Home About Speaking Framework Press Podcasts Field Notes Say Hello
SCORE Mentors Chicago — 2026 Cybersecurity Web Series

SCORE Session 3 — Ransomware

A danger to your business and your wallet

How ransomware attacks actually unfold against small businesses, why backups alone no longer save you, what an attack really costs, and how to approach the decision to pay or not to pay.

← Previous: Cyber Insurance Next →

In the third session of the SCORE Chicago cybersecurity series, Cyrus Walker explains why ransomware has become the leading threat to small businesses and the number one driver of cyber insurance claims. He covers how ransomware-as-a-service and AI have made attacks cheaper and faster, walks through real incidents at Change Healthcare, CDK Global and Joliet public schools, and breaks down the six stages of an attack, including double extortion and the destruction of backups. The session closes with the prevention basics — patching, air-gapped backups, MFA and security awareness training — the questions to answer before deciding whether to pay, and a live Q&A.

Key takeaways

  • 86% of small-business breaches involve ransomware, compared with 39% at large organizations, and the median ransomware victim had only 228 employees. Attackers see small businesses as low-hanging fruit.
  • The ransom is a small part of the bill. The average demand is around $115,000, but the total cost of an incident averages $4.4–5 million once downtime, response, legal notification and lost customers are counted.
  • Backups alone are no longer the answer. About 93% of ransomware attacks target backup repositories, so backups need to be air-gapped — physically disconnected from the network — and kept current so a restore doesn’t reintroduce old vulnerabilities.
  • Most attacks come through three doors: unpatched software, compromised credentials and phishing. Regular patching, MFA confirmed on a separate device, and security awareness training close most of them.
  • Whether to pay is a business decision, not a rule. First check for clean offline backups, confirm what data was stolen, consult your cyber insurer — acting without it can void coverage — and ask the FBI, which may already hold a decryption key.

← Back to Podcasts