Skip to content
HIFENCE

Ransomware in Mid-Market Companies: 5 Decisions the CEO Must Make, Not IT

Picture of Daniel Sarica, the founder of HIFENCE. Daniel Sarica

Published: May 6, 2026

This article is not about security technologies. It is about the 5 decisions an executive makes that determine the difference between a company attackers pick and one they pass by.
Small and mid-market companies have become ransomware attackers’ preferred target, and most attacks exploit management gaps, not technical ones.


Decision 1: Who Has Access to What

In a 100-person company, access to systems has expanded over time without anyone keeping score. Someone needed an application, they got access. Someone left, the access stayed. A consultant came in for a project, and their account was never deactivated at the end.
A few years later, you have 200–300 active accounts across various systems. Nobody knows how many there are or whose they are.
For an attacker who has gained initial access, that mess is a gift. With a few hours of exploration, they find a forgotten account that has access to everything, or identify a former employee whose credentials still work. This is where we can help with cybersecurity services.

The Questions You Ask IT

  • How many active accounts do we have in the systems that matter (email, ERP, CRM, VPN, file shares)?
  • How many active employees do we have? What’s the difference?
  • What process do we have when someone leaves? Who notifies IT, how quickly do accounts get closed, who confirms?

The typical answer in mid-market companies: “I’d have to check,” “It depends on the department,” “Each manager handles their own.” All three mean the same thing: there is no process, there is improvisation.

What You Require to Happen

A written process, simple, one page long. HR notifies IT one week before a departure. IT has a checklist covering every system - email, VPN, ERP, CRM, phone system, badge access, cloud, GitHub if applicable. On the departure date, everything gets closed the same day. One person in IT confirms it was done, by email, to HR and the manager.
And a quarterly review: the list of active accounts vs. the list of active employees. The difference gets closed. 30 minutes per quarter.


Decision 2: MFA on Everything That Matters

This is the decision with the biggest impact for the lowest cost. It is also the most poorly made one in mid-market companies.
The dominant attack vector in 2025 is credential compromise. An employee uses the same password at work as on a personal website. The website gets breached, the password shows up in public dumps, the attacker tries it on the company email. It works.
There is one control that blocks this scenario completely: multi-factor authentication (MFA). On email, on VPN, on cloud systems, on any service with access to critical data or systems. If the attacker has the password but not the employee’s phone, they don’t get in.
MFA is included for free in Microsoft 365, Google Workspace, and most modern solutions. Cost: zero. Operational cost for users: one second a day, one push notification approval.

Your Decision as an Executive

MFA mandatory on all critical systems. No exceptions, no “we’ll look at it later,” no “only for those who want it.”
Watch out for internal resistance. Employees will say it’s annoying. Internal IT, without authority from leadership, will cave. You will get exemption requests: “executive X doesn’t want it, he’s too busy,” “salesperson Y complains it wastes his time.” Your answer is simple: there are no exceptions, especially for accounts with important access. Executive accounts are exactly the accounts an attacker wants most.
The question you ask 3 months from now: how many accounts don’t have MFA active? The correct answer is zero. Anything else is a problem.


Decision 3: The Backup Exists vs. the Backup Works

Almost every mid-market company has a backup. Almost none has tested it.
”The backup exists” means an automated job runs and copies data somewhere. If the job doesn’t throw errors, everyone assumes it’s fine. “The backup works” means that in an incident, the data can actually be restored within an acceptable timeframe.
The difference between the two shows up only at the first incident, when it’s too late.
We have seen companies that believed they had backups because they were getting “completed successfully” emails, but when it mattered they discovered the backup had been saving empty files for months. Or a backup stored on the same system that got encrypted. Or a backup that worked, but restoring a single database took 3 days - time the company didn’t have.

What You Require to Happen

  • A real restore once per quarter. Not a check that the job runs, but an actual restore of a data set onto a test system
  • At least one copy of the backup isolated from the company network. If an attacker compromises Active Directory, they must not be able to automatically reach the backup too
  • A clear estimated recovery time: if everything goes down tomorrow, in how many hours are we 50% operational? In how many days at 100%?

The question you ask quarterly: when was the last real restore, what was restored, how long did it take, what did we learn? If the answer is “we didn’t do a real test this quarter,” your backup is an illusion.


Decision 4: Who Makes the Decisions if Everything Goes Down Tomorrow

Most mid-market companies have never discussed this scenario. Yet the first 24 hours of an incident determine 60–70% of the total cost.
Here is what a typical incident looks like: somewhere around 3 a.m., systems stop responding. Someone calls internal IT. IT doesn’t know exactly what to do, so they call the CEO. The CEO doesn’t know who to call externally. 4–6 hours disappear into panic, and decisions get made badly under pressure. Someone makes a decision that makes things worse - for example, restarting a server and losing the evidence the cybersecurity firm would have used for the investigation.

What You Need Written on 2 Pages, Somewhere Accessible

  • Who calls whom, in what order, with what phone numbers (external IT, the cybersecurity firm or MSSP you have an incident response agreement with, legal counsel, your insurer if you carry a cyber policy)
  • Who in the company has the authority to decide to shut systems down to limit the spread
  • Who communicates with employees, customers, and vendors in the first 24 hours, and what they communicate
  • Legal notification obligations: state data breach notification laws (every US state has one, and deadlines vary), HIPAA’s breach notification rule if you handle health data, notification clauses in customer contracts and in your cyber insurance policy, plus reporting the attack to the FBI’s IC3 and CISA. Who owns the reporting?
  • Do we pay the ransom or not if a demand appears? The FBI’s official position is: don’t pay. Decide this now, not under pressure

2 pages, readable under stress, with phone numbers and clear roles. Printed, scanned, in the CEO’s personal drive, on your phone. Not on the company network (which may be unavailable during an incident).


Decision 5: How You Verify That What You Decided Actually Happens

The most common mistake in mid-market companies isn’t a lack of decisions. It’s that decisions get made, IT confirms they’ve been implemented, and then nobody ever checks again.
A year later, when an incident hits, it turns out MFA wasn’t active on all accounts, the backup hadn’t been working for 3 months, and the offboarding procedure wasn’t applied to the last 5 people who left.
What you require: a fixed cadence, quarterly, 1–2 hours. You ask concrete questions, IT brings verifiable answers.

The Concrete Questions for the Quarterly Meeting

  • How many active accounts do we have? How many active employees? What’s the difference?
  • How many accounts don’t have MFA active?
  • When was the last real backup restore? How long did it take?
  • How many critical vulnerabilities published in the last 3 months are still unpatched?
  • What did we postpone from last quarter’s list, and why?

These questions don’t require technical knowledge from you. They only require concrete answers. And if the answer is “we haven’t checked” or “I’d have to look,” that is itself useful information - it shows an area where the company has no visibility.


What It Costs, What You Save

For a company of 80–150 employees, implementing these 5 decisions generally costs under $60,000 in the first year. Ongoing annual costs after that: $15,000–$30,000.
The average cost of a successful ransomware incident for the same company: $500,000–$1.5 million. Recovery + downtime + lost contracts + legal costs + a possible ransom. Plus the reputational impact, which never shows up in a spreadsheet but is felt for months.
That math isn’t close. It’s a question of when, not if, you will be attacked. Attackers work on volume and pick easy targets. Your decision is whether your company is an easy target or not.


Checklist: 10 Questions for You as an Executive

  • Is there a list of all active accounts in the systems that matter?
  • Is the difference between active accounts and active employees zero?
  • Is MFA active on email, VPN, and critical systems for all users?
  • Has the backup actually been restored in the last quarter?
  • Is there at least one copy of the backup isolated from the company network?
  • Is there a written incident plan, 2 pages, with phone numbers?
  • Does someone in the company know who to call at 3 a.m. if everything goes down?
  • Has the pay/don’t-pay ransom decision been discussed in advance, not under pressure?
  • Is there a quarterly cadence for reviewing security with IT?
  • Who in the company personally answers for it if an incident happens tomorrow?

If you answered “no” or “I don’t know” to more than 3 questions, you have clear opportunities for improvement. These things don’t get fixed overnight, but they don’t take a year either. The 5 decisions above, implemented with discipline, take your company off attackers’ target lists in 3–4 months.


If You Want to Understand Where Your Company Is Exposed

If you’re not sure where you stand on the areas above, or you want to check what’s missing, you can start with a short conversation where we analyze your current situation and identify the real priorities for your company.