Skip to the main content.
Panzura-Icon-FullColor-RGB@0.75x

Panzura

Our enterprise data success framework allows enterprises to build extraordinary hybrid cloud file and data systems.

architecture-icon

Platforms

Complementary file and data platforms that deliver complete visibility, control, resilience, and immediacy to organizations worldwide.

Layer_1-1

Resources

Find insights, news, whitepapers, webinars, and solutions in our resource center.

Layer_1-2

Company

We bring command and control, resiliency, and immediacy to the world’s unstructured data. We make it visible, safeguard it against damage, and deliver it instantly to people, workloads, and processes, no matter where they are.

10 min read

Panzura Express and Why Single-Site Organizations are the Real Ransomware Target

Panzura Express and Why Single-Site Organizations are the Real Ransomware Target

Table of Contents

Panzura Express and Why Single-Site Organizations are the Real Ransomware Target
21:36

The Firms Most Convinced They're Too Small to Hit Are Getting Hit Most Often. Here's Where the Risk Concentrates Below 300 Employees — and What Panzura CloudFS Changes About Surviving It

Key Takeaways:

  • Ransomware concentrates in the mid-market. Research indicates that 88% of breaches are at small and mid-sized organizations against 39% at large ones. A small firm holds irreplaceable data behind a one-to-three-person generalist IT team and can least afford the downtime and recovery cost.
  • Backups are where recovery fails. Attackers went after backups in 94% of attacks and succeeded 57% of the time. Restore-from-backup as a recovery path fell to 53% of victims in 2025, a four-year low. Scheduled, network-reachable, rarely-tested backups fail when they are needed.
  • Immutable snapshots change recovery from a project to a rollback. CloudFS holds the authoritative copy immutable in object storage with snapshots as often as every 60 seconds. Threat Control adds real-time detection of mass encryption and anomalous access. Panzura Express is packaged for single-site mid-market firms.

This is Part 1 of a 3-part series on Panzura Express. Read Part 2 and Part 3.

There’s an assumption inside a lot of small- to mid-sized firms that ransomware is a big-company problem. The names that make the news run to thousands of employees and hundreds of millions in revenue. The conventional wisdom says if you’re a 200-person engineering firm with one office and two people in IT, you’re too small to be worth the trouble.

The data says the opposite. Verizon’s 2025 Data Breach Investigations Report found ransomware present in 88% of breaches at small- and mid-sized organizations, against 39% at large enterprises. The organizations most convinced they’re immune are the ones getting hit most often.

That inversion is structural. Understanding why it happens tells you most of what you need to know about how to survive it.

Why the risk concentrates below 300 people

Attackers are picking targets according to what they perceived as expected return, and a small- and mid-sized single-site organization scores well on every variable that matters to them.

Let’s start with defense. A firm of 100 to 300 people typically runs a one-to-three-person IT team with few or no dedicated security staff and likely not even a storage administrator. The people keeping the lights on are dedicated generalists doing everything from laptop provisioning to network troubleshooting to putting out fires every afternoon and weekend. Security is a responsibility layered on top of a full plate. That’s not a criticism of the people but rather an honest description of the resource constraints. A three-person team can’t watch everything, and attackers know which things go unwatched.

Now look at the data behind those thin defenses. A mid-sized engineering, architecture, or manufacturing firm holds exactly the kind of information that makes recovery non-negotiable. That includes AEC design files, CAD and CAM assets, as well as case records, media libraries, years of project history. In many instances, it’s the entire operating memory of the business. A firm that loses its active project files loses the ability to deliver the work it’s already paid for.

Put those together and you have the attacker’s ideal target.

  • High-value, irreplaceable data — the operating memory of the business, not a copy of something held elsewhere.
  • Defenses run by people already at capacity — a generalist team with no room to watch everything.
  • An organization that can’t afford downtime — and often can’t afford a security team to prevent it in the first place.

There’s a notable second-order effect. Mastercard’s 2025 survey of more than 5,000 small and mid-sized business owners found that nearly one in five who suffered a cyberattack went on to file for bankruptcy or close. For a mid-sized firm, the stakes are often existential, which is exactly what makes the ransom more likely to get paid.

 And the recovery bill is real money even before anyone considers a ransom. Sophos’s 2025 State of Ransomware study, which surveyed 3,400 organizations hit by ransomware, found that firms with 100 to 250 employees paid an average of $638,536 to recover. That figure excludes any ransom payment entirely. For an organization of that size, a six-figure recovery cost is a threat to the business.

The backup problem nobody talks about until it’s too late

Most small- and mid-sized firms believe they’re covered because they have backups. The truth is that backups are where ransomware recovery typically fails.

The reasons are common:

  • They run on a schedule. Nightly, if you’re diligent, which means the best case after an attack is losing a full day of work across the whole firm.
  • They’re reachable from the same network as the live data. So, the ransomware reaches them, too. Modern attackers hunt for backups specifically and encrypt or delete them before they trigger the visible attack.
  • They’re rarely tested. The first time anyone discovers the restore doesn’t work is the morning they need it to.

That backup-hunting is a standard operating procedure. Sophos found in The Impact of Compromised Backups on Ransomware Outcomes that in 94% of ransomware attacks, the attackers attempted to compromise the victim’s backups, and that across all sectors 57% of those attempts succeeded. The thing most firms are counting on to save them is exactly what the attacker goes after first, and the research indicates that more than half the time, they get it.

Verizon’s own analysis notes that small and mid-sized organizations are less likely than large ones to have current, readily available backups. The gap goes beyond prevention and includes the ability to recover, which determines whether an attack is a bad week or a closed business.

Organizations appear to be learning this the hard way. In Sophos’s 2025 The State of Ransomware in the Enterprise report, the share of victims who recovered by restoring from backups fell to 53%, down from 73% the year before, reaching a four-year low. When backup recovery keeps failing, fewer organizations rely on it, and more end up paying. That’s the disturbing trajectory.

Moreover, an organization can run backups faithfully for years and still discover, at the worst possible moment, that the copy it needs is not current, already encrypted, or corrupt.

What immutability changes about recovery

The defense that holds against ransomware is a version of the data the attacker cannot touch. That’s what immutable file data means in practice. An immutable snapshot is a point-in-time record of the file system that, once written, cannot be altered or deleted. Not by an administrator, a compromised account, or ransomware that has taken over the network. It sits in object storage as a permanent record. This is how Panzura CloudFS is built. The authoritative copy of your data remains immutable in object storage, and the file platform your users work in reads and writes against a local cache. The immutability is part of the architecture. In fact, Panzura was named a Representative Vendor in the latest Gartner® Market Guide for Cyberstorage1,

As we see it, two things change the recovery equation entirely.

  • The first is frequency. When snapshots can be taken as often as every 60 seconds, the amount of work at risk collapses from a day to about a minute. Recovery requires you roll back to the snapshot from just before the attack. The difference between losing a day and losing a minute is the difference between a crisis and an inconvenience.
  • The second is immutability. It removes the backup’s weakness. There’s no restore project to run or fatal question of whether the copy survived the attack, because the snapshots were never reachable by the intruders who did the encrypting. Recovery becomes a rollback rather than a rescue operation.

For a firm without a storage administrator, that last point is perhaps the most important one. Immutability in CloudFS doesn’t ask the two-person IT team to have a flawless backup regime or to execute a complex recovery under pressure with detailed recovery scripts and procedures per application on data type. It simply asks them to select a point in time and roll back to it. That protection doesn’t depend on a team having spare capacity.

Catching the attack, not just surviving it

Recovery is the safety net. But the earlier you know an attack is underway, the less there is to recover from. A small IT team is the least likely to be watching at the moment it matters. As previously mentioned, they've got their hands full already.

This is the job of Threat Control, a capability of CloudFS through Panzura Data Services. It watches file behavior for the signatures of an attack in progress, such as mass encryption, mass deletion, and anomalous access patterns that precede data loss. It then alerts administrators as it happens, rather than relying on a nightly backup window where the data is already encrypted.

Panzura Data Services is also the same layer that makes the entire file estate searchable and records file activity for audit. For instance, that includes the access history a compliance review requires without a separate tool. But in the context of ransomware, its job is early warning that shrinks the window between when an attack starts and when someone notices, so the immutable snapshots underneath have less to undo.

Table 1. Traditional backup vs. immutable snapshots for ransomware recovery

Recovery factor Traditional backups Immutable snapshots
Data loss window (RPO) Up to 24 hours (nightly schedule) As little as 60 seconds  
Can attackers alter or delete it Yes — targeted in 94% of attacks, compromised 57% of the time No — immutable once written, unreachable by ransomware  
Recovery method Restore project: locate, rebuild, verify Roll back to a pre-attack point in time
Depends on storage administrator Yes — complex restore under pressure No — select a snapshot and revert
First failure discovered Often at restore time, when it’s too late N/A — snapshots verified and always available 
Typical outcome for a 3-person IT team Days of downtime, possible data loss Minutes to recover, no data loss

Why single-site organizations, specifically

Everything comes into sharper focus when you compare the mid-market single-site organization directly against the large enterprise attackers are wrongly assumed to prefer. The enterprise is a harder target because size buys defenses and recovery capability the mid-market can’t easily staff or fund.

Table 2. Mid-market single-site vs. large enterprise: ransomware risk profile

Factor Mid-market single-site (100-300 employees) Large enterprise (1,300+ employees)
Ransomware present in breaches 88% 39%
Dedicated security staff Typically none Dedicated storage / infrastructure team
Business impact of an attack Existential — ~1 in 5 SMBs close after a cyberattack Bad quarter, disclosure filing
Average recovery cost (excl. ransom) ~$638,536 (100–250 employees) Higher absolute cost, absorbable relative to revenue 
Tested, available backups Less likely to have current backups  More likely to maintain and test backups


The table above makes the attacker’s logic visible. The mid-market firm holds comparably valuable data, protects it with a fraction of the resources, and is less likely to afford both the downtime and the recovery bill.

What single-site organizations can do

The firms getting hit hardest aren’t careless. They’re carrying enterprise-grade risk on the resources a mid-sized business can muster, and attackers have learned to find them. You can’t hire your way to a large enterprise’s security posture on a mid-market budget, and you can’t expect a three-person team to watch everything at once.

What you can do is change what happens before, during, and after an attack, and get all three from one place instead of stitching them together from separate products. That’s what Panzura Express is built to do. It’s a single-site edition of the Panzura CloudFS platform, licensed for one office and delivered through a partner, that brings the same protections CloudFS runs in global enterprise deployments at the scale for a mid-market organization

  • Panzura CloudFS with a local high-availability node pair — the file system your users work in, with the authoritative copy held immutable in object storage and snapshots as often as every 60 seconds.
  • Panzura Data Services with Threat Control — real-time detection of ransomware and anomalous behavior, so the attack is caught as it happens, plus estate-wide search and audit for compliance.
  • Panzura Nexus is the same file data made answerable through Microsoft 365 Copilot, so the knowledge you’re protecting is also usable.

All of this is delivered under one annual license, with no separate security product to buy and no storage administrator required to run it. And because Panzura Express runs the same code as multi-site CloudFS, a firm that grows past one office expands through a license change rather than a migration. The protection carries forward unchanged.

Prevention will always be imperfect, especially with a small team. Recovery is where the outcome is actually decided. Immutability, paired with detection that fires in time to matter, is what makes recovery something you can count on. The goal isn’t to never get hit. It’s to make getting hit survivable, so a bad stays a bad day instead of becoming the reason the firm doesn’t see next year.

The fastest way to know whether Panzura Express fits your environment is to walk it through with a Panzura expert or partner who can size it to your office, your object storage, and your team. Let's talk and see what recovery in minutes actually looks like for an organization your size.

[1] Gartner®, Market Guide for Cyberstorage, Vishesh Divya, 23 February, 2026

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of the Gartner research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.



Frequently Asked Questions (FAQs)

  • Why do backups fail during a ransomware attack?

    Attackers target backups deliberately, and traditional backup architecture makes them easy to reach. Sophos found intruders attempted to compromise backups in 94% of ransomware attacks and succeeded 57% of the time. Backups also run on a fixed schedule, sit on the same network as live data, and typically go untested until the moment an organization needs a restore.

  • What is an immutable snapshot?

    An immutable snapshot is a point-in-time record of a file system that cannot be altered or deleted once written, including by an administrator, a compromised account, or ransomware that has taken control of the network. It is held in object storage as a permanent record, which places it outside the reach of an attacker who has compromised the live environment. Panzura CloudFS uses immutable snapshots.

  • How do immutable snapshots differ from traditional backups for ransomware recovery?

    Traditional backups are network-reachable, run on a schedule, and require a restore project executed under pressure. Immutable snapshots cannot be modified by an attacker, can be taken as often as every 60 seconds as with Panzura CloudFS, and recover by rolling back to a point in time. The data loss window drops from as much as 24 hours to roughly one minute.

  • Can ransomware encrypt or delete immutable snapshots?

    No. Immutability is enforced at the storage layer, so a snapshot cannot be rewritten or removed after it is written, even by an account holding full administrative rights. This closes the failure mode behind most unsuccessful ransomware recoveries, where the protection an organization relied on had already been compromised before the visible attack began.

  • What is Panzura Express?

    Panzura Express is a single-site edition of the Panzura CloudFS platform, licensed for one office and sold exclusively through partners. It combines immutable file storage, real-time ransomware detection, and Microsoft 365 Copilot access to file data under one annual license. It is built for mid-market organizations running one to three generalist IT staff without a dedicated storage administrator.

  • How does Panzura Express protect against ransomware?

    Panzura Express protects file data through three layers. The authoritative data is held immutable in object storage, snapshots run as often as every 60 seconds, and Threat Control detects mass encryption, mass deletion, and anomalous access as they happen. Recovery is a rollback to a pre-attack point in time rather than a restore project, so no storage administrator is required.

  • Can Panzura Express scale beyond a single site?

    Yes. Panzura Express runs the same code as multi-site Panzura CloudFS, so an organization that grows past one office expands through a license change rather than a data migration. Immutable snapshots, Threat Control, and existing file data carry forward unchanged, with no re-implementation of the security posture required at the additional sites.

     


About the author
Darrin Chapman
Darrin Chapman

Darrin Chapman is Senior Director of Product Marketing. With nearly 30 years of experience spanning Dell/EMC, Cohesity, and NetApp, Chapman articulates Panzura’s value proposition to the marketplace.

Panzura Express for Single-Site Firms: Eliminate the Hardware Shortage Queue

Panzura Express for Single-Site Firms: Eliminate the Hardware Shortage Queue

Sold-Out Drives, Repricing Vendors, 30-Week Lead Times. Express Delivers Enterprise-Grade File Storage With Immutability, Ransomware Protection, and...

Panzura Express and Why Single-Site Organizations are the Real Ransomware Target

Panzura Express and Why Single-Site Organizations are the Real Ransomware Target

The Firms Most Convinced They're Too Small to Hit Are Getting Hit Most Often. Here's Where the Risk Concentrates Below 300 Employees — and What...

Panzura Express and Flexible Growth from One Office to Many Without Migration or a Ceiling

Panzura Express and Flexible Growth from One Office to Many Without Migration or a Ceiling

Most Storage Systems Make You Migrate to Grow. Here is How a License-Based Path Turns the Second-Site Project Into a Line-Item Change — and What the...