Why Small Firms Are Turning to Outside Analysts to Catch Ransomware Early

ESET argues that pairing threat research with managed detection gives smaller companies a fighting chance against ransomware crews that now industrialise their attacks.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial image, 16:9, full-frame edge-to-edge
Share

Key points

  • ESET is pitching a combined model of threat research and Managed Detection and Response (MDR) aimed squarely at small and mid-sized businesses.
  • MDR means a small firm rents a team of outside analysts who watch its computers around the clock and step in when something looks wrong.
  • Ransomware crews, criminal groups that lock a company's files and demand payment, increasingly target smaller firms that lack in-house security staff.
  • The pitch: intelligence on how specific gangs operate feeds directly into the monitoring, so alerts arrive with context rather than as raw noise.
  • The approach is a response to the ransomware-as-a-service economy, where gangs rent their tools to affiliates and hit hundreds of small victims a year.

Security vendor ESET is making a case that smaller companies can no longer defend themselves with antivirus software alone, and that they need the same kind of intelligence-led monitoring the Fortune 500 has been buying for years.

The argument, laid out in a briefing first reported by BleepingComputer, is straightforward. Ransomware crews now operate like businesses. They have HR, payroll, affiliate programmes and negotiators. A corner-shop accountancy firm in Leeds and a regional hospital in Ohio face the same tooling used against banks.

So what is a small firm supposed to do about it?

What is MDR, in plain English?

MDR stands for Managed Detection and Response. In practice, it means a company pays an outside team of security analysts to watch its computers, laptops and servers day and night. When something suspicious happens at 3am, those analysts see it, decide whether it is real, and either fix it themselves or ring the customer.

Think of it as renting a security guard for your network instead of hiring one. For a firm with 40 staff and no dedicated IT security person, that is often the only realistic option.

Where does threat research fit in?

Threat research is the intelligence side: analysts who spend their days studying how specific criminal gangs work. Which ransomware group uses which login-stealing tool. Which phishing lure, meaning a fake email designed to trick staff into clicking, is doing the rounds this week. Which stolen passwords are on sale on which forum.

ESET's pitch is that this intelligence should feed directly into the monitoring. If researchers know a gang called, say, Akira is currently breaking in through unpatched VPN devices, the MDR team can hunt specifically for that pattern in customer networks before the ransom note appears.

Why the focus on small and mid-sized firms?

Because that is where the volume is. Ransomware affiliates, the freelancers who rent attack tools from the big gangs, are paid on commission. They favour easier targets. A dentist's office with a flat network and no backups pays out faster than a bank with an incident-response retainer.

Leak sites run by groups such as LockBit, Cl0p and Play have listed thousands of victims under 500 employees. Most never make the news. Many quietly pay.

What ordinary customers should take from this

If you are a customer of a small business, a local pharmacy, a family solicitor, a specialist retailer, your data sits on their systems too. When they get hit, your name, address, card details or medical notes can end up on a criminal leak site.

Ask the businesses you deal with whether they have any form of continuous monitoring. It is a fair question. It is also the kind of question that pushes the market in the right direction.

The uncomfortable truth is that no product stops every attack. What matters is how fast someone notices, and whether that someone knows what they are looking at.

© 2026 Threat Vectr