It usually starts on an ordinary morning. Someone tries to open the price list and it will not open. Then the invoice folder will not open. Then nothing on the shared drive opens, and there is a plain text file on the desktop with an email address and a deadline. No alarm, no flashing skull on the screen. Just a normal Tuesday that stops working.
Most reporting about a cyber attack in Hong Kong focuses on banks, airlines and hospitals, which is why owners of ten-person firms assume this is not their problem. The data says otherwise. Verizon's 2024 Data Breach Investigations Report found that 88% of breaches at small businesses involved ransomware or extortion. For a small firm, this is close to the only kind of attack worth planning for.
What ransomware actually is
Ransomware, 勒索軟件 in Chinese, is software that scrambles your files so you cannot open them, then asks for money to unscramble them. Picture someone letting themselves into the shop overnight, changing every lock in the place, and leaving a note with a price for the keys.
There is a second half that owners often miss. Before locking anything, most groups quietly copy your files out first. Customer lists, staff ID card scans, signed contracts, bank details. So a business with perfect backups still has a problem, because the threat is no longer only "you cannot get your files back". It is also "we will publish them".
That changes what good preparation looks like. Backups solve the locked door. They do nothing about the copy that already left the building.
How it usually gets in to a small firm
Almost always through one of three doors, and none of them are clever.
Someone clicks something. An email that looks like a supplier invoice, a courier notice, or the boss asking for an urgent payment before a flight. HKCERT handled 12,536 security incidents in Hong Kong in 2024, the highest figure in five years, and roughly 62% of those were phishing, up 108% on the year before. The quality has changed as well. IBM has noted that AI can produce a convincing phishing email in about five minutes, against roughly sixteen hours to write one by hand. The old advice about spotting clumsy English no longer protects anyone.
Something is out of date. An old server in the back room, a PC nobody has restarted since 2022, a website running a plugin last updated years ago. Attackers scan the entire internet for known weaknesses. They are not choosing you, they are checking everyone at once and seeing who answers.
A remote login is weak. Since the pandemic, many small firms left a way to reach the office computer from home. That is a door facing the internet, and very often the only thing guarding it is one password that has never been changed. This is one of the most common ways a 黑客攻擊 begins, and it needs nobody to click anything at all.
What the days after actually look like
The first day is not really about technology. It is about the fact that nothing works. The point of sale system, the booking sheet, the accounts package, the shared drive. Staff arrive and there is nothing for them to do. You write orders on paper and hope you can reconcile them later.
Day two often brings the worst surprise: the backup drive was plugged into the same network, so it was encrypted too. Someone then has to work out what was copied out, which usually means paying an outside firm to look, because you cannot tell from the inside.
After that it stops being an IT problem. You have to decide what to tell customers whose data may be involved. Hong Kong does not legally force you to report a breach, but the Privacy Commissioner recommends notifying the affected people and the office, and customers who hear about it from somewhere else react far worse than customers you rang yourself. You report to the police, you speak to your bank if payment details are in there, and you find out whether your insurance covers any of it.
Very few small firms are back to normal in a day. Two to four weeks of degraded trading is realistic, and most of that cost is not the ransom. It is staff being paid to wait, orders that quietly went to a competitor, and a month of your own attention spent here instead of on the business. The widely quoted IBM figure of USD 4.88 million as the average cost of a data breach in 2024 is a global average dominated by very large organisations, so do not read it as your bill. Read it as the reason attackers keep doing this.
Why paying is not a clean solution
Paying looks like the fast route out. It rarely is.
The decryption tool you get back is written by criminals, and it is often slow, partial, or fails on large files. Recovery still takes days, and you still have to rebuild the machines, because you cannot trust a computer somebody else controlled.
Paying also does not delete the copy of your data. You are buying a promise from an anonymous party, with no way to verify it. Some firms have paid and been approached again months later.
There is a legal edge as well. Sending money to an unknown overseas party can put you on the wrong side of sanctions and anti-money-laundering rules, and your bank will have questions.
And the hole is still open. If a weak remote login let them in on Monday, it is still there on Friday unless someone actually closes it.
What a non-technical owner can arrange this month
None of this requires you to understand the technology. It requires you to ask for specific things and check they were done.
- Keep one backup that is disconnected. An external drive unplugged after each backup, or a cloud backup with its own separate login. Then restore one real file from it this month, to prove it works.
- Turn on two-step login for company email and for any remote access. This single step stops most account takeovers.
- Agree one office rule: any request to change bank details or send money urgently is confirmed by phone, on a number you already had, never the number in the email.
- Ask whoever manages your systems for a written list of anything still running that the manufacturer no longer supports, with a date to replace it.
- Make sure staff who leave lose their access the same week, not eventually.
Five items. A morning of phone calls and one follow-up.
Know what you look like from the outside
Attackers see your business from the outside first, the way someone sizing up a shop looks at the front door. What is visible there decides whether you look easy.
Our own scan of 214 Hong Kong business websites found an average exposure score of 41 out of 100, where 0 means nothing is exposed and 100 means wide open. 72% had at least one finding we rate high or critical. 62% had no DMARC record and 35% had no SPF record, which in plain terms means anyone can send email that appears to come from the company's own address. That is exactly how a convincing fake invoice reaches your accounts clerk. And 17% published the owner's personal name and contact details in public domain registration records, which is where a targeted email gets the specific detail that makes it believable.
None of that is visible from your desk, and most of it is fixable in an afternoon by whoever already looks after your website.
If you would like to see what your own business currently looks like from the outside, our free website security check reports exactly that.