Dark empty office at dusk with fog on the floor

The scariest cybersecurity story isn’t about a ghost in the server room.

It’s about a real business that can’t access its files, process payroll, serve customers, or make it through another month.

Just because you’re not big enough to make national news doesn’t mean you’re too small to be attacked. Criminals don’t need to know your company’s name. They need to find a way in, and a way to make money.

Verizon’s 2025 Data Breach Investigations Report analyzed 3,049 incidents involving small businesses. In that report’s breach data, ransomware was present in 88% of small-business breaches.[2] That doesn’t mean 88% of small businesses will be attacked; it does mean ransomware is a serious part of the threat picture for small organizations.

The cases below show how an attack can turn into a business crisis. One is a publicly reported example of a company that shut down. The other two are illustrative composite scenarios based on common attack methods, not accounts of specific, unnamed local businesses.

1. Ransomware locks up a real company, and operations stop

In 2025, the BBC reported on KNP, a 158-year-old transport company in the United Kingdom. According to the report, ransomware attackers encrypted company data and left staff unable to access systems needed to run the business. KNP ultimately went under, and about 700 people lost their jobs.

The BBC reported that investigators believed an employee’s password may have been guessed to gain access. That detail is a warning, not a reason to point fingers: a single weak or exposed password can become an entry point into a much larger business.

When core systems become unavailable, routine work can grind to a halt. Dispatchers may be unable to plan routes. Staff may lose access to customer records, invoices, and schedules. Even if employees can still make calls or send messages, they may not have the information needed to do their jobs.

For a business that depends on its systems to deliver services and get paid, every hour of disruption can mean lost revenue, frustrated customers, and mounting recovery costs.

Server room aisle lined with racks of blinking network lights

A ransom note may demand payment, but paying is no guarantee that systems will be restored or stolen information kept private. The chilling reality is that an attack can leave a company with difficult choices and no simple path back to normal.

Read the BBC’s report on KNP.[1]

2. A convincing email drains a business account

Now picture a South Sound business preparing to pay a regular supplier. An email arrives with an updated invoice and new bank details. The message looks familiar. The timing makes sense. The payment goes out.

Only later does the real supplier call to ask why the invoice is still unpaid.

This is an illustrative composite of a business email compromise (BEC) scam. In these schemes, criminals may impersonate a supplier or business leader, or take over a legitimate email account, to trick someone into sending money to an account controlled by the attacker. No encrypted computers are required. A single authorized transfer can cause devastating financial loss.

The FBI’s 2024 Internet Crime Report recorded 21,442 BEC complaints and more than $2.77 billion in reported losses.[3] Those are nationwide complaint figures, not a measure of risk for any individual business, and losses may be underreported. Still, they show why a familiar-looking email should never be the only proof behind a major payment.

Woman on the phone at a desk reviewing a security dashboard

A missing payment can affect cash flow immediately. Reversing a fraudulent transfer may be difficult, and the business still owes its real supplier. Staff may spend days contacting banks, investigating email accounts, and explaining the disruption to customers or vendors.

If personal or regulated information was exposed, the incident may also raise compliance and notification obligations. Those requirements vary by the information involved and applicable laws, so businesses should get appropriate legal advice.

Make payment changes a two-channel conversation: call a known, independently verified phone number before changing bank details or sending a large transfer. Don’t use the phone number in the unexpected email.

3. An unpatched server becomes a doorway, and the backup is no good

Here’s another illustrative composite. A small company’s server is overdue for security updates. The update keeps getting postponed because “everything seems to be working.”

An attacker finds a weakness in an internet-facing system and gets inside. Files and business applications become unavailable. The company turns to its backup, only to discover that the latest copy is incomplete, inaccessible, or hasn’t been tested for restoration.

This is how a technical issue becomes an operations crisis. A backup that has never been tested is a hope, not a recovery plan. And a backup connected to the same network may be vulnerable to the very incident it is meant to help recover from.

Verizon’s 2025 report found that exploiting vulnerabilities was an initial access route in 20% of breaches it reviewed.[2] CISA warns that recovery without backups can take weeks or months, and may not be possible.[4] Neither figure predicts what will happen to your business. Both make clear why timely patching and reliable recovery plans matter.

Technician at a laptop beside a server rack and backup drives

When recovery stalls, the losses go beyond the repair bill:

  • Downtime and lost revenue: Work slows or stops while systems are restored.
  • Reputational damage: Customers may lose confidence if orders, appointments, or commitments are missed.
  • Compliance complications: A data incident can require investigation and may trigger legal or regulatory obligations.
  • Staff and owner strain: Your team gets pulled away from serving customers and running the business.
  • A threat to survival: For a company without cash reserves or a workable recovery plan, prolonged disruption can become a business-ending event.

How to keep your business out of the ghost story

There is no single tool that can promise you’ll never face an attack. But practical, consistent safeguards can reduce common risks and help you recover faster.

  • Manage systems proactively. Keep software, servers, and internet-facing equipment updated. Know what you have, who manages it, and what still needs attention.
  • Use multifactor authentication (MFA). Require an additional verification step for email, remote access, and administrator accounts. MFA makes a stolen password harder to use on its own.
  • Protect and test backups. Keep separate copies of important data, including an offline or otherwise protected copy. Test whether you can actually restore the files and systems your business needs. CISA outlines practical steps in its guide to backing up business data.[4]
  • Train employees on real-world scams. Teach staff to pause and verify unexpected requests involving money, passwords, or sensitive information. Make reporting a suspicious message easy and blame-free.
  • Plan for an outage. Decide who to contact, how to reach your IT support provider, and how you’ll handle essential work if your normal systems are unavailable.

Your protections should fit your systems, budget, and business needs. Proactive managed IT services and a data backup and recovery plan can help you identify problems before they become emergencies and understand what recovery would actually involve.

Knightwolf Cybersecurity & IT Services is locally owned and veteran-owned, serving Olympia, Tacoma, and the South Sound. We explain technology in plain English, provide 24/7/365 network management, and back our work with a 100% no-small-print satisfaction guarantee.

Don’t wait until the lights flicker and your files disappear. Request your FREE Network & Backup Risk Assessment to get a clearer picture of your risks, backup readiness, and next steps.

Sources / References

  1. BBC News. KNP cyber-attack puts 700 jobs at risk after firm collapses. 2025. https://www.bbc.com/news/articles/cx2gx28815wo
  2. Verizon Business. 2025 Data Breach Investigations Report (DBIR). 2025. https://www.verizon.com/business/resources/reports/dbir/
  3. Federal Bureau of Investigation Internet Crime Complaint Center (IC3). 2024 Internet Crime Report. 2025. https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
  4. Cybersecurity and Infrastructure Security Agency (CISA). Back Up Business Data. 2026. https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/back-up-business-data