A ransomware attack does not always announce itself with a frozen screen and a dramatic demand for cryptocurrency. Sometimes, the first sign is far more ordinary. Employees cannot open shared folders. The accounting team loses access to invoices. Orders stop appearing in the system. A supplier calls to ask why it received a strange email. By the time the business understands what has happened, its data may already have been copied and its systems locked.

For a small or medium-sized enterprise, this can bring daily operations to a halt within hours. Yet many SMEs across Southeast Asia still approach ransomware mainly as an IT concern. Cybersecurity is often delegated to an external provider, addressed through an annual software purchase or discussed only after an employee clicks on a suspicious link.

That approach no longer reflects how ransomware works. Today’s attackers are not only trying to encrypt files. They are looking for any form of leverage that can force a company to pay. This may involve stealing customer information, threatening to expose confidential documents, approaching clients directly or disrupting the systems a business relies on to collect payments and deliver services.

The threat has moved beyond damaged computers. It now reaches cash flow, customer confidence and the ability of a company to continue trading.

Smaller companies are attractive targets

Many SME owners assume cybercriminals are mainly interested in banks, government agencies and multinational companies. After all, larger organisations hold more data and have more money to lose. However, they also tend to have larger cybersecurity teams, better monitoring systems and clearer incident response procedures.

An SME may present a much easier route to payment. Singapore’s Cyber Security Agency recorded 165 ransomware cases in 2025, compared with 159 in 2024. SMEs remained disproportionately affected, partly because smaller organisations often operate with fewer cybersecurity resources and less mature processes.

The regional picture is equally concerning. INTERPOL reported more than 135,000 ransomware-related attacks across Asia and the South Pacific in 2024. Manufacturing, financial services and real estate were among the sectors affected. Verizon’s 2025 Data Breach Investigations Report found ransomware involved in 51 per cent of the Asia-Pacific breaches it analysed. It also found that four out of five regional breaches involved system intrusion, while attacks exploiting vulnerabilities increased by 34 per cent.

These attacks do not always require months of detailed planning. Cybercriminals can scan large numbers of businesses for outdated software, poorly protected remote access systems and exposed servers. Stolen usernames and passwords are also widely traded online, allowing attackers to test the same credentials across multiple services.

Once an opening appears, an attacker can move from one company to the next. This makes SMEs appealing not because each victim can afford a large ransom, but because the process can be repeated. A criminal group may prefer several relatively easy targets over one highly protected corporation.

Ransomware has changed

Earlier ransomware incidents usually followed a simple sequence. Malicious software entered the company network, encrypted files and displayed a ransom demand. The business was told it would receive a decryption key after making payment. The modern version is more calculated. Attackers may spend days or weeks inside a network before making themselves known. During that time, they look for information that can increase pressure on the victim.

This may include employee records, customer databases, financial documents, commercial contracts, intellectual property and private correspondence. Once the information has been copied, attackers can threaten to publish or sell it. Some groups also contact customers, employees or business partners to inform them that their data has been compromised. Others threaten to launch additional attacks against the company’s website or online services.

Encryption is now only one part of the strategy. In some cases, attackers steal information and demand payment without locking any files. This is why maintaining backups, while essential, is no longer enough by itself. A clean backup may allow the company to restore a system, but it cannot recover the confidentiality of data that has already been stolen. It also does not guarantee that the attacker has been removed from the network.

Sophos found that only 54 per cent of affected organisations used backups to restore data in 2025. Unpatched vulnerabilities were the most common technical cause identified in its research. Where attackers entered through an exploited vulnerability, backups were also more likely to be compromised. The question for SMEs is therefore not simply whether they have backups. It is whether those backups are protected, regularly tested and capable of supporting a real recovery.

The weakest points are often routine ones

A ransomware incident rarely begins with technology that looks especially advanced. It often starts with a basic task that was delayed or overlooked. A software update may not have been installed. An employee may have reused a password. A former staff member’s account may still be active. Remote access may have been introduced during a busy period and never properly secured.

None of these decisions may appear serious on their own. Together, they can leave a business exposed. Compromised credentials were the initial access method in 22 per cent of the breaches examined in Verizon’s 2025 report. Its research also found that, in the median case, less than half of a user’s passwords across different services were unique.

This means one stolen password can potentially provide access to several systems. Third-party access creates another area of risk. Most SMEs depend on a network of accountants, software companies, web developers, payroll providers, outsourced IT teams and logistics partners. These relationships are necessary, but each external account or connection needs to be controlled.

Verizon reported that third-party involvement in breaches doubled in its 2025 analysis. The answer is not to avoid external providers. It is to know which providers can enter company systems, what information they can reach and whether their access is still required. Access granted for a short project should not remain open indefinitely. Shared administrator passwords should not pass between suppliers. Former contractors should not retain access simply because nobody remembered to remove it. These are operational habits rather than expensive cybersecurity projects, but they can make a significant difference.

The ransom may not be the biggest expense

The amount demanded by an attacker tends to receive the most attention. For many SMEs, however, the greater cost comes from being unable to operate normally. Consider a distributor that cannot see its inventory, a clinic that cannot access patient appointments or a professional services firm that loses access to client documents and email. Even if the systems are restored eventually, the disruption can quickly spread across the business.

Staff may be unable to work. Orders may be delayed. Invoices may not be issued. Customers may leave because they cannot get a clear answer about when services will resume. The business may also need to engage cybersecurity investigators, lawyers, communications advisers and data recovery specialists. Depending on the information involved, it may need to notify customers, regulators or other authorities.

Sophos estimated the average recovery cost of a ransomware attack, excluding the ransom, at US$1.53 million in its 2025 research. The average ransom payment was US$1 million. These global figures are not representative of what every Southeast Asian SME will face. They do, however, show that the cost of rebuilding systems and restoring operations can exceed the original demand.

Payment does not provide certainty either. A decryption tool may restore only part of the affected data. It may work too slowly for a company that needs to resume operations immediately. Attackers may keep copies of stolen information, and paying once may signal that the business could be pressured again.

More importantly, payment does not close the vulnerability that allowed the attack to happen. This is why ransomware needs to be discussed as a business continuity issue. The central question is not merely how to block an attack, but how the company will continue operating when a critical system becomes unavailable.

What SME owners should do first

Cybersecurity advice can quickly become technical, expensive and difficult to prioritise. Most SMEs do not need to begin by building a sophisticated security operation. They need to address the weaknesses most likely to cause serious disruption.

  • Work out what the business cannot function without

Every company has a small number of systems that keep the operation moving. These may include email, payment processing, payroll, customer records, inventory or an industry-specific platform. Owners should know which systems must be restored first and how long the company could reasonably operate without them.

This exercise also helps identify practical alternatives. Could staff process urgent orders manually? Is there a secure offline list of important contacts? Can customers still reach the company when its main email system is unavailable?

  • Protect important accounts with multi-factor authentication

Multi-factor authentication should be used for email, financial platforms, cloud software, administrator accounts and remote access tools. This adds another verification step after the password. It is not perfect, but it makes many stolen credentials considerably harder to use.

Senior employees and business owners should not be exempt. Their accounts are often particularly valuable because they may contain financial information, confidential conversations and approval authority.

  • Make patching somebody’s clear responsibility

Software updates are easily delayed because they interrupt work or require a system restart. Yet unpatched internet-facing systems remain one of the most common routes into company networks. The business should know who is responsible for updating its firewalls, servers, website software, remote access products and other important platforms.

When IT is outsourced, the contract should clearly state whether patching is included, how often updates are applied and how the provider confirms the work has been completed. Assuming a supplier is handling it is not the same as verifying that it has been done.

  • Keep backups separate and test them

Critical data should be backed up regularly, with at least one protected copy that cannot be easily altered through the main company network. A restoration test is equally important. Companies often discover during an emergency that a backup is incomplete, corrupted or dependent on passwords nobody can find. Testing shows whether the data can actually be recovered and how long that process will take.

  • Decide what happens during the first few hours

An incident response plan does not need to be a lengthy manual. A practical checklist is more useful than a document nobody can understand during a crisis. It should identify who contacts the IT provider, insurer, legal adviser and relevant authorities. It should also establish who can authorise emergency spending, disconnect affected systems and communicate with customers.

Employees should know whom to call when something looks wrong. They should not attempt to investigate independently, delete suspicious files or continue using a possibly compromised device. Singapore SMEs can access pre-approved cybersecurity solutions through the Productivity Solutions Grant under the SMEs Go Digital programme. These packages cover areas including anti-malware protection, firewalls and data backup.

Other Southeast Asian markets also provide national advisories and incident response support. CyberSecurity Malaysia, for example, continues to emphasise secure backups, stronger password practices and employee awareness as basic ransomware protections.

SME owners need to ask operational questions

SME leaders do not need to understand every cybersecurity product or technical term. They do need enough visibility to know whether the business is prepared. When was the last successful backup restoration? Who currently has administrator access? Are accounts removed as soon as an employee or contractor leaves? Which supplier can access customer data? Who would make decisions if the company’s email and accounting systems went offline at the same time?

These are not questions only for the IT team. They affect whether salaries can be paid, orders can be completed and customers can be kept informed. They determine how quickly the company can recover and how much damage a disruption can cause. Ransomware groups have refined their methods because they understand how businesses respond under pressure. They target not only technical weaknesses, but also uncertainty, poor preparation and the fear of prolonged disruption.

SMEs need to prepare with the same understanding. The most resilient companies will not necessarily be those spending the most on cybersecurity. They will be the ones that know which systems matter, limit unnecessary access, maintain recoverable backups and have already decided what to do before a crisis begins.


Also read: Can your business run without you? The succession test for SME owners in Malaysia

Leave a comment

Trending