Zscaler’s ThreatLabz team tracked 351 victims across 334 organisations hit by a single ransomware campaign over one month. The pattern in who got compromised is worth ten minutes of anyone’s time, because it cuts against the core assumption most small businesses still operate on: that ransomware primarily goes after IT admins with the keys to the kingdom.
It doesn’t—not primarily. It goes after managers.
What the data shows
Sixty-two percent of victims held a manager-level title or above. Three-quarters worked in one of five business functions: accounting and finance, sales, operations, HR, or marketing. By industry, half worked in either industrials or IT services. The average victim was 46 years old, with Gen X making up the largest single generational share. The researchers attribute this less to age itself and more to where that generation sits on the org chart: established, mid-to-senior, and holding roles with direct business access.
For two decades, IT departments have treated “who has access” as a technical question: who holds the server passwords, who can install software, and who can reach every folder. Attackers are asking a fundamentally different question: who in this business can move money, approve a payment, or hand over a customer list—regardless of their system permissions?
An accounts payable manager doesn’t need domain admin rights to be worth compromising. They need access to invoices, payment approvals, and vendor banking details—which every accounts payable manager has by default. The same applies to a sales manager sitting on pricing data and live deals, or an operations manager coordinating across suppliers.
Why this matters more for small businesses
The ThreatLabz report is written for large enterprise organisations with dedicated security operations centers. Most small businesses don’t have that, and don’t need it: a five-person consultancy doesn’t require the monitoring infrastructure of a five-thousand-person industrial firm. But the underlying finding transfers directly—and matters even more at small scale.
In a small business, the “manager” and the person with the widest business access are almost always the same individual. Crucially, there is no dedicated security team standing between that account and everything else. The office manager who handles bookkeeping, arranges travel, and runs the shared inbox holds one of the most powerful accounts in the company, whether anyone recognises it or not. If that account is compromised, there is frequently nothing else standing between an attacker and the entirety of the business’s Microsoft 365 environment.
What reduces the risk at small scale
The report’s own top recommendations—network segmentation, continuous SOC monitoring, and inline AI detection tools—aren’t wrong; they are simply built for a different headcount and budget. The controls that translate directly to a small business include:
1. Conditional access, properly configured. This remains the single highest-leverage control available in a standard Microsoft 365 Business Premium licence. Restrict sign-ins to compliant, managed devices and enforce strong multi-factor authentication (MFA). That step alone eliminates the majority of automated account-takeover pathways described in the research.
2. Know which accounts matter most, and protect them first. You don’t need a complex access-review programme. You need to identify the two or three people in the business who can approve invoices, transfer funds, or export sensitive client data. Ensure their accounts have the strict security controls applied—not an afterthought because they are “admin staff” rather than IT personnel.
3. Focus training on impersonation, not just link-clicking. The research highlights attackers impersonating internal IT support over Teams or Slack to trick users into handing over credentials. In a small business context, the threat is usually social engineering: an attacker impersonating Microsoft, a trusted supplier, or a company director requesting an urgent payment. Anyone with financial or data authority must follow an out-of-band verification process (verifying via a second, trusted channel) before acting on unusual requests.
4. Back up somewhere the compromised account cannot reach. The research noted multiple organisations where several employees were compromised in a single attack. If your backup system relies on credentials accessible from a compromised manager’s account, an attacker can wipe or encrypt those backups before you notice the intrusion. Backups must be isolated, immutable, and managed via separate, dedicated administrative credentials.
None of these steps require new security platforms or a major capital budget. They simply require treating the office manager’s account with the same security priority as the IT administrator’s—because that is precisely how attackers are treating them.