Attackers discovered that companies pay faster when they can’t operate than when their data is at risk. This changes what you need to protect.
Marks & Spencer’s online ordering went dark for 46 days. Asahi Group’s breweries stopped producing beer. Jaguar Land Rover halted vehicle production across four countries. These weren’t data breaches in the traditional sense. They were operational shutdowns, and they represent how ransomware has evolved from a data problem into an existential threat to business continuity. When an attack can bring that kind of operation to its knees for six weeks, no business is immune.
The pattern across 2025’s most damaging attacks was consistent: attackers didn’t just encrypt files and demand payment. They targeted the systems that keep businesses running: production controls, ordering platforms, logistics coordination, inventory management. When those systems go dark, every hour of downtime translates directly into lost revenue, empty shelves, and frustrated customers.
Here’s your quick read brief:
- Ransomware incidents increased 45% in 2025, with manufacturing remaining the most targeted sector for the second consecutive year at 19.3% of all attacks (NordStellar, 2025).
- 88% of SMB breaches now involve ransomware, compared to 39% of large enterprise breaches (Verizon, 2025).
- An average ransomware attack costs $1.8 to $5 million, including downtime and recovery, with operational disruption driving the majority of costs beyond the ransom itself (VikingCloud, 2026).
Your disaster recovery plan covers fires and floods, but does it account for a six-week outage of core systems?
The Shift from Data Theft to Operational Paralysis
Criminals learned that encrypting your customer database creates urgency. Shutting down your ability to ship products or process payments creates desperation.
Between January and September 2025, researchers documented 4,701 confirmed ransomware incidents worldwide, a 34% increase over the same period in 2024 (Cybersecurity News, 2025). But the raw numbers tell only part of the story; what changed more significantly was how attackers maximized impact.
The Asahi Group attack in September 2025 illustrates this evolution well. According to SocRadar’s analysis, ransomware spread from corporate IT systems into production environments, forcing the beverage company to halt operations at multiple breweries and soft drink factories. With core ordering and shipping systems encrypted, Asahi reverted to manual processes, including fax machines and handwritten orders. The company reported a sharp drop in soft drink sales, with recovery projected to extend into early 2026 (SocRadar, 2025). This wasn’t an attack on data. It was an attack on the ability to do business.
The Jaguar Land Rover incident followed a similar pattern. After attackers compromised systems in what appears to have been a multi-stage operation involving both data theft and operational disruption, the automaker shut down production globally. Plants in the UK and other countries stopped producing vehicles. Industry analysts estimated the broader economic impact in the billions when considering the effect on suppliers and the wider automotive ecosystem (SocRadar, 2025).
Critical infrastructure sectors, including manufacturing, healthcare, energy, transportation, and finance; faced heavy targeting throughout 2025. The targeting is strategic. These industries have low tolerance for downtime, complex operational dependencies, and regulatory pressures that increase willingness to pay. When production lines stop, when patients can’t receive care, when shipments can’t move, the pressure to restore operations overwhelms other considerations.
Manufacturing saw the sharpest increase, with 1,156 incidents in 2025, a 32% jump from 2024. The sector has maintained its position as the most targeted industry for two consecutive years, accounting for 19.3% of all ransomware cases (NordStellar, 2025). Construction followed with 443 incidents, representing significant growth as attackers recognized the industry’s combination of valuable project data and limited operational resilience.
Why SMBs Face Disproportionate Risk
Over two-thirds of ransomware attacks between 2024 and 2025 targeted businesses with fewer than 500 employees. Attackers view smaller companies as easier targets that pay faster.
Ransomware was involved in 88% of breaches in small and mid-sized businesses (SMBs) in 2025, compared to 39% of breaches at larger organizations (Verizon, 2025). SMBs with up to 200 employees and revenues up to $25 million experienced the highest concentration of attacks (NordStellar, 2025).
The reasons are practical. Smaller organizations often lack dedicated security staff and operate with limited cybersecurity budgets. They’re more likely to rely on outdated software, have minimal security monitoring, and depend on external vendors for IT support. When attacked, they’re more likely to pay ransoms quickly to avoid business disruptions because they simply can’t absorb extended downtime.
The M&S attack, despite targeting a major retailer, offers lessons directly applicable to smaller businesses. The attack began with social engineering: an attacker impersonated an M&S employee and convinced a third-party help desk to reset credentials. No sophisticated exploit required. The vendor, operating without robust verification procedures, granted access that ultimately enabled £300 (~$410) million in damages (BlackFog, 2025).
For smaller businesses that often rely more heavily on vendors for IT services, this third-party risk is amplified. Your security posture is only as strong as the weakest link in your vendor chain. When a payroll provider, IT support company, or software vendor is compromised; that breach extends to every business they serve.
The financial asymmetry makes the situation worse. Large enterprises can absorb operational disruption while recovering. For an SMB, six weeks without online ordering or several days without production capability can be genuinely existential. The M&S attack is projected to reduce their annual profit by £300/$410 million; that’s a significant hit for a company of their size but not fatal. The same percentage impact on a business with $10 million in revenue could mean closure.
Building Operational Resilience Beyond Data Backup
Your disaster recovery plan probably covers fires and floods. But does it account for six weeks without your core business systems?
Traditional business-continuity planning focuses on data recovery. Back up your files, have redundant systems, and you can restore after a disaster. Ransomware attacks that target operations require a fundamentally different approach because they don’t just threaten your data; they threaten your ability to function while data is being restored.
Start by mapping your operational dependencies. Which systems genuinely can’t go down without stopping revenue? For a manufacturer, this might be production control systems, quality management databases, and shipping coordination platforms. For a professional services firm, it might be project management tools, time tracking systems, and client communication channels. For any business with physical products, inventory management and order processing are critical paths.
Then ask yourself: what manual workarounds exist for each critical function? Asahi reverted to fax machines and handwritten orders. It was painful and slow, but it allowed some orders to continue flowing. M&S physical stores remained operational even as their online presence went dark. Having thought through manual alternatives before an attack, even if they’re inefficient, gives you options when systems fail.
Network segmentation takes on new importance when the goal is operational resilience. Production systems that control manufacturing equipment shouldn’t share network pathways with email servers. If ransomware encrypts your corporate network, segmented operational technology can continue functioning while you recover. The Asahi attack spread from IT to production precisely because those boundaries didn’t exist or weren’t enforced.
Vendor security requirements deserve serious attention in light of how many major attacks have originated with third parties. The M&S breach came through a vendor help desk. Require verification procedures for credential resets. Ensure vendors implement multi-factor authentication (MFA). Include security requirements in contracts, not as legal theater, but as genuine operational protections. The cost of vendor due diligence is trivial compared to the cost of a vendor-enabled breach.
Finally, incident response speed matters more than ever. Organizations take an average of 241 days to identify and contain breaches (IBM, 2025). When attacks target operational systems, you don’t have 241 days. You have hours before the impact becomes severe and days before it becomes potentially catastrophic. Practiced response procedures with clearly defined roles, tested on a regular basis, compress that timeline dramatically.
The 48-Hour Operational Resilience Assessment
You can’t fix everything immediately, but you can identify your biggest operational vulnerabilities in two days of focused attention.
Day one focuses on identifying what matters most. List every system that directly touches revenue: order processing, production scheduling, shipping coordination, payment processing. List every system required for your core service delivery. Then list every third party with access to your network—whether through direct connections, remote support tools, or credential access. Finally, identify any single points of failure: systems where one component down means the whole function stops.
This exercise often reveals surprises. Businesses discover dependencies they hadn’t explicitly recognized. A manufacturing company might realize their entire production schedule depends on one database that hasn’t been tested for recovery. A professional services firm might find that their project delivery process would halt completely if their collaboration platform went offline.
Day two stress-tests your recovery assumptions. Pick one critical system and actually attempt to restore from backup, following your documented procedures with the team members who would handle a real recovery. Time how long it takes. Note what fails. Identify any systems that have no tested recovery path at all. Ask the hard question: if this system was encrypted tomorrow morning, what would we actually do in the first four hours?
The goal isn’t to fix everything in 48 hours. It’s to know where you’re most vulnerable so you can prioritize remediation intelligently. The business that knows their backup restoration actually takes 72 hours instead of the assumed 8 hours can make informed decisions about their risk tolerance and resource allocation.
Protecting Operations, Not Just Data
M&S, Jaguar Land Rover, and Asahi Group aren’t technology companies. They’re a retailer, an automaker, and a beverage producer. Ransomware groups don’t discriminate by industry because they’ve learned that operational disruption creates payment pressure regardless of what you sell. A construction company unable to access project specifications faces the same pressure as a hospital unable to access patient records.
The question for every business is no longer just “is our data backed up?” It’s “can our business function while we recover?” Companies that can answer “yes” have thought through manual workarounds, segmented their critical systems, tested their actual recovery capabilities, and considered the vendor relationships that might become attack vectors.
For businesses already working with IT providers or managing internal teams, this operational resilience conversation often reveals gaps that neither party had explicitly addressed. Co-managed arrangements can be particularly effective here because they combine the internal team’s knowledge of operational dependencies with specialized security expertise of an external provider that’s focused on threat-landscape awareness. The combination matters because operational resilience requires both understanding the business and understanding the threat.
Test Your Operational Awareness
Wondering how your operational resilience would hold up against the attacks making headlines? Sagacent Technologies helps businesses identify their critical dependencies and build practical response capabilities before attackers force the conversation. If you’d like to discuss where your operations might be most vulnerable, contact Sagacent for a confidential conversation.
Glossary of terms
- Operational Technology (OT): The hardware and software that controls physical processes: manufacturing equipment, building automation systems, production lines, HVAC controls. Unlike IT systems that handle information, OT systems make things happen in the physical world. As these systems become increasingly connected to networks, they become reachable by attackers who previously could only target data.
- Double Extortion: The standard ransomware model now involves two threats: encrypting your systems so you can’t operate, and stealing your data with threats to publish it publicly if you don’t pay. Even if you can restore from backups and get operations running, the stolen data gives attackers ongoing leverage. This is why data protection and operational resilience both matter.
- Recovery Time Objective (RTO): The maximum time your business can survive with a critical system offline before the impact becomes unacceptable. If your ERP system has a 24-hour RTO but your actual tested recovery takes five days, you have a gap that ransomware attackers will exploit. Knowing your actual recovery times, not assumed times, is foundational to operational resilience.
Extra Reading
- NordStellar Ransomware Statistics 2025 (Incident volumes and industry targeting)
- Verizon 2025 Data Breach Investigations Report (SMB ransomware involvement)
- VikingCloud Ransomware Statistics 2026 (Cost analysis)
- Cybersecurity News Ransomware Recap 2025 (Attack trends and critical infrastructure targeting)
- SocRadar Top 10 Ransomware Attacks 2025 (Asahi and JLR case studies)
- BlackFog M&S Breach Analysis (Attack timeline and methodology)
- IBM Cost of a Data Breach Report 2025 (Detection and containment timeframes)