Cheapskates wouldn’t pay for security help, got hit by ransomware, and went bust months later
A small construction company rejected a cybersecurity firm’s offer because its owner considered the cost unnecessary. Weeks later, ransomware encrypted the company’s unpatched server and the backup drive connected to it, leaving the business unable to access essential records; it closed within months. The incident illustrates how a small firm can be targeted and why separate, reliable backups and software updates matter.
The article also describes a phishing attempt between two landscaping and construction companies. Attackers who had taken over an executive’s email sent convincing requests for proposals, then directed recipients to a fake Microsoft 365 sign-in page that asked for passwords and time-limited two-factor authentication codes. The account’s filtering rules hid the campaign from its owner, while the receiving user’s two-factor authentication helped expose the deception.
- A construction firm shut down after ransomware encrypted its server and connected backup.
- The owner had declined a security provider’s help weeks earlier.
- A separate phishing campaign used a fake Microsoft 365 login to seek credentials.
New here? Start with this
Ransomware is malicious software that locks up a company's files and data until the victim pays money to restore access. In this story, a construction company's servers were infected after the owner declined to invest in cybersecurity protections, leaving the business unable to access vital records and ultimately forcing it to close.
Small businesses are frequent targets for ransomware attacks because they often have fewer defences than large corporations but still hold valuable data. The incident highlights why regular software updates and keeping separate backup copies of important files—stored away from the main computer systems—are essential safeguards.
The story also describes how attackers compromised an executive's email account and used it to send convincing fake emails to other construction firms. These messages directed recipients to a fraudulent login page designed to steal passwords and security codes, demonstrating how quickly security breaches can spread between businesses if employees aren't careful about verifying requests.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
The incident illustrates why cybersecurity investment is fundamental to business survival, not an optional expense. The construction company faced a clear risk assessment and chose to discount it; the resulting losses—business closure—vastly exceeded what preventive security measures would have cost. Small businesses are increasingly targeted precisely because they're seen as vulnerable, making investment in basic security practices (patching, reliable backups, employee training) an essential business requirement, not a luxury.
The case against
The narrative risks unfairly blaming small business owners facing genuine resource constraints. Small companies have real budget limitations where security spending competes with payroll and operations; moreover, cybersecurity vendors have commercial incentives to overstate threats, and no defence is entirely foolproof. Rather than presenting this as poor judgment by the owner, the focus should be on the actual perpetrators: the criminals conducting these attacks. Small businesses deserve sympathy as crime victims, not criticism for insufficient spending on defence.