Mid-sized businesses carry an outsized share of ransomware disruption
THE BRIEF
Manufacturing represented more than a quarter of the victims. Professional services, construction and wholesale were also prominent, reflecting the position of mid-sized companies inside larger supply chains. Nearly 30% of organizations in the study had at least one vulnerability already known to be exploited. Companies with annual revenue between $10 million and $50 million made up roughly half of the incidents, while the largest mid-market segment experienced fewer attacks. The figures come from a security-risk company’s dataset and are not an official census of all ransomware. North American organizations dominated the sample, so the percentages should not be generalized equally to every region or sector. The practical finding is still clear: a supplier can face enterprise-level ransomware pressure without enterprise-level staffing. Large customers may demand extensive security evidence, while the same company has too few people to assess hundreds of its own vendors. Recovery planning must therefore focus on the services and dependencies customers rely on most.
WHY IT MATTERS
When a mid-sized supplier stops operating, the disruption can spread to customers, employees and downstream partners even if the company is not a household name. Lost production, delayed deliveries and unavailable professional services can damage customer relationships faster than technical recovery restores them. Managers should treat ransomware resilience as a business-continuity obligation: define which services must continue, who can make emergency decisions and how identity, communications, backups and key suppliers will be restored together. The result can be lost money, account disruption and long recovery work for affected people.
WHO SHOULD CARE
Owners and managers of mid-sized companies, manufacturing and professional-services firms, procurement leaders, insurers and large customers should care because ransomware at a supplier can interrupt operations across an entire commercial chain. They need clear steps because delays can increase financial, privacy or operational harm.
WHAT TO DO NOW
- Identify the customer-facing services that must be restored first and assign accountable owners.
- Test backups together with identity, communications and critical application dependencies.
- Prioritize remediation of vulnerabilities listed as known to be exploited.
- Require multi-factor authentication for remote access, administration and backup systems.
- Create an incident communication plan for employees, customers, insurers and key suppliers.
- Reduce vendor-review workload by focusing on dependencies that could stop essential operations.
VERIFICATION NOTE
The existence, methodology and figures are confirmed in Black Kite’s report and independent coverage by Cybersecurity Dive. The dataset is vendor-produced, North America is heavily represented and the study is not a complete global census. Percentages are therefore attributed to the report rather than presented as universal ransomware prevalence. That limitation is reflected in this assessment.