It was 2:14am on a Tuesday. Our after-hours monitoring flagged anomalous network behavior at a manufacturing client in the northwest suburbs — unusual encrypted traffic, large internal file transfers, and a spike in disk write activity across their server infrastructure. By the time our team was on the phone with their on-call contact at 2:31am, the ransomware had already encrypted a significant portion of their file server.
By 6am, we had isolated the infected systems, confirmed which backups were clean, and begun recovery. By end of day, the business was substantially operational. It was not painless. But it was survivable — because they had the right infrastructure and a practiced response plan in place.
Most Chicago small businesses do not. And the gap between "we have antivirus" and "we can recover from ransomware" is enormous.
There is a common and dangerous misconception that ransomware targets large enterprises. The reality is almost the opposite. Organized ransomware groups have shifted heavily toward small and mid-sized businesses precisely because they hold valuable data, process payments, and often lack the security infrastructure to detect or contain an attack.
According to FBI cybercrime data, small businesses account for the majority of ransomware victims. The average ransom demand has risen to tens of thousands of dollars — far beyond what most small businesses budget for contingencies. And paying the ransom does not guarantee recovery: a significant percentage of businesses that pay never recover all their data.
The business types we see targeted most frequently in the Chicago metro area include:
Understanding the attack vectors is essential because effective prevention requires addressing the actual entry points, not just installing software and hoping for the best.
Phishing emails remain the dominant entry point. In 2026, AI-generated phishing emails are indistinguishable from legitimate business communications. An employee clicks a link or opens an attachment, and a loader executes silently in the background. The ransomware itself may not activate for days or weeks — giving it time to spread laterally across the network before triggering.
Exposed remote access services. Remote Desktop Protocol (RDP) exposed to the internet without MFA is still one of the most common entry points we see. Attackers scan for open RDP ports, brute-force weak credentials, and gain direct access to systems. One exposed RDP port with a weak password is often all it takes.
Unpatched software vulnerabilities. Legacy operating systems, unpatched applications, and outdated firmware create exploitable vulnerabilities that ransomware groups weaponize quickly after disclosure. A business running Windows systems that are not actively managed and patched is operating with known holes in its security posture.
Supply chain and vendor compromise. Attackers increasingly target managed service providers, software vendors, and IT supply chains to reach their actual targets. A vulnerability in a vendor's remote management tool can provide access to hundreds of client environments simultaneously.
Important: By the time ransomware announces itself — with the note on your screen demanding payment — attackers have typically been inside your network for days or weeks. They have already exfiltrated data. Recovery requires addressing both the encryption event and the underlying compromise.
If ransomware triggers on your network, the actions you take in the first hours determine whether you recover in days or weeks — and how much you lose in the process.
1. Isolate immediately. Disconnect affected systems from the network as fast as possible. Ransomware spreads laterally — every minute an infected machine stays connected, it is potentially encrypting additional file shares, backup drives, and adjacent workstations. Pull network cables, disable Wi-Fi, kill switches on managed switches if you have them.
2. Do not turn off systems yet. Counterintuitively, you generally do not want to power off infected machines immediately. Running memory may contain encryption keys or forensic artifacts that can aid recovery. Consult your IT team or incident response provider before shutting anything down.
3. Contact your IT provider immediately. If you have a managed IT provider, call them now — not in the morning. Incident response is time-sensitive. Every hour of delay is additional encrypted data and extended recovery time.
4. Identify your backups — and verify they are clean. This is the critical question. Do you have backups? Are they offline or otherwise isolated from the infected network? Have they also been encrypted? A backup that lives on a network share that ransomware can reach is not a real backup. If your backups are clean and recent, recovery is a matter of hours to days, not weeks.
5. Do not pay the ransom without expert consultation. Paying is not always wrong, but it should never be the first move. Many ransomware variants have known decryptors. Some attackers will take payment and not deliver a working decryption key. Paying also does not guarantee the exfiltrated data stays private. Get expert counsel before making any payment decision.
6. Document everything for insurance and legal purposes. If you carry cyber liability insurance, notify your insurer promptly — most policies have notification deadlines. Document the timeline, affected systems, and all response actions. If sensitive data was exfiltrated, you may have notification obligations under Illinois data protection law.
7. Preserve forensic evidence. Before wiping and rebuilding systems, ensure that forensic images are preserved. Understanding how attackers got in is essential to preventing a repeat incident after you restore operations.
The businesses that recover from ransomware quickly — or avoid it entirely — are not the ones with the most expensive antivirus. They are the ones that have done the fundamental work across a few critical areas:
Immutable, offsite backups. The single most important ransomware defense is a backup strategy that ransomware cannot reach. This means backups that are air-gapped or written to immutable storage — systems where the ransomware, even if it reaches the backup infrastructure, cannot overwrite or encrypt backup data. Cloud backup with immutable retention policies, combined with tested restore procedures, is the baseline.
Multi-factor authentication everywhere. MFA on email, remote access, cloud services, and administrative accounts eliminates the vast majority of credential-based attacks. If an attacker steals a password but cannot satisfy MFA, they are stopped. This is non-negotiable in 2026.
Network segmentation. When ransomware executes on a workstation, network segmentation limits how far it can spread. Your accounting systems should not be on the same flat network as your guest Wi-Fi. Your backup servers should not be reachable from your general workstation environment. Proper segmentation turns a potential catastrophe into a contained incident.
Endpoint detection and response (EDR). Basic antivirus does not detect modern ransomware, which is specifically designed to evade signature-based detection. EDR tools use behavioral analysis to identify ransomware activity — unusual encryption patterns, mass file modifications, lateral movement attempts — and can automatically isolate infected endpoints before damage spreads.
Patching and vulnerability management. Keeping systems patched is unglamorous but essential. Critical vulnerability patches should be applied within 24-48 hours of release. Managed IT services handle this continuously so you are not relying on a staff member to remember to run Windows Update.
Security awareness training. Employees who can identify phishing attempts are one of your most effective defenses. Regular training combined with simulated phishing campaigns — where you test whether employees click — dramatically reduces successful phishing attacks.
Our cybersecurity and managed IT services are built around the layered defense model that actually prevents and contains ransomware. We provide 24/7 endpoint monitoring, managed EDR, network segmentation design and maintenance, backup management with immutable retention, and incident response support when the worst happens.
For businesses that have never formally assessed their ransomware exposure, we offer a straightforward IT security assessment that evaluates your backup posture, network architecture, endpoint protection, access controls, and patching hygiene against current ransomware tactics. You come away with a clear, prioritized action list — not a 40-page report that nobody reads.
The client who got hit at 2am recovered because the systems and relationships were already in place. That preparation started months before the attack.
Get a ransomware readiness assessment from Chicago's experienced managed IT and cybersecurity team. Know where you stand before an attack forces the question.
Schedule a Security Assessment