Cybersecurity

What Ransomware Actually Does to a Small Business, Hour by Hour

Ransomware does not happen all at once. It unfolds over hours or days, and almost every stage is a place it could still be stopped. Here is what an attack on a small business actually looks like, hour by hour.

7 min read

read

·

Clock and a three-stage timeline from Hour 0 to encryption, ending in a padlock, showing how a ransomware attack unfolds.

An article by

nexus ideal solutions logo
Nexus Ideal Solutions

Managed IT Team

Most people picture ransomware as a single moment: a skull on the screen, everything locked, a demand for payment. That image is the last five minutes of an attack that has usually been running for hours or days already.

Understanding the real timeline matters, because almost every stage before that final screen is a place the attack could still be caught and stopped. The businesses that lose everything are rarely the ones that got unlucky. They are the ones where nothing was watching during the hours that counted.

Here is what a ransomware attack on a small business actually looks like as it happens. The specifics vary, but the shape is consistent, and it is drawn from how these attacks are known to unfold rather than from any one incident.

Hour 0: The Way In

It almost never starts with the ransomware itself. It starts with a door.

Most commonly that door is a person. Someone clicks a link in a convincing email, enters their password on a page that looks like the real Microsoft login, and moves on with their day, having noticed nothing. AI has made those emails far harder to spot than the clumsy phishing of a few years ago. Other times the door is a server exposed to the internet with an unpatched vulnerability, or a remote-access tool with a weak password that gets guessed.

At this point nothing appears wrong. No files are locked. The business is operating normally. But an attacker now has a foothold, and the clock the business does not know is running has started.

Hours 1 to 24: The Quiet Part

This is the stage almost nobody knows about, and it is the most important one.

A competent attacker does not detonate immediately. They look around first. They map the network, find out what the compromised account can reach, and hunt for the things that will make the attack hurt most: the file server, the accounting system, the customer database. They escalate privileges, trying to get from one ordinary user account to an administrator account that can reach everything.

And crucially, they go looking for the backups. Modern ransomware operators know that a business with good backups can simply restore and ignore them, so finding and destroying or encrypting the backups is a deliberate early step. A backup sitting on the same network, reachable from a compromised admin account, is not a safety net. It is another target.

This quiet phase can last hours or days. It is also the single best place to catch an attack, because the attacker is moving around, touching things they should not, and behaving in ways that do not match normal activity. Something has to be watching for that behavior for it to be caught. This is exactly what endpoint detection and response is for, and on the systems we manage it runs through Huntress, whose security operations center reviews critical detections around the clock, at 2am on a Sunday the same as 2pm on a Tuesday. The value of that is entirely in this window: a detection during the quiet phase is an attack stopped before the damage, not cleaned up after it.

The Point of No Return: Encryption Begins

When the attacker has what they need, mapped the network, gained admin rights, and dealt with the backups, they trigger the encryption. This is the part everyone pictures, and by the time it starts, the hard part of the attack is already over. The attacker has been in the building for hours.

Encryption is fast. Files across the network become unreadable in minutes to a couple of hours, depending on size. Employees start seeing files they cannot open, applications that will not load, and eventually the ransom note itself. This is usually the first moment anyone in the business realizes something is wrong, and it is very nearly the worst possible moment to find out, because there is almost nothing left to do about it in the moment.

The Morning After: The Decision Nobody Wants

The business arrives to locked systems and a demand, typically for cryptocurrency, often with a deadline and a threat to leak stolen data if payment is not made. Because the modern playbook is not just to encrypt but to steal data first, paying to unlock the files does not undo the theft.

Now the real cost lands, and most of it is not the ransom. It is the downtime: every day the business cannot operate. It is the recovery labor. It is the potential breach-notification obligations if customer or patient data was taken. It is the customers who lose confidence. Studies of small-business ransomware consistently find the total cost dwarfs the ransom demand itself, and a meaningful share of small businesses hit never fully recover.

The decision of whether to pay is genuinely awful, and it is one no business should be making for the first time in the middle of the crisis. Which is the whole point of everything that comes before it.

Where the Timeline Gets Broken

Read back through those stages and a pattern emerges: there is no single wall that stops ransomware. There is a series of them, and the attack has to get through all of them. A business that has several in place rarely becomes a headline.

Multi-factor authentication is the wall at Hour 0. Even if a password is phished, the attacker cannot log in without the second factor, and the most common entry point closes. Patching and removing needless internet-facing services shut the other common doors.

Detection and monitoring is the wall during the quiet phase, Hours 1 to 24. This is where an attack in progress gets caught while there is still time, and it is why around-the-clock detection matters more than any other single control: attackers deliberately work nights and weekends precisely because that is when nobody is watching at most businesses.

Offsite, immutable backups are the wall at the encryption stage. If the backups are offsite and cannot be altered or deleted, even a fully successful encryption becomes a bad week rather than a closed business, because the data can be restored. This is why immutability specifically matters: it is the property that survives an attacker with full admin access.

And a written recovery plan is the wall the morning after. A business that knows what to restore, in what order, and who does it recovers in a fraction of the time of one improvising under pressure.

The Honest Version

No provider can promise you will never be attacked, and anyone who does is not being straight with you. What is true is that ransomware is a process with many steps, most of them quiet, and that a business with layered defenses forces an attacker to defeat every layer while giving itself many chances to catch them. Most attacks that succeed do so because there was nothing watching during the hours that mattered and nothing to restore from afterward.

That is a fixable situation, and none of the fixes are exotic. They are multi-factor authentication, patching, around-the-clock detection, immutable backups, and a plan. The businesses that have them are not lucky. They are prepared.

Want to know which of those walls your business actually has in place? Ask us for a security assessment and we will show you where the gaps are before someone else finds them.

Frequently Asked Questions

How long does a ransomware attack take? From the initial break-in to the encryption, often hours to several days. Attackers usually spend a quiet period mapping the network and finding backups before triggering anything. The encryption itself is fast, but by then the attack has been underway for a while, which is why detection during the quiet phase matters so much.

Why do attackers go after backups first? Because a business that can restore from backup can ignore the ransom. Modern ransomware deliberately seeks out and destroys or encrypts reachable backups. This is why an offsite, immutable backup, one that cannot be altered even by an admin account, is the single most important protection against having to pay.

Should we pay the ransom? It is a genuinely hard decision and one to make with expert guidance, not alone under pressure. Paying does not undo any data theft that already happened, does not guarantee working decryption, and marks you as willing to pay. The far better position is not needing to, which is what backups and a recovery plan provide.

Does antivirus stop ransomware? Traditional antivirus catches known threats but misses the behavior-based, hands-on-keyboard activity of a modern ransomware operator moving through a network. Endpoint detection and response, watched by a security operations center around the clock, is built to catch that in-progress activity, which is where attacks are actually stopped.

Why does 24/7 monitoring matter so much? Because attackers deliberately act during nights, weekends, and holidays, when most businesses have nobody watching. On the systems we manage, critical detections are reviewed around the clock through Huntress, so the quiet phase of an attack does not get a free pass just because it started at 2am.

We are a small business. Are we really a target? Yes, and often specifically because attackers assume the defenses above are missing. They are not chasing prestige, they are chasing the path of least resistance, and an unprotected small business is exactly that. The good news is the same defenses that protect large organizations are entirely available to small ones.

Other useful insights

Get started today

Small enough to know your setup. Big enough to run it right.

A small team that gets to know your environment, so you're not re-explaining it to a stranger every time something breaks.

45+ years engineering experience

NJ, NY, PA, MA & FL coverage

24/7 monitoring

Vendor agnostic

Get started today

Small enough to know your setup. Big enough to run it right.

A small team that gets to know your environment, so you're not re-explaining it to a stranger every time something breaks.

45+ years engineering experience

NJ, NY, PA, MA & FL coverage

24/7 monitoring

Vendor agnostic

Get started today

Small enough to know your setup. Big enough to run it right.

A small team that gets to know your environment, so you're not re-explaining it to a stranger every time something breaks.

45+ years engineering experience

NJ, NY, PA, MA & FL coverage

24/7 monitoring

Vendor agnostic