Cheapskates wouldn't pay for security help, got hit by ransomware, and went bust months later
Ransomware and phishing aren’t just buzz‑words for the big‑ticket enterprises; they’re the daily nightmare for the small‑shop down the road. When “We Got a Guy” Becomes “We Got Ransomed” The first story is a textbook example of how complacency kills.
Ransomware and phishing aren’t just buzz‑words for the big‑ticket enterprises; they’re the daily nightmare for the small‑shop down the road. The two cases shared by Dave Hatter of Intrust IT lay bare how cheap‑skate attitudes toward security can sink a business faster than any market downturn. As a founder who’s been wiring up hosting infrastructure for a decade, I’ve seen the same patterns repeat: an outdated server, a single‑point‑of‑failure backup, and a belief that “we’re too small to be a target.” The reality is that the same ransomware gangs that hit multinational banks will happily lock down a local construction firm if there’s money on the line.
When “We Got a Guy” Becomes “We Got Ransomed”
The first story is a textbook example of how complacency kills. A small construction company called Intrust for a security assessment, only to have the proposal shot down by the owner who trusted a family‑friend for IT support. The owner’s exact words, as quoted by Hatter, were “We got a guy, my brother’s uncle’s cousin does my IT, don’t need you guys.” That sentiment is echoed across countless SMBs that think a one‑person shop can fend off sophisticated attackers.
Three weeks later the same firm was on the receiving end of a ransomware hit. Their only Windows server was old and unpatched, housing all critical data. The backup strategy was equally naïve: a single external drive physically attached to the same server. When the ransomware encrypted the server, it also encrypted the backup drive, leaving the business with no way to pay employees or settle invoices. Hatter’s account makes it clear the firm “couldn’t pay their employees” and “didn’t know who owes them money.” Within months the company folded.
For independent hosting providers, this is a cautionary tale. Relying on a single on‑premise backup is a recipe for disaster. Off‑site replication, whether via a reputable cloud provider or a geographically separate data centre, is non‑negotiable. The cost of a proper backup solution is pennies compared to the loss of revenue and reputation when a ransomware lockout hits.
The Phishing Playbook Gets Smarter
The second incident shows how phishing has evolved from misspelled emails to highly targeted, AI‑crafted spear campaigns. Attackers compromised an executive’s Microsoft 365 account at a landscaping firm and used it to send fraudulent RFP requests to a construction partner. The emails were immaculate—no grammar errors, a matching return address, and a button that appeared to download a proposal.
When the recipient clicked the button, they were redirected to a counterfeit Microsoft 365 login page that looked identical to the real one but lived on a non‑Microsoft domain. Even the two‑factor authentication prompt was replicated, capturing both password and the one‑time code. Behind the scenes, the attackers performed a classic man‑in‑the‑middle, forwarding the credentials to Microsoft so that the legitimate service sent an SMS to the victim, which the attacker then harvested.
This level of sophistication means traditional “look for the typo” defenses are obsolete. The attack leveraged a trusted relationship—an email from a known contact—making it virtually impossible for a user to spot the fraud without additional safeguards.
Why “Best Practices” Fail in Production
Both stories underline a gap between textbook security advice and what actually works on the ground. The construction firm’s “backup on the same server” is a textbook no‑no, yet it’s still being practiced. The phishing case demonstrates that relying on password‑plus‑SMS 2FA is no longer sufficient; attackers can hijack the second factor by exploiting the authentication flow itself.
In my own hosting operations, I’ve seen “best practice” checklists that ignore the real threat model: they assume a perimeter defense will stop everything, ignoring insider compromise or credential theft. The reality is that once an attacker has a valid credential, they can pivot inside any environment that trusts that identity. The only way to blunt that is to adopt phishing‑resistant MFA—hardware security keys or platform‑based passkeys—so that a stolen password and SMS code are useless without the physical token.
The Real Cost of Ignoring Security
Financially, the construction company’s downfall illustrates the hidden cost of “cheap” security. The owner dismissed Intrust’s proposal as “too expensive,” yet the ransomware attack likely cost the business far more in lost payroll, unpaid invoices, and eventual closure. The intangible loss—brand trust, employee morale, and the founder’s reputation—cannot be quantified but is devastating.
For hosting providers, the lesson is clear: under‑investing in security is a false economy. Clients will look for the cheapest hosting tier, but if you cannot guarantee data integrity and availability, you’ll lose them to competitors who can. The margin you protect by skimping on security is quickly eroded by the fallout of a breach.
Tools That Actually Work
Hatter’s client survived the phishing onslaught thanks to a home‑grown solution called TarBot, which runs inside Microsoft 365 and leverages Entra ID P2 to flag anomalous logins. The tool “throws off a bunch of telemetry… that allows… to say, this is an anomalous login, revoke the token, and make the user log in again.” While TarBot is not the only product in the market, its success shows that real‑time behavioural analytics can stop attacks within minutes.
For independent providers, integrating similar detection capabilities—whether via Microsoft’s native conditional access policies, third‑party SIEM tools, or custom scripts—adds a critical layer of defense. The goal is to surface suspicious activity before the attacker can exfiltrate data or move laterally.
Actionable Steps for SMBs and Hosting Providers
First, audit your backup architecture. Ensure backups are immutable, stored off‑site, and tested regularly. Second, enforce phishing‑resistant MFA across all privileged accounts; hardware keys are cheap at scale and far more reliable than SMS codes. Third, deploy real‑time login analytics—whether through Microsoft’s Entra ID P2, a third‑party solution, or an in‑house script—to detect and block anomalous sessions.
Finally, educate users on the new reality of phishing. The old rule “look for bad grammar” no longer applies. Conduct regular simulated phishing drills that mimic the sleek, AI‑generated emails described by Hatter, and reinforce the need to verify login URLs and MFA prompts. A security‑aware workforce is the last line of defence.
Bottom Line: Security Is a Business Decision, Not an After‑thought
These two cases from Intrust’s column are not isolated anecdotes; they are a microcosm of the broader threat landscape that small and medium businesses face daily. The choice to skimp on security, whether out of pride or cost‑concern, directly translates into operational risk and potential business failure. As a founder who’s built and run hosting infrastructure for years, I can say with certainty that the price of a robust backup and MFA strategy is a fraction of the loss incurred when ransomware or a phishing breach shuts you down.
In the end, the decision is simple: treat security as a core component of your service offering, invest in proven tools, and never assume you’re too small to be a target. The cost of doing so is far less than the price of being pwned.
— Allan Ali, Founder
This article was produced with AI-assisted research and editorial support. Reporting is based on the source material cited below. Sources: The Register; theregister.com; Global1.News (10 October 2026).
By Allan Ali, Global1.News
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)