DEV Community

Da
Da

Posted on Originally published at mrplanb.com

Mid Market Companies Account for 73 Percent of Disclosed Ransomware Incidents in Black Kite Analysis

Mid market companies are carrying a disproportionate share of publicly disclosed ransomware and data extortion incidents. Help Net Security reported on August 24, 2026 that Black Kite analyzed 13,336 incidents with known company revenue across North America and Europe between January 2023 and June 2026. Companies with annual revenue between $10 million and $1 billion accounted for 73 percent of those incidents, and their share remained between 72 percent and 75 percent throughout the period.

The consistency matters. This is not one unusual quarter caused by a single campaign. It suggests that ransomware operators repeatedly find the economics of mid sized organizations attractive. These companies often have valuable data and meaningful ability to pay, but may have smaller security and infrastructure teams than the largest enterprises. Recovery therefore has to be treated as an engineering capability rather than an assumption. Mr.PlanB’s guide to the 3 2 1 1 0 backup rule provides a useful framework for separating production data from protected recovery copies.

The smaller end of the mid market is heavily represented

Help Net Security reported that more than half of the mid market victims in the analysis had annual revenue between $10 million and $50 million. Manufacturing accounted for more than a quarter of mid market victims, followed by professional, scientific and technical services and construction.

That profile makes sense from an attacker’s perspective. Many companies in these sectors depend heavily on operational systems, shared files, ERP platforms, virtual machines and third party services. Downtime can stop production, delay projects or prevent staff from serving customers. The resulting business pressure can make an extortion demand more effective.

The important defensive conclusion is that smaller infrastructure teams should prioritize resilience around the systems that stop the business when unavailable. A complete inventory of every possible asset is useful, but recovery planning needs to identify which services must return first and what dependencies they require.

Exposure before encryption is part of the ransomware problem

The Black Kite analysis also found widespread weaknesses in public facing systems. Help Net Security reported that 54.7 percent of more than 120,000 assessed mid market organizations had at least one significant patch management issue affecting an internet facing system. More than a quarter had a vulnerability already known to be exploited by attackers. Nearly one third had at least one stealer log finding, indicating exposed credentials collected by information stealing malware.

These signals show why ransomware defense cannot begin at the moment encryption starts. Attackers often need initial access, credentials, discovery and administrative control before they can damage large parts of an environment. Backup servers, hypervisors and identity systems can become targets during that preparation.

The recovery architecture should assume that production credentials may eventually be compromised. Independent backup identities, restricted deletion rights and separate storage paths make it harder for one stolen administrator account to destroy both production and recovery data.

A successful backup job is not the same as a successful recovery

Mid market teams often have backup software because it is an obvious requirement. The harder question is whether those backups can rebuild business services under pressure. A green job status says that data was copied. It does not prove that the copy is complete, clean, accessible or fast enough to meet the organization’s recovery objective.

Mr.PlanB’s guide to backup testing recommends moving beyond file checks toward application recovery, isolated restore environments and full system testing. For ransomware scenarios, isolated testing is especially valuable because teams need to know whether a restored system can be trusted before reconnecting it to production networks.

Recovery time should also be measured. Restoring several terabytes of data may be technically possible while still taking too long for the business. That gap should be discovered during a test, not during an incident.

Disaster recovery has to include dependencies and decision making

Ransomware can affect more than files. Identity services, DNS, virtualization, network management and backup infrastructure may all be unavailable at the same time. Restoring a server is not useful if the authentication or network services it depends on are still offline.

Mr.PlanB’s disaster recovery plan guide treats recovery as a coordinated process involving service priorities, dependencies, roles, contact paths, infrastructure rebuilds and testing. That broader model is particularly important for companies with small teams because the same administrators may be responsible for several systems during the incident.

The 73 percent figure should not be interpreted to mean every mid market company will be attacked. It shows where a large share of publicly disclosed incidents is already concentrated. Organizations in that range should therefore assume ransomware is a normal business continuity risk and test their infrastructure accordingly.

The strongest defense is not a promise that attackers can never get in. It is a combination of reducing exposure, protecting credentials, isolating recovery copies and proving that critical services can be rebuilt when preventive controls fail.

Originally published on the Mr.PlanB blog.

Top comments (0)