In August 2024, the renowned vodka producer Stoli Group suffered a devastating ransomware attack that crippled its IT infrastructure and forced its U.S. subsidiaries into Chapter 11 bankruptcy.
The attack disabled Stoli’s enterprise resource planning (ERP) system, forcing the company to rely on manual processes for critical operations like accounting.
This disruption not only delayed recovery until 2025 but also prevented compliance with lender reporting requirements, contributing to $78 million in debt and further straining the business.This incident underscores the growing threat ransomware poses to businesses of all sizes. For small and medium-sized businesses (SMBs), the lessons from Stoli’s experience are especially pertinent. While SMBs may not have the resources of large corporations, they are increasingly targeted by cybercriminals due to perceived vulnerabilities.
How SMBs Can Learn from Stoli’s Experience
- Prioritize Regular Data Backups
Implementing a robust backup strategy, such as the 3-2-1 rule (three copies of data on two types of media, with one copy stored offline), can help businesses recover quickly without paying ransoms6. - Invest in Cybersecurity Tools
Comprehensive antivirus software, firewalls, and multi-factor authentication (MFA) are essential first lines of defense against ransomware attacks. - Train Employees on Cybersecurity Practices
Human error is often the weakest link in cybersecurity. Regular training on phishing awareness and safe online practices can significantly reduce risks. - Develop an Incident Response Plan
A well-documented response plan ensures swift action during an attack, minimizing downtime and financial losses. - Limit Access Privileges
Adopt a “least privilege” approach to restrict access to sensitive systems and data, reducing the potential impact of a breach.
Why SMBs Should Act Now
The financial and operational fallout from Stoli’s ransomware attack serves as a stark reminder that no business is immune to cyber threats. For SMBs, a single cyberattack could mean halted operations, loss of customer trust, and even closure. Proactive measures are not just an option—they are a necessity in today’s digital landscape.If you’re unsure where to start or need guidance in strengthening your cybersecurity posture, contact us today.
Our experts can help you implement tailored solutions to protect your business from evolving threats and ensure your operations remain resilient. Don’t wait until it’s too late—secure your future now!
Resource:
Building ransomware resilience on a small business budget
Ransomware ends businesses when recovery is impossible, not when encryption happens. That distinction is the whole strategy, and it is affordable.
- Keep one backup copy offline or immutable. Attackers delete backups they can reach before triggering encryption. A copy that cannot be modified from the production network is what makes recovery possible.
- Restore something every quarter and time it. An untested backup is a hypothesis. Knowing it takes eleven hours to restore your main system changes how you plan.
- Multi factor authentication on remote access and email. Most ransomware arrives through stolen credentials or a phishing message rather than an exotic exploit.
- Limit administrative rights. Ransomware spreads with the permissions of whoever ran it. Ordinary users working as local administrators is how one machine becomes fifty.
- Segment the network so that finance, operations and any production systems are not reachable from a single compromised laptop.
- Decide the ransom question in advance. Discuss with your leadership and counsel now what you would do, because that conversation goes badly under pressure. Paying does not guarantee recovery and does not remove notification obligations.
Write down the first hour too. Who disconnects affected systems, who calls the insurer, who preserves evidence, who talks to staff and customers. Small organizations recover well when somebody has thought about the first hour, and poorly when everybody improvises at once.
Canadian businesses handling personal information should also plan for the privacy side, since a ransomware incident involving personal data can trigger reporting and notification duties even when systems are restored successfully.
The first hour, written down
Most small organizations lose time at the start of a ransomware incident because nobody is sure who decides what. Writing a single page in advance removes that hesitation, and it does not need to be sophisticated.
- Who declares an incident. Name one person and one backup. They do not need technical depth, only the authority to say this is happening and to pull people off other work.
- Who disconnects what. Isolating affected machines quickly limits spread, so decide in advance whether staff are authorized to unplug a machine without asking permission. In most cases they should be.
- Who preserves evidence. Powering a machine off destroys memory contents that can explain what happened. If you have insurance or expect a claim, the insurer’s responders will want the machine isolated rather than wiped.
- Who calls the insurer and counsel. Policies usually require early notice and often require you to use their panel of responders, so this call generally comes before you engage anybody else.
- Who talks to staff and customers. Silence gets filled with speculation. A short honest holding message on day one buys goodwill you cannot buy later.
What recovery actually looks like
Organizations consistently underestimate recovery time because they think of it as restoring files. In practice it is rebuilding systems in dependency order, verifying that restored data is clean, resetting credentials across the environment, and doing all of it while normal work is suspended.
The practical preparation is to write down which systems must come back first and what each one depends on. Payroll may depend on a file server, which depends on directory services, which depends on a specific server being rebuilt first. Knowing that order in advance saves a day, and a day is often the difference between a recoverable week and a serious financial loss.
How Secur-IT Data Solutions can help
We help small and mid sized Canadian businesses build recovery capability that actually works, starting with backups that survive an attacker and restores that have been tested. Where a business wants monitoring but cannot staff it, our managed service provides the out of hours coverage that catches an attack before encryption starts. We work with organizations across Toronto and the GTA as their managed security provider, and we are happy to start with a conversation rather than a quote. Get in touch with our team and we will tell you honestly whether this is something you need help with or something you can close yourself.

Krikor Tengerian is the CEO and founder of Secur-IT Data Solutions, a Toronto-based cybersecurity firm focused on helping Canadian organizations secure their infrastructure and critical systems. With over 25 years of experience across cybersecurity and IT infrastructure, he has supported organizations in hardening networks, protecting critical workloads, and aligning security controls with business and regulatory requirements.
Krikor actively shapes the direction and themes of Secur-IT’s educational content, collaborating with AI tools to structure, refine, and expand articles while providing the real-world context, use cases, and review to keep them accurate and practical for readers. He regularly shares insights on OT security, threat detection, incident response, and Canadian cybersecurity compliance to help industrial and commercial organizations better understand and reduce their cyber risk.



