For a distributor, a carrier, a manufacturer or a dealership group, the real cost of a cyber incident is not the ransom. It is the days the operation cannot run - and most of that cost is decided before the incident, by choices nobody wrote down.
Security coverage talks about data. Operating businesses run on motion: trucks dispatched, lines scheduled, parts ordered, deals funded. When ransomware hits a company like that, the breach headline is beside the point — the event that hurts is the operation standing still while everyone works out who decides what.
In RSM's January 2026 survey of 501 midmarket executives, 96% said they felt good about their security posture. In the same survey, roughly one in four had taken a ransomware attack or demand within the year. Both numbers are real. The gap between them is where operating companies live: confident, busy, and untested.
Not the sophistication of the attacker. Four things, all decided in advance or not at all:
List the five systems the operation cannot run without. For each: who can restore it, has that restore been tested, and what is the paper fallback. Then enforce MFA on finance and admin accounts if it is not already on. None of that requires buying anything, and it moves more downtime risk than most six-figure tools.
If you want the whole picture ranked and costed, that is what the Exposure & Opportunity Review produces. If the question arrived stapled to an insurance renewal, start with what carriers now ask for.