Small and midsize businesses are being caught off guard by a wave of ransomware they never used to face, and the reason is that attackers have quietly changed who they target and how, according to Tim MalcomVetter, general manager at Coalition Security and co-founder of Wirespeed.
The shift has left smaller firms exposed to attacks they were never built to withstand. "Attackers' evolved approach is catching SMBs on their heels since they largely didn't have to contend with these kinds of attacks previously and don't have the personnel and resources to defend themselves," MalcomVetter said.
The change, he said, comes down to economics. Attackers behave like any rational business, chasing the best return for the least effort and risk, and for a decade the biggest returns came from large enterprises. That has stopped working as well. After years of ransomware, MalcomVetter said, it is now rare for a major enterprise to be locked out of its entire IT stack. When a brand name does make the news, it is usually a subsidiary or a single under-protected application rather than the core business, which means smaller ransoms. Enterprises are also paying less often than they once did, even when an attack partly succeeds. "For attackers, the friction is higher, and the value is lower," he said.
So the attackers moved down-market. MalcomVetter framed it in the language of business strategy: rather than developing new methods, they took proven techniques to a new customer base. "They have not pivoted to new products, but to new markets and distribution," he said. Small businesses do not carry the logo recognition that makes headlines, but that no longer matters to the economics.
What makes the smaller segment worth the trouble is scale, and this is where AI enters. The pivot works as a volume play, MalcomVetter said – what he called "low end disruption," a numbers game rather than a hunt for a single large payout. Heavily automated attack playbooks let a crew hit many small targets at once for the effort a single enterprise once required.
"Attackers can reap the same financial rewards by targeting several SMBs simultaneously with the same level of effort it would take to target a single large enterprise with a larger ransom," he said, and automation and AI are what make that possible.
The problem for those businesses is that the market has not equipped them to respond. Most cybersecurity products are built for large, complex enterprises or are simply too expensive for a small firm, MalcomVetter said, and the options aimed at the lower end are often weaker. The few down-market offerings, he said, "tend to be washed-out solutions that failed to compete in the enterprise segment, so they're generally not as good at stopping threats."
Compounding it is who actually runs security for most small businesses. The majority of SMBs in North America rely on one of more than 10,000 managed service providers for their IT support, MalcomVetter said, and the quality of that support is wildly inconsistent. Those providers range from one-person operations to large private-equity-backed firms with more than $100 million in annual recurring revenue, so a small business's protection can depend heavily on which end of that spectrum its provider sits.
The gap MalcomVetter points to is speed. Attackers choose the moment and get a head start; defenders have to catch up. Most endpoint security tools take anywhere from a minute to more than 15 minutes just to gather signals and route them to a human, he said, and there is little room to compress that. In a world where both sides move at the speed of automated AI, that head start is often enough for an attacker to reach their goal before a defender can respond.