- Client files stolen.
- Patient care interrupted.
- Tax records exposed.
- Systems taken offline.
- Regulators asking questions.
- Clients demanding answers.
That is the ransomware reality facing professional services firms in 2026.
The risk is no longer theoretical. In September, ransomware and data-extortion activity attributed to SilentRansomGroup reportedly targeted major U.S. law firms, including Greenberg Traurig and Holland & Knight. In July, accounting firm Todd, Hamaker & Johnson suffered an Akira ransomware incident involving reported theft of client and employee data. In August, Jones, Little and Co., CPAs was listed by the Dark Project group in an unverified ransomware claim.
Different organizations. Different attackers. Same lesson:
The cost of prevention is measurable. The cost of being unprepared is not.
The Ransomware Math Is Getting Worse
Ransomware math is simple:
Expected loss = probability of attack × total cost of recovery
Both numbers are rising.
Depending on the dataset, ransomware appears in approximately 39% of SMB cyber claims and nearly 90% of SMB breaches. Industry reporting also places average ransomware recovery costs at approximately $1.7 million, excluding the ransom itself.
For a mid-sized firm, downtime alone can exceed $12,000 per day. A healthcare breach can average approximately $7.42 million when investigation, legal costs, notification, remediation, lost business, and operational disruption are included.
These figures are not predictions for every incident. They are risk-planning numbers. They show why “we are too small to be targeted” is no longer a rational strategy.
A basic exposure example
Imagine your firm experiences:
- Five business days of major downtime
- $12,000 in daily lost productivity and revenue
- $150,000 in incident response and forensic expenses
- $100,000 in legal, notification, and consulting costs
- $300,000 in client loss, remediation, and reputational damage
That simplified event already exceeds $610,000, before a ransom is paid and before considering long-term consequences.
If the incident involves sensitive healthcare, financial, or legal information, the exposure can be substantially higher.
The Cost of Paying the Ransom
Paying may seem like the fastest path back to normal operations.
It is not a guaranteed solution.
A ransom payment may provide a decryption key. It does not necessarily:
- Remove the attacker’s access.
- Delete stolen data.
- Prevent publication on a leak site.
- Resolve regulatory obligations.
- Restore lost client confidence.
- Repair compromised systems.
- Recover every damaged or corrupted file.
Modern ransomware groups frequently use double extortion. They steal data first, encrypt systems second, and then threaten to publish sensitive information.
That changes the decision entirely.
You may be negotiating over both availability and confidentiality. Even if your files are restored, your firm may still need to determine what was accessed, which individuals must be notified, and whether reporting obligations were triggered.
Payment also creates uncertainty around sanctions, insurance approval, accounting treatment, and law-enforcement coordination. Any ransom decision should involve qualified legal counsel, your cyber insurer, and experienced incident-response professionals.
The Cost of Not Paying
Not paying does not mean the incident is free.
You may still face:
- Extended downtime
- Emergency technology replacement
- Forensic investigation
- Legal and regulatory review
- Client notification
- Credit monitoring
- Lost billable hours
- Missed court or tax deadlines
- Delayed patient care
- Employee overtime
- Reputational damage
This is why ransomware protection cannot be reduced to a ransom-payment policy. The real objective is to prevent the attack, contain it quickly, and recover operations without allowing the attacker to control your decisions.
Your best negotiating position is not a better ransom negotiator.
It is a secure, tested environment that gives you alternatives.
Why Professional Services Firms Are Prime Targets
Law firms, medical practices, and accounting firms share an uncomfortable combination:
- Valuable information
- High confidentiality expectations
- Time-sensitive operations
- Lean internal teams
- Extensive use of email and cloud applications
- Clients who cannot easily tolerate service interruptions
Law firms: confidentiality has a price
Law firms hold privileged communications, litigation strategy, discovery files, intellectual property, settlement documents, trust accounting information, and personal data.
The reported September 2026 incidents involving Greenberg Traurig and Holland & Knight demonstrate that firm size does not eliminate risk. Public reporting linked both firms to SilentRansomGroup activity, with limited file access and client information reportedly involved. Details remain subject to investigation, but the broader lesson is clear:
Attackers are targeting the data, not merely the server.
Effective law firm cybersecurity must include identity governance, secure file sharing, endpoint security, email protection, MFA, backup, disaster recovery, vendor oversight, and documented response procedures.
That is also why managed IT for law firms should be designed around confidentiality and business continuity: not simply helpdesk ticket resolution.
Medical practices: downtime can affect patient care
A medical practice may depend on its electronic health record, scheduling platform, imaging systems, billing software, phones, and patient portals.
If those systems are unavailable, the impact is immediate.

Healthcare organizations face both financial and clinical consequences. The average healthcare breach cost is often cited at approximately $7.42 million, reflecting the sector’s complex response requirements and the sensitivity of protected health information.
Under HIPAA, your contingency planning must address data backup, disaster recovery, and emergency-mode operations. The U.S. Department of Health and Human Services ransomware guidance emphasizes frequent backups, tested restoration, and appropriate safeguards for systems containing electronic protected health information.
A backup that has never been restored is not a recovery strategy.
It is an assumption.
Accounting firms: financial data and FTC safeguards
Accounting and tax firms hold tax returns, Social Security numbers, payroll records, bank information, financial statements, and identity documents.
The reported Akira incident involving Todd, Hamaker & Johnson illustrates why accounting firms are attractive targets. Attackers reportedly claimed to have stolen approximately 40 GB of data, including sensitive client and employee information.
The Jones, Little and Co. incident, attributed to Dark Project, remains an unverified criminal-group claim. That distinction matters. But even an unverified claim should prompt a serious question:
Could your firm determine quickly whether the allegation was true, what data was affected, and what action was required?
For covered organizations, the FTC Safeguards Rule requires a written, risk-based information security program. Core expectations include MFA, access controls, encryption, security testing, employee training, service-provider oversight, and an incident response plan.
Ransomware prevention and response are not separate from compliance.
They are exactly what regulators expect you to operationalize.
Why Temporary Fixes Fail
“I got a guy.”
“He handles the server.”
“Margaret knows where the backups are.”
These arrangements may work for replacing a printer. They are not enough to manage a modern ransomware event.
Temporary or informal approaches commonly fail because they lack:
-
Complete documentation
No one has a current map of systems, accounts, vendors, and dependencies. -
Continuous endpoint security
Antivirus may be installed, but suspicious behavior is not actively monitored or investigated. -
MFA enforcement
One compromised password can expose email, cloud storage, and financial systems. -
Tested backup and disaster recovery
Backups exist, but restoration time and data integrity are unknown. -
Least-privilege access
Users and vendors retain more access than their roles require. -
Incident response ownership
Staff do not know who to call or what to isolate during the first hour. -
Regulatory documentation
Your firm cannot prove that safeguards were implemented, tested, or reviewed.
Your technology provider may be helpful and trustworthy. That is not the same as having the staffing, tools, specialization, and redundancy required for cybersecurity.
You would not manage a complex medical condition with occasional advice from someone who “knows a little about medicine.” You need the right specialist, the right procedures, and ongoing monitoring.
Your technology deserves the same discipline.
Prevention Costs Less Than Recovery
A mature ransomware protection program should reduce both sides of the equation: the likelihood of a successful attack and the impact when something goes wrong.
That typically includes:
- MFA for email, cloud applications, remote access, and privileged accounts
- Managed endpoint security with detection and response capabilities
- Patch and vulnerability management
- Email security and impersonation protection
- Conditional access and identity governance
- Least-privilege permissions
- Device encryption
- Network segmentation
- Immutable, offline, or otherwise protected backups
- Regular backup restoration testing
- Documented business continuity and disaster recovery
- Security awareness training
- Vendor risk management
- Incident response exercises

The goal is not to purchase every security product available. The goal is to build a coordinated program where each control supports the others.
Internal IT vs. managed IT
Internal management can work for organizations with sufficient staff, expertise, budget, and after-hours coverage.
Potential advantages:
- Direct control
- Familiarity with internal workflows
- Immediate access to business leaders
- Existing knowledge of applications and systems
Potential disadvantages:
- Hiring and training costs
- Employee turnover
- Limited cybersecurity specialization
- Competing support priorities
- Delayed testing and documentation
- Single points of failure
- Limited 24/7 monitoring
A qualified managed services provider offers economies of scale, specialized expertise, predictable costs, standardized processes, and ongoing oversight.
That does not eliminate your accountability. It gives you a broader operating model for managing risk.
Your 2026 Ransomware Checklist
Start with an IT assessment or IT audit that answers these questions:
- Are all users required to use MFA?
- Can you identify every device connected to your environment?
- Are endpoints monitored for suspicious behavior?
- Can a compromised account be disabled immediately?
- Are backups protected from unauthorized deletion?
- When was the last successful restoration test?
- How quickly can critical systems be recovered?
- Do you know which data is subject to HIPAA, FTC safeguards, or contractual confidentiality requirements?
- Do vendors have appropriate access controls and written security obligations?
- Does leadership know exactly what happens during the first hour of an incident?
If you cannot answer confidently, you have an opportunity to replace assumptions with evidence.
A structured IT assessment can identify gaps across identity, endpoints, cloud systems, backup architecture, vendor access, compliance, and recovery.
Final Word
Ransomware is not merely a technical problem.
It is a financial risk. A continuity risk. A compliance risk. A client-trust risk.
For law firms, medical practices, accounting firms, and businesses subject to the FTC Safeguards Rule, the math is increasingly straightforward:
Prevention costs money. Unpreparedness can cost millions.
The right strategy combines ransomware protection, endpoint security, MFA, secure backup, business continuity, disaster recovery, and ongoing managed IT support.
Do not wait for the ransom note to discover whether your systems can recover.
Start with a professional IT assessment, establish your priorities, and build a security program that gives your business a reliable path forward when: not if: something goes wrong.
For additional guidance, review A PC of Mind’s resources on FTC Safeguards compliance and business continuity planning.
This article is for general informational purposes and is not legal, regulatory, insurance, or incident-response advice. Consult qualified counsel and cybersecurity professionals regarding your organization’s specific obligations.