← Back to BlogManaged IT

How Much Does a Ransomware Attack Cost a Small Business?

AOP IncAugust 2, 2026
ransomwarecybersecuritysmall businessmanaged ITdata breachcyber insuranceincident responsebackupsLake CharlesSouthwest Louisiana

$115K

Median Ransom Paid (Verizon 2025 DBIR)

88%

Of Small-Business Breaches Involve Ransomware (Verizon 2025 DBIR)

$1.53M

Avg. Recovery Cost, Ransom Excluded (Sophos 2025)

A ransomware attack costs the median victim $115,000 in ransom alone, according to Verizon's 2025 Data Breach Investigations Report — and the ransom is usually the smaller line item. Sophos' State of Ransomware 2025 found the average cost to recover from an attack, excluding any ransom payment, was $1.53 million across all company sizes. For a small business, the realistic total depends on how long you're down and whether data was stolen, but the bill always has the same four parts: downtime, recovery, the ransom decision, and notification and legal costs.

The headline numbers understate the small-business reality, not overstate it. The FBI's Internet Crime Complaint Center logged $16.6 billion in total reported cybercrime losses in its 2024 annual report, with ransomware complaints up 9% year over year — and the report is explicit that its ransomware loss figures exclude lost business, time, wages, files, and equipment. Those uncounted categories are exactly where a 20-person company bleeds.

Below, we break the bill into its four components, then translate the research numbers into what they'd actually mean for a Lake Charles-sized firm.


Why Small Businesses Take the Harder Hit

It's tempting to assume ransomware crews only chase hospitals and Fortune 500 logos. The data says the opposite. Verizon's 2025 DBIR found ransomware present in 88% of breaches at small and mid-sized businesses, versus 39% at large organizations. Attackers automate their targeting, and small companies are the path of least resistance: no dedicated security staff, remote access that hasn't been hardened, backups that have never been test-restored, and one shared password away from the accounting system.

The asymmetry is what makes it dangerous. A large enterprise can absorb a bad week; a small firm runs on this month's receivables. That profile fits a lot of Southwest Louisiana — contractors, medical and dental clinics, law offices, distributors, and plant-services companies around Lake Charles running lean, often with no in-house IT at all. If you want the prevention side first, start with our small business cybersecurity checklist; the rest of this post is about the invoice you get when those controls aren't there.

Where the Money Goes: The Four Costs

Every ransomware bill decomposes into the same four buckets. Here's what each one covers and what the current research says about it:

Cost Component What It Includes What the Data Shows
Downtime & lost business Idle payroll, missed revenue, blown deadlines, customers who quietly move on Only 53% of victims fully recovered within a week (Sophos 2025) — nearly half were still rebuilding after week one
Recovery & remediation Forensic investigation, rebuilding servers and workstations, restoring data, hardening what was breached $1.53M average excluding ransom (Sophos 2025) — a mean pulled up by large enterprises, but the work categories are identical for a 20-person shop
The ransom decision Negotiation, payment, and the risk that the decryptor is slow, partial, or never comes Median payment $115,000; 64% of victims refused to pay (Verizon 2025 DBIR). Those who did pay averaged 85% of the initial demand (Sophos 2025)
Notification & legal Breach attorneys, mailed notification letters, credit monitoring, regulator exposure (HIPAA for clinics) Louisiana law (La. R.S. 51:3074) requires notifying affected residents within 60 days of discovering a breach, plus written notice to the Attorney General's Consumer Protection Section

There's a fifth cost that never shows up on the incident invoice: what happens afterward. Cyber insurance premiums typically get reassessed after a claim, customers and vendors ask harder questions, and any contract that required you to safeguard their data is now a conversation. None of that is a line item, and all of it is real money.

The 20-Person Lake Charles Firm: A Worked Example

National averages are abstract, so let's make it concrete. The figures below are an illustration with stated assumptions — not survey data — so you can swap in your own numbers.

1

Idle payroll: ~$24,000 per week

Assume 20 employees at an average fully loaded cost of $30/hour. One week of systems being down is 20 × $30 × 40 hours of payroll producing nothing.

2

Revenue at risk: ~$48,000 per week

Assume $2.5 million in annual revenue. Divided across 52 weeks, every week of near-zero output puts roughly $48,000 on the line — and remember, per Sophos, nearly half of victims aren't fully back inside a week.

3

Recovery labor: billed in days, not hours

Even a small-scale rebuild — forensics, reimaging a dozen workstations, restoring a server, closing the hole that let the attacker in — is specialist work measured in days.

4

Notification & legal: per-person costs multiply fast

If client or patient records were taken, Louisiana's 60-day notification clock starts at discovery — legal review, mailed letters, and credit monitoring are priced per affected person.

Add it up: in this illustration, the first week is already roughly $72,000 in payroll and revenue exposure before a single recovery invoice or legal bill arrives — and Verizon's median ransom payment of $115,000 sits on top of all of it if you choose to pay. A ransomware attack doesn't need to look like the national headlines to be the worst financial event in a small company's history.

Southwest Louisiana businesses already understand downtime better than most — we plan for it every hurricane season. Ransomware is the same business-continuity math with no forecast track and no five-day cone. The disciplines overlap almost completely, which is why our hurricane IT preparedness checklist for SWLA reads a lot like a ransomware readiness plan: know what systems matter, know where the backups are, and know who does what when things go dark.

What Actually Shrinks the Number

You can't negotiate the averages, but you can decide which side of them you land on. Five controls move the cost curve more than anything else:

Tested, offline backups. The single biggest lever. A backup the attacker can't reach — offline or immutable — and that you've proven you can restore turns "pay or die" into "restore and rebuild." Be honest about the limit, though: backups don't undo data theft, so extortion threats and notification duties can survive even a perfect restore.

Multi-factor authentication everywhere. Stolen credentials remain one of the most common ways attackers walk in the front door. MFA on email, remote access, and financial systems closes the cheapest path.

Email security done right. Most small-business attacks start in the inbox. Filtering, sender authentication, and tighter sender controls stop the first click — we walked through one practical control in our post on building an approved-sender whitelist in Microsoft 365.

Endpoint detection and response. Catching an intrusion in hours instead of weeks changes every number in the table above. EDR watches behavior — a process encrypting files in bulk gets isolated, not discovered Monday morning.

A rehearsed incident response plan. The companies that recover fastest aren't lucky; they've decided in advance who to call, what to isolate, and what order to restore in. The plan costs almost nothing. Not having one costs days.

Standing all of this up — and watching it around the clock — is the core of AOP's managed IT and cybersecurity service. We quote it as flat-rate pricing customized to your business, so protection is a predictable monthly number instead of an unpredictable six-figure event.

Frequently Asked Questions

Will cyber insurance pay for a ransomware attack?

Often it covers a meaningful share — forensics, recovery, business interruption, sometimes the ransom itself — but only if you meet the policy's conditions. Carriers increasingly require MFA, EDR, and tested backups on the application, and misstating those controls is a common reason claims get denied. Treat the insurance application as a control checklist, and expect your premium to be reassessed after any claim.

Do good backups prevent ransomware losses?

They're the single biggest cost reducer, but not a complete shield. Modern crews steal data before they encrypt anything, so even a flawless restore leaves you facing extortion threats and notification obligations. Backups need to be offline or immutable — attackers hunt for them first — and tested with real restores, not assumed to work.

What should we do in the first 24 hours?

Disconnect affected machines from the network, but do not power them off or wipe them — memory and logs are evidence your forensics team and insurer will need. Call your IT or security provider and your insurer's breach hotline before rebuilding anything. Change credentials from a known-clean device, preserve logs, and don't communicate with the attacker on your own. Notification decisions go through legal counsel, not gut feel.

Should we just pay the ransom?

Most victims now don't — 64% refused in Verizon's 2025 DBIR. Paying doesn't guarantee a working decryptor or that stolen data is actually deleted, and the U.S. Treasury has warned that payments to sanctioned groups can create legal exposure of their own. It's a decision to make with counsel, your insurer, and law enforcement — and report the attack to the FBI's IC3 either way.

How do most ransomware attacks on small businesses start?

Phishing emails, stolen or reused credentials, and unpatched or exposed remote access — VPNs and remote desktop in particular. The inbox is the front door, which is why email controls and MFA close the most common paths in before anything more exotic matters.

Know your number before an attacker does

AOP helps Lake Charles and Southwest Louisiana businesses close the gaps that drive these costs — backups, MFA, email security, EDR, and a response plan — as one flat-rate managed service, quoted for your business.

Explore Managed CybersecurityTalk to Our Team

Or call us at (337) 477-3700.

AOP Inc

Advanced Office Products (AOP) is Southwest Louisiana's trusted technology partner, providing Managed IT Services, cybersecurity, fiber internet, cloud hosting, and Kyocera office equipment to 350+ businesses across the Lake Charles region and Southeast Texas.

Stop Managing Vendors. Start Growing Your Business.

One call. One partner. Fiber, IT, cloud, security, and equipment — all from AOP. Schedule a free 30-minute strategy session with our team.

GET YOUR FREE STRATEGY SESSION