The Lethal Cost of 'Too Small to Target'

AI-generated image · US National Wire
A construction firm's refusal to invest in cybersecurity ended in total business failure after a ransomware attack.
A small construction company that had operated for years went out of business within months after a ransomware attack, according to reporting from The Register.
Dave Hatter, a cybersecurity and compliance consultant with Intrust IT, reported that the company's owner had previously vetoed a proposal to hire his firm, claiming the business was too small to interest hackers. The owner reportedly told Hatter that his one-person IT staff was all he could afford, stating, “We got a guy, my brother’s uncle’s cousin does my IT, don’t need you guys.”
Three weeks later, the company was hit by ransomware. The attack targeted an old, unpatched Windows server containing all critical company data. While the firm maintained a backup drive, it was connected to the same server, resulting in both the primary data and the backups being encrypted.
Hatter noted that the loss of data left the company unable to pay employees or determine which clients owed them money. While it is unknown if the firm paid the ransom, the lack of off-site or cloud-based backups and the failure to patch servers proved fatal to the organization.

