Ransomware Protection for Mid-Market Companies: The Practitioner's Guide
TL;DR: Ransomware protection for mid-market companies (100 to 500 employees) comes down to five controls done well: EDR on every endpoint, MFA on every identity, immutable backups following 3-2-1, network segmentation, and a tested incident response plan. IBM's 2024 Cost of a Data Breach Report puts the average ransomware incident at $4.91 million. The stack below costs a fraction of that.
This article gives you a tiered framework with real tool names, real prices, and a 72-hour response runbook. No fluff.
Why Mid-Market Companies Are the Sweet Spot for Ransomware Gangs
You're caught in the middle. Too big to be ignored, too small to fund the security org that a Fortune 500 runs. Ransomware-as-a-Service (RaaS) affiliates know this. Groups like LockBit, BlackCat, and their successors operate on a franchise model: the core developers build the malware, affiliates buy in and target companies where payouts beat the effort.
A 50-person dental practice pays small. A 5,000-person enterprise has a SOC. A 250-person manufacturer with $80M revenue, 1099 contractors, and one IT director? That's the target profile. The Verizon 2024 DBIR found that 62% of ransomware victims fell into the SMB and mid-market band.
Compliance pressure compounds the risk. If you're in healthcare (HIPAA), defense supply chain (CMMC), or selling to enterprise (SOC 2), a ransomware event isn't just downtime. It triggers mandatory breach notifications, audit failures, and contract clauses you'd rather forget.
CISA's StopRansomware Guide (stopransomware.gov, updated October 2023) is the federal baseline. It's accurate, but it assumes you have staff to read 50 pages of guidance. Most mid-market teams don't.
Tier 1 Controls: Where to Spend First if Budget Is Tight
If you do nothing else this quarter, do these four things.
MFA on every identity. Stolen credentials are the initial access vector in roughly 80% of breaches (Verizon DBIR 2024). MFA blocks the attack before EDR ever fires. Two realistic options: Okta Workforce Identity ($6/user/month for SSO + Adaptive MFA) or Microsoft Entra ID P1 ($6/user/month, free if you already have M365 E3). If you're already in Microsoft's stack, Entra is the obvious pick. If you're hybrid SaaS, Okta's app catalog is hard to beat. See our multi-factor authentication best practices guide for rollout sequencing.
EDR on every endpoint. Legacy antivirus loses to living-off-the-land techniques because attackers use signed Windows binaries (PowerShell, WMI, PsExec) that AV won't flag. CrowdStrike Falcon Pro runs ~$60 to $100 per endpoint per year and ships with managed threat hunting via OverWatch. SentinelOne Singularity Core runs ~$50 to $80 per endpoint per year and includes one-click rollback for ransomware encryption events. Either is fine. Pick the one whose console your team will actually log into. Our endpoint protection platform selection guide breaks down the differences.
Patch management on a cadence. The 1-10-60 rule (detect in 1 minute, investigate in 10, contain in 60) collapses when half your fleet is two months behind on patches. Automox or NinjaOne (~$3 to $6 per endpoint per month) automates third-party and OS patching. Set a 7-day SLA for critical CVEs.
Immutable, air-gapped backups. This is the difference between a bad week and bankruptcy. Follow the 3-2-1 rule: 3 copies of data, on 2 different media, with 1 stored offsite. Veeam Data Platform (~$800 to $1,200 per year for 10 workloads) is the mid-market standard, and its immutable repository on hardened Linux or object storage means ransomware can't encrypt your recovery point even if it lands on the backup server. For a full vendor and contract guide, see our backup and disaster recovery services buyer guide.
Tool sprawl is the quiet tax. Mid-market stacks routinely carry a dozen or more security products with overlapping coverage, and the licensing adds up long before anyone audits whether three of them are doing the same job.
Tier 2 Controls: Add These Before Your Next Audit or Insurance Renewal
Once Tier 1 is real and documented, these are next.
Network segmentation. If one VLAN gets encrypted, the others stay up. This is a CMMC Level 2 requirement (AC.L2-3.1.3, "Separate the duties of individuals to reduce the risk of malevolent activity") and a HIPAA addressable safeguard. Minimum viable: separate production, corporate, guest, and IoT VLANs with firewall rules between them. Cato Networks bundles SASE plus segmentation if you're replacing aging firewalls anyway.
SIEM for detection and log retention. EDR sees endpoints. It doesn't see your firewall, your M365 audit log, or your Okta sign-in events correlated together. Splunk Cloud runs ~$2,000 to $4,000 per month at mid-market ingest volumes. Microsoft Sentinel is consumption-based and usually lands at ~$100 to $300 per day for the same workload, and it's much cheaper if you're already in M365 E5. Pick Sentinel for Microsoft shops, Splunk for heterogeneous environments.
Zero Trust Architecture principles. ZTA isn't a product. It's three rules: verify every identity, enforce least privilege, segment lateral movement. In practice for mid-market, that means MFA + conditional access + segmented networks + privileged access workstations for admins. Maps cleanly to NIST CSF 2.0 PR.AA controls.
Cyber insurance alignment. Underwriters now require MFA, EDR, tested backups, and a documented IR plan as minimum controls. Miss one and you'll see exclusions, sublimits, or a 40% premium hike at renewal. The full picture is in our cyber insurance requirements 2026 breakdown.
Tool Consolidation: Cut Sprawl Without Cutting Coverage
The three-person IT team can't manage twelve consoles. Context-switching between tools blows past the 1-10-60 benchmark before the analyst even logs in.
Two consolidation plays work for mid-market:
Platform consolidation. CrowdStrike Falcon now covers EDR, identity threat detection, and threat intelligence in one console. SentinelOne Singularity adds cloud workload protection and ITDR. Cato Networks collapses SD-WAN, firewall, segmentation, and threat detection into one SASE stack.
Anti-data exfiltration (ADX). This is an emerging category worth knowing about. BlackFog and Halcyon focus specifically on blocking data exfiltration before encryption, which is the leverage modern ransomware crews use even if your backups are clean. Add this layer once Tier 1 and 2 are solid, not before.
A realistic consolidated stack for a 200-person company:
- CrowdStrike Falcon Pro: ~$15,000/year
- Entra ID P1 (included in M365 E3): bundled
- Microsoft Sentinel: ~$45,000/year
- Veeam Data Platform: ~$8,000/year
- Automox patching: ~$10,000/year
- Cato Networks SASE: ~$30,000/year
Total: roughly $108,000/year, or about $540 per employee. Compare that to a single ransomware event averaging $4.91M and the math gets simple.
The 72-Hour Ransomware Response Runbook
This is the part most articles skip. Prevention is half the work. Response is the other half.
Hour 0 to 4 (Contain). Isolate affected endpoints from the network. Do not power them off if you'll need forensic images. Revoke active sessions in Okta or Entra. Disable compromised accounts. Page your IR retainer or MSP. Preserve EDR, firewall, and DNS logs.
Hour 4 to 24 (Assess). Identify patient zero and the initial access vector. Determine blast radius: which data, which systems, which customers. Verify backup integrity in an isolated test environment. Engage legal counsel before any ransom communication. Open your cyber insurance policy and check the notification deadline (usually 24 to 72 hours).
Hour 24 to 48 (Recover). Restore from verified immutable backups using Veeam or equivalent. Rebuild from known-good images. Do not clean infected systems in place, you'll miss persistence. Test restored systems in a segmented network before reconnecting to production.
Hour 48 to 72 (Harden and Notify). Patch the exploited vulnerability across the fleet. Rotate every privileged credential and service account. File required notifications: HIPAA gives you 60 days from discovery (45 CFR §164.412), CMMC requires DIBNet reporting, and state breach laws vary from 30 to 90 days. Document the full timeline for the insurance claim.
CyberStar publishes our IR SLA publicly. If you get breached on a Thursday night, we're on-site Friday morning. Competitors won't put that in writing.
The Mandiant M-Trends 2024 industry median for dwell time before detection is 10 days. Pulling under that comes from tuning SIEM rules rather than shipping vendor defaults. Every MSP has a SOC. Not every SOC is actually watching.
Mapping Controls to SOC 2, HIPAA, and CMMC
Compliance and ransomware protection are the same budget, not two.
- SOC 2 Type II: EDR maps to CC6.8 (malware detection). Immutable backups map to A1.2 (recovery). MFA maps to CC6.1 (logical access). See our SOC 2 readiness playbook for evidence requirements.
- HIPAA Security Rule: Network segmentation supports §164.312(a)(1) Access Control. Backups support §164.308(a)(7) Contingency Plan. IR plan supports §164.308(a)(6) Security Incident Procedures.
- CMMC Level 2: 110 practices from NIST SP 800-171. Key ransomware-relevant controls include IR.L2-3.6.1 (incident response capability), RA.L2-3.11.1 (risk assessments), and SI.L2-3.14.1 (malicious code protection).
HIPAA compliance isn't a checkbox. We audit our Nashville healthcare clients quarterly, not annually. Why? Because the OCR doesn't care that you were compliant in January if your firewall rules drifted in March. Steady quarterly upkeep beats annual panic-mode remediation on both cost and audit outcome. We run the same model for our Charlotte cybersecurity and Tampa cybersecurity clients.
FAQ
How much does ransomware protection cost for a 200-person company? A reasonable annual range is $90,000 to $130,000 covering EDR, MFA, SIEM, immutable backups, patching, and SASE. That's about $450 to $650 per employee per year.
Should we pay the ransom? No. The FBI advises against payment (IC3 advisory, ongoing). Decryption keys often don't work. Re-infection rates run high. And OFAC sanctions exposure is real if the threat actor is on the SDN list. Focus your money on backups and IR retainers instead.
What's the difference between EDR and traditional antivirus? AV matches file signatures. EDR watches process behaviour, parent-child relationships, memory injection, and lateral movement, then correlates across endpoints. AV catches known malware. EDR catches what attackers actually do in 2025.
Does cyber insurance cover ransomware if we don't have MFA? Mostly no. Most carriers now exclude or sublimit ransomware claims when minimum controls (MFA on email and remote access, EDR, tested backups, documented IR plan) weren't in place at the time of the incident. Some won't bind a policy without them at all.
How long does ransomware recovery take without a tested backup plan? Sophos State of Ransomware 2024 puts the median recovery at 1 month for organisations using backups, and longer when backups weren't tested or were also encrypted.
If you're within 90 days of a SOC 2 or HIPAA audit and don't know where you stand on ransomware controls, book a free 30-minute audit with Mike. We'll tell you exactly which gaps your current stack leaves open, with no sales theatre.
Know exactly where your security stands.
Get your free security assessment →Know exactly where your security stands.
Most IT directors are one audit away from a nasty surprise. We remove the guesswork.
- A full assessment of your environment, mapped to SOC 2 and HIPAA.
- A prioritised remediation plan you can act on, whether you hire us or not.
- Managed protection across endpoints, data, and incident response.
- Fixed monthly pricing, so there are no per-incident surprises.
The assessment is free, and the plan is yours to keep.