York Computer logo York Computer
Managed IT & Security
Cybersecurity News

Small Construction Firm Closes Months After Ransomware — The 'Too Small to Be a Target' Myth, Again

York Computer •

A cautionary tale made the rounds this week: a small construction company was warned by a cybersecurity consultant to invest in professional IT, brushed it off as unnecessary for a business its size, got hit with ransomware that encrypted everything — including its only backup — and closed within months. It's not a flashy zero-day story. It's the far more common one: a small business owner who assumed criminals wouldn't bother, and lost the company because of it.

What actually happened

The story was shared by cybersecurity consultant Dave Hatter and reported on October 9. A small construction firm, despite being advised by the consultant, fell victim to a ransomware attack after its owner dismissed the need for professional IT services, believing the business was too small to be a target. The attack encrypted all critical data and the company's only backup, leading to its closure within months.

The same write-up paired that failure with a success story from a different company that had modern security tooling in place. Phishing emails led to a fake Microsoft 365 login page, successfully capturing credentials and a two-factor authentication code through a man-in-the-middle attack. However, the victim's company utilized security software that detected the anomalous login and revoked access within minutes, preventing significant damage.

Two small businesses. Same class of attacker. One is gone, the other barely noticed.

Why this matters for small businesses in 2026

The "we're too small to be a target" argument hasn't been true for years, and the data keeps piling up. Ransomware now appears in 83% of SMB breaches according to the Verizon 2026 Data Breach Investigations Report. Small businesses are specifically appealing to ransomware crews because they tend to run older gear, rely on a single backup, and don't have anyone watching the network after 5pm.

Attackers also don't hand-pick victims the way most owners imagine. They scan the entire internet for exposed services, blast phishing emails at every address they can scrape, and whoever clicks or whoever has an unpatched firewall is who they hit. Being small doesn't make you invisible — it makes you cheap to attack.

What your managed-IT provider should already be doing

The difference between the construction firm that closed and the company that shrugged off a credential-theft attack came down to a short list of controls. If you have a managed-IT provider, these should already be in place — and you should be able to get a straight answer about each one:

- **Offsite, immutable backups that are tested.** The construction firm had "a backup." It got encrypted along with everything else. Backups that live on the same network as production are not backups. - **Phishing-resistant MFA on Microsoft 365 and every admin account.** SMS codes and basic app prompts get bypassed by the man-in-the-middle kits criminals rent for a few hundred dollars. - **Identity monitoring that flags anomalous logins and can kill a session automatically.** That's what saved the second company. - **Patch management on the firewall, the switches, the servers, and every endpoint — on a schedule, not when someone remembers.** - **An actual incident-response plan with phone numbers, not a folder nobody has opened in two years.**

If you're doing this with an in-house tech who's also running helpdesk and ordering laptops, you're asking one person to do five jobs. That's where co-managed IT backup for your existing IT person fits — 24/7 monitoring, after-hours coverage, and security tooling alongside the person you already have. If you have no IT staff at all, that's what a full managed-IT and cybersecurity stack is for.

The uncomfortable question

If your network got encrypted tonight — every file server, every workstation, every QuickBooks file, every job folder — could you be back in business by Monday? Not "could you survive," but could you actually operate?

If the answer is no, or you're not sure, that's the real finding from this week's story. The construction firm's owner wasn't negligent in any dramatic way. He just made the same bet thousands of small-business owners make every day: that nothing bad will happen, so paying for protection isn't worth it. The bet paid off until it didn't, and then there was no company left to course-correct.

What York Businesses Should Do

Construction, trades, and professional-services firms are the backbone of York County's small-business economy, and they're exactly the profile ransomware crews are hitting. If you don't have tested offsite backups and phishing-resistant MFA on your Microsoft 365 this week, that's the first conversation to have with York Computer or whoever runs your IT.

Sources

Worried whether your business is exposed to this? Talk to York Computer.

Managed IT & cybersecurity for York County small businesses.

← Back to all articles