TL;DR: The Verizon 2026 Data Breach Investigations Report confirms small and midsize businesses are now the primary ransomware target: 96% of ransomware victims where organization size was known were SMBs, and ransomware grew to 48% of all breaches. The attack chain almost always starts months earlier with a stolen credential, then exploits an unpatched vulnerability. Preferred Data Corporation helps North Carolina small businesses close that chain with immutable backup, 24/7 managed detection and response, phishing-resistant MFA, credential and dark-web monitoring, and disciplined patching.
Key takeaway: For SMBs, ransomware is no longer a big-company problem you can ignore. The 2026 DBIR shows the median ransom paid fell to $139,875 and 69% of victims refused to pay, which means recovery now depends on whether you have tested, immutable backups, not on whether you can afford the ransom.
Worried your small business is one stolen password away from a ransomware shutdown? Get a defense review today. Contact Preferred Data Corporation at (336) 886-3282. BBB A+ rated, serving High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the Piedmont Triad since 1987.
Why does the Verizon 2026 DBIR say SMBs are the primary ransomware target?
Small and midsize businesses are now the primary ransomware target because 96% of ransomware victims with a known organization size were SMBs, according to the Verizon 2026 DBIR. The report analyzed 7,152 confirmed breaches involving SMBs during the period from November 1, 2024 through October 31, 2025. Ransomware itself grew to 48% of all breaches, up from 44% the prior year, so the threat is both more common and more concentrated on smaller organizations.
For a High Point manufacturer or a Greensboro professional services firm, this reframes the risk conversation. Attackers are not skipping past small companies to chase enterprises. They are automating, and the volume of stolen credentials and unpatched systems makes SMBs the path of least resistance. As the Help Net Security summary of the 2026 findings notes, ransomware operators favor whoever is easiest to compromise, and that is increasingly the underprotected small business.
Three numbers from the report frame the SMB reality:
- 7,152 confirmed breaches in the dataset involved SMBs.
- 96% of size-known ransomware victims were SMBs.
- Ransomware reached 48% of all breaches, up from 44% year over year.
How does a ransomware attack on a small business actually start?
Most ransomware attacks start with a stolen credential long before the ransom note appears. The 2026 DBIR found that 73% of ransomware victims had an associated infostealer infection or credential-leak event in the year prior to the attack. In half of those cases, 50%, the credential-leak event happened within 95 days of the ransomware attack, per the SpyCloud analysis of the 2026 DBIR.
That timeline matters. It means there is usually a window of roughly three months between when an employee's password is stolen by malware and when the ransomware fires. During that window, the credential is often sitting in a criminal marketplace or a dark-web dump. Businesses that monitor for their own leaked credentials can find and reset those passwords before an attacker uses them.
The second half of the attack chain is unpatched software. The 2026 DBIR reports that vulnerability exploitation is now the number one initial-access and breach vector, a shift the Mimecast breakdown of the 2026 DBIR highlights as a decisive change in attacker behavior. Combine a stolen password with an unpatched internet-facing system and you have the modern SMB ransomware playbook.
Two-part defense you can start now: monitor for leaked credentials and patch known-exploited vulnerabilities on a tight cadence. Preferred Data Corporation's cybersecurity team builds both into a single managed program. Call (336) 886-3282.
Should a small business pay the ransom?
The data says most do not, and most survive without paying. The 2026 DBIR found that 69% of ransomware victims did not pay the ransom, and the median ransom that was paid fell to $139,875, down from $150,000 the prior year, according to the Cyber Insurance News summary of the report. Declining payment rates suggest that better-prepared organizations are choosing to restore from backup instead of funding criminals.
The practical lesson is that your recovery strategy, not your checkbook, determines whether a ransomware attack becomes a catastrophe. If your backups are immutable, meaning they cannot be altered or deleted even by an attacker who has domain admin rights, and you have tested a full restore, you can refuse the ransom and rebuild. If your only backups sit on the same network the attacker just encrypted, you have no real option.
Here is how the two recovery paths compare for a typical NC small business:
| Factor | No immutable backup + no MDR | Immutable backup + 24/7 MDR |
|---|---|---|
| Likely to pay ransom | Higher, often forced | Lower, 69% of victims did not pay |
| Median ransom exposure | Up to $139,875 or more | Avoidable via restore |
| Detection of credential leak | None until encryption | Caught in the ~95-day window |
| Restore confidence | Unknown, untested | Tested, documented recovery |
| Downtime | Days to weeks | Hours to days |
Even a partial improvement, immutable backups on their own, changes the math. PDC's backup and business continuity service is built to give you a restore you have actually tested, not one you are hoping works.
What about third-party and vendor risk for SMBs?
Third-party exposure is a major and growing driver of SMB breaches. The 2026 DBIR found that third parties were involved in 55% of SMB breaches, meaning more than half of small business incidents trace back to a vendor, supplier, software provider, or other outside party. The Push Security review of the 2026 DBIR emphasizes that supply-chain and connected-account risk now sit at the center of the breach picture.
For a small manufacturer in the Piedmont Triad, this often looks like a compromised software vendor pushing a malicious update, a managed service with over-broad access, or a partner whose leaked credentials open a door into your systems. You cannot audit every vendor's security team, but you can control the blast radius: limit vendor access, segment your network, require MFA on every external connection, and monitor for anomalous vendor activity.
Three third-party realities from the report:
- 55% of SMB breaches involved a third party.
- Credential theft frequently arrives through connected vendor accounts.
- Vulnerability exploitation, the top vector, often lands via unpatched vendor or third-party software.
PDC's managed IT services and network infrastructure practice apply least-privilege access and segmentation so a single compromised vendor cannot reach your entire environment.
What should a North Carolina small business do about it right now?
The most effective response maps directly to how the 2026 DBIR says attacks happen: stop the credential theft, close the vulnerability, and guarantee recovery. Because 73% of victims had a prior credential leak and vulnerability exploitation is the top vector, the highest-leverage controls are credential monitoring, tight patching, and immutable, tested backups.
Preferred Data Corporation, a High Point MSP serving NC since 1987, maps each DBIR finding to a specific control:
| DBIR 2026 finding | PDC control | Service |
|---|---|---|
| 73% had a prior credential leak | Dark-web and credential monitoring, phishing-resistant MFA | Cybersecurity |
| Vulnerability exploitation is the #1 vector | Known-exploited-vulnerability patching cadence | Managed IT |
| 96% of ransomware victims are SMBs | 24/7 managed detection and response | Cybersecurity |
| 69% did not pay, recovery via backup | Immutable backup and tested restore | Backup and continuity |
| 55% of SMB breaches involved third parties | Least-privilege access, network segmentation | Network infrastructure |
This is not a checklist you buy once. It is an ongoing managed program, because the credential leaks and new vulnerabilities that feed ransomware arrive continuously. Manufacturers can review our manufacturing IT and OT security approach, and professional services firms can see our professional services IT model.
Ready to close the ransomware attack chain before it closes your business? Call Preferred Data Corporation at (336) 886-3282 for a defense review tailored to your NC small business.
Frequently Asked Questions
What percentage of ransomware victims are small businesses in 2026?
According to the Verizon 2026 DBIR, 96% of ransomware victims where the organization size was known were small and midsize businesses. The report analyzed 7,152 confirmed breaches involving SMBs and found ransomware grew to 48% of all breaches, up from 44% the prior year. Small businesses are now the primary ransomware target, not an afterthought.
How much is the average ransom payment in 2026?
The 2026 DBIR reports the median ransom paid fell to $139,875, down from $150,000 the prior year. Just as important, 69% of ransomware victims did not pay the ransom at all, which signals that more organizations are recovering from immutable backups instead of paying criminals. Your recovery strategy, not the ransom amount, determines your real exposure.
How do most ransomware attacks on SMBs begin?
Most begin with a stolen credential months before the ransomware fires. The 2026 DBIR found that 73% of ransomware victims had an infostealer infection or credential-leak event in the prior year, and 50% experienced that event within 95 days of the attack. Vulnerability exploitation is now the number one initial-access vector, so a stolen password plus an unpatched system is the common pattern.
Why is third-party risk a big deal for small businesses?
The 2026 DBIR found that third parties were involved in 55% of SMB breaches. That means a vendor, supplier, software provider, or partner is implicated in more than half of small business incidents. Limiting vendor access, segmenting your network, and requiring MFA on external connections reduces how far any single compromised third party can reach.
Can immutable backups really let me avoid paying a ransom?
Yes, when they are properly isolated and tested. Because 69% of 2026 DBIR ransomware victims did not pay, recovery increasingly depends on backups an attacker cannot alter or delete, even with admin rights. Preferred Data Corporation builds immutable backup with documented, tested restores so you can rebuild rather than negotiate. Call (336) 886-3282 to review your current backup posture.
Does Preferred Data Corporation serve small businesses across the Piedmont Triad?
Yes. Preferred Data Corporation is a High Point, NC MSP founded in 1987, serving small and midsize businesses across High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the wider Piedmont Triad. We provide managed IT, cybersecurity, immutable backup, and network services mapped to the real attack patterns in the 2026 DBIR. Call (336) 886-3282 to get started.
Related Resources
- Verizon 2026 Data Breach Investigations Report
- SpyCloud: Top takeaways from the 2026 Verizon DBIR
- Help Net Security: Lessons from the Verizon DBIR 2026 findings
- PDC Cybersecurity Services
- PDC Backup and Business Continuity
- PDC Managed IT Services
- SMB breach economics: an NC small business survival budget
- Ransomware 2026 H1 report: 146 groups, Qilin leads, NC SMB defense priorities