intrusion.

T+4 Hours - Lateral Movement

The attacker now seeks greater privileges, particularly access to an administrator account that would allow movement across the network, system changes, and access to critical data.

A reused password, an account without MFA, or an old account that was never disabled may open the way. With the required privileges, the attacker maps the network and looks for customer files, accounting records, billing tools, and backups.

Backups become a priority target because a company that can restore its systems has less reason to pay.

T+12 Hours - Attacking the Backups

Before triggering encryption, the attacker tries to delete, alter, or disable the organization's backups - especially when those backups are continuously connected to the network and accessible through the same administrative accounts as production systems.

Leadership may believe the company is protected because backups run every day, without knowing whether they are isolated, recently tested, or actually recoverable when needed.

T+24 Hours - Encryption Begins

The next morning, employees begin reporting problems. Files no longer open, the accounting system is unavailable, and people initially assume it is an ordinary server outage.

Then a ransom note appears. It states that the data has been encrypted, payment is required, and the company has only a few days to respond.

In many cases, a second threat accompanies the encryption: the attacker claims to have copied company data and threatens to publish it. This double-extortion tactic creates two simultaneous risks - operational shutdown and the potential disclosure of confidential information.

T+48 Hours and Beyond - The Business Is Paralyzed

Two days earlier, everything began with one email. Now billing has stopped, customer files are inaccessible, some processes have shifted to manual work, and leadership must answer questions it never prepared for.

Who should be called? Do the backups work? Will the insurer respond? Was personal information stolen? Does the Commission d'accès à l'information need to be notified?

This is no longer only an IT problem. It is an operational, financial, legal, and reputational crisis whose effects may continue long after systems return to service.

The difference between a company that resumes operations quickly and one that struggles for months is usually determined before the ransom note appears - through access protection, system monitoring, backup quality, and a tested response plan.

The attack may begin with a click. The ability to stop it is built long before that moment.

The Scenario at a Glance

  • T+0 - Phishing. Business risk: initial compromise. Defensive measure: awareness and email filtering.
  • T+30 min - Establishes a foothold. Business risk: undetected presence. Defensive measure: endpoint detection, logging, and alerts.
  • T+4 h - Moves laterally. Business risk: administrator account compromise. Defensive measure: MFA and least-privilege access.
  • T+12 h - Targets backups. Business risk: loss of recovery capability. Defensive measure: isolated and tested backups.
  • T+24 h - Encrypts systems. Business risk: operational shutdown. Defensive measure: response plan and restoration procedures.
  • T+48 h - Extortion. Business risk: legal and reputational crisis. Defensive measure: insurance, regulatory assessment, and communications.

What Ransomware Really Costs

The main cost of ransomware is not necessarily the ransom. It is the disruption and recovery.

According to Statistics Canada, 88% of Canadian businesses affected by ransomware in 2023 did not pay. The same source reported that total recovery expenditures following cybersecurity incidents doubled between 2021 and 2023, from approximately $600 million to $1.2 billion across Canada.

For one business, the total may include:

  • lost production and revenue during downtime;
  • emergency specialists, whose services cost more than planned prevention;
  • system rebuilding and verification that the attacker is no longer present;
  • legal and notification obligations when personal information is affected; and
  • customer attrition following a data disclosure.

The Law 25 Obligation Many SMBs Overlook

In Quebec, ransomware affecting personal information can constitute a privacy incident under Law 25. If the incident presents a risk of serious injury, the organization must assess that risk and, where required, notify the Commission d'accès à l'information and the individuals concerned.

Failing to consider this obligation adds regulatory risk to an existing crisis. See our article on Quebec Law 25 for SMBs for a more detailed explanation.

Cyber insurers may also examine whether the safeguards declared in an application were genuinely in place. See What Cyber Insurers Review Before Offering Coverage for details.

Where Can the Attack Be Stopped?

The good news is that every step in this scenario is also an opportunity to interrupt the attack. An SMB does not need perfection everywhere. It needs enough effective layers to stop being an easy target.

At T+0: Employee Awareness

An employee who recognizes phishing is less likely to open a fraudulent attachment or link, especially when training uses realistic examples rather than a purely theoretical annual reminder.

At T+30 Minutes: Strong Authentication and Detection

MFA can substantially reduce the usefulness of a stolen password, although some techniques can bypass weaker forms of MFA. Endpoint detection, useful logging, and actionable alerts may also reveal unusual behaviour.

At T+4 Hours: Updates and Access Management

Attackers often exploit known vulnerabilities or overly permissive accounts. Timely security updates, least privilege, and vulnerability management reduce these opportunities.

At T+12 Hours: Isolated, Tested Backups

Protected backups can change the outcome of an incident. They support restoration without relying on the attacker, provided the organization has tested that the required data and systems can actually be recovered.

At T+48 Hours: A Prepared Response Plan

A response plan reduces improvisation. Knowing whom to call, in which order, and with what authority helps turn a chaotic event into a coordinated process.

These measures are achievable for an SMB. The most common gap is not always budget; it is the absence of a clear view of what should be addressed first.

See Where You Stand

This scenario is a chain of events, and every link is a place where the attack can be interrupted.

The practical question is not simply, "Could this happen to us?" It is, "At which stages are we already protected, and where is the next gap?"

If you do not know whether your backups, administrator access, or MFA would withstand this scenario, schedule a 20-minute introductory call. We can identify the likely points of failure and clarify where to begin.

Frequently Asked Questions

How can an SMB protect itself against ransomware?

Use several complementary layers rather than relying on one product: phishing awareness, appropriate MFA, timely updates, least-privilege access, endpoint protection, and protected, tested backups. A vulnerability assessment can identify known technical exposure, while a broader audit examines processes, governance, and preparedness.

What should we do after a ransomware attack?

Activate the incident response process and coordinate containment with qualified responders. Avoid rushed changes that may destroy evidence or worsen the incident. If personal information may be involved, assess the privacy obligations. If the organization has cyber insurance, contact the insurer according to the policy before incurring costs that require prior approval.

Should we pay the ransom?

Payment does not guarantee recovery or prevent disclosure. The decision carries operational, legal, insurance, and public-policy implications and should not be made without incident-response, legal, insurance, and law-enforcement input.

How much does a ransomware attack cost in Canada?

There is no standard cost for one SMB. Costs depend on the duration of the interruption, the systems and data affected, response and rebuilding work, legal obligations, and customer impact. Statistics Canada reported $1.2 billion in total recovery expenditures following cybersecurity incidents across Canadian businesses in 2023.

Is a Quebec SMB genuinely a target?

Yes. Opportunistic attackers look for accessible organizations, not only large ones. CIRA's 2025 survey reported that 24% of participating Canadian organizations said they had been targeted by ransomware in the previous 12 months. This is survey data from participating decision-makers, not a national incidence rate.

Sources

  • Statistics Canada, Impact of cybercrime on Canadian businesses, 2023, Canadian Survey of Cyber Security and Cybercrime, October 21, 2024.
  • Canadian Centre for Cyber Security, Ransomware threat outlook 2025 to 2027.
  • Canadian Centre for Cyber Security, National Cyber Threat Assessment 2025-2026.
  • CIRA, 2025 Cybersecurity Survey. Treat this as respondent survey data rather than an official national incidence statistic.
Topics
SMB ransomwareQuebec ransomwareSMB cyberattackransomware backupsincident responseLaw 25 privacy incident
RD
About the Author
Rémi Douville
President · RDCybersécurité Inc.

More than 12 years of cybersecurity experience.

PMP · Master’s degree in Computer Engineering, specializing in cybersecurity management

Want to know where you stand?

Schedule a 20-minute introductory call. We will review your situation and clarify the most useful next step.

Schedule a Call →