Ransomware coverage tends to lead with the payment — how much a company handed over, how many millions, how the number keeps climbing. That's not actually the most useful statistic for a small or midsize business trying to decide what to fix first. The more useful one, from VikingCloud's 2026 research, is this: 96% of ransomware attacks specifically target backup locations before anything else. Attackers know a business with a working backup can simply refuse to pay, so they go after the backup first, and only then start encrypting.
It's working less often than it used to, which is genuinely good news. Sophos's State of Ransomware 2026 report and Verizon's 2025 Data Breach Investigations Report both point the same direction: the median ransom payment has fallen, and 64% of victims now refuse to pay outright, up from about half two years ago. That shift correlates directly with better backup hygiene at the organizations that survive an attack without paying.
The less good news is who's still getting hit. Ransomware accounts for 88% of small business breaches, compared with 39% at large companies, according to Huntress's 2026 tracking — small businesses aren't a secondary target, they're the primary one. The reasons are unglamorous: weaker patching cadence, no dedicated security staff, and often a single backup copy sitting on the same network the ransomware just compromised.
The fix isn't exotic. A tested 3-2-1 backup setup — three copies of your data, on two different types of media, with one copy stored offline or off-network — removes the leverage that makes ransomware profitable in the first place. It costs a fraction of what a single incident does, and unlike most security spending, you can actually verify it works before you need it. Restore from it. See what breaks.