When I talk to small businesses about IT security, sooner or later this sentence comes up: “There's nothing here worth stealing.” Often that is even true. It just doesn't matter. What kills a business is not what its data is worth to an attacker — it is the time it cannot work.

Since 2022 there has been a series of cases that can be laid side by side. They are instructive, though not in the way the headlines suggest.

Five firms, five standstills

ZEGO Textilveredelungszentrum, Aschaffenburg, around 60 employees, a textile finisher serving workwear brands. Attacked in late March 2026; by the company's own account the machines stood still for almost six weeks. The insolvency petition followed in early July 2026. Operations continue.

Fasana, Euskirchen, napkins and hygiene paper, around 240 employees. Encrypted on 19 May 2025, roughly 190 devices had to be rebuilt. The decisive detail sits in the administrators' reports: the May wages could not be paid on time. That shrank the window for an investor solution from twelve weeks to eight. The petition came on 1 June — thirteen days after the attack. The estate has since been declared insufficient and production is winding down.

Eu-Rec, Hermeskeil, recycling, around 50 employees. Attacked on 7 April 2025, with data on some 200 customers exfiltrated, bank details included. The petition followed sixteen days later.

Schumag, Aachen, precision components, 194 years old, around 450 employees. Attacked in September 2024, self-administration filed in October. The board described the connection itself: they had a clear turnaround plan and had to accept that the existing restructuring plans were void after the attack. The restructuring succeeded even so — 374 jobs were saved.

Prophete, bicycles, around 400 employees. Attacked in November 2022, three weeks of standstill across production, invoicing and dispatch, petition four weeks later. The provisional administrator named two causes of equal weight: procurement problems with expensive excess stock — and the losses from the attack, which the shareholders were no longer willing to carry.

The pattern is not the ransom

In none of these cases was the ransom demand the reason for the filing. What knocked these firms over was the outage: six weeks in which no goods leave the building while wages, rent and lease payments carry on unchanged. At Fasana the tipping point can even be traced to something that has nothing to do with extortion — a payroll run that did not go through.

A figure from a Bitkom survey in February 2026 fits this exactly: in a total IT outage, German companies remain able to work for an average of 20 hours. One in five would have to stop immediately; only eight per cent would last beyond 48 hours. Four in ten have made no preparation at all.

Twenty hours. The cases above are measured in weeks.

The uncomfortable part

Now the part the trade press tends to leave out: in none of these cases is the attack documented as the sole, independently verified cause.

For Eu-Rec the reports themselves cite irregular order intake and high energy costs. At Fasana, thin margins and rising raw material prices played their part — and the search for an investor ultimately failed because the owner of the land would not sell, a circumstance with no connection to IT whatsoever. At Prophete the procurement problems stood alongside the attack as an equal cause. At Schumag the crisis demonstrably predated the attack; what the attack destroyed was the restructuring plan, not the company.

One case is regularly counted in by the IT press that does not belong there: at the plant engineering firm Wehrle-Werk in Emmendingen, fifteen months separate the attack from the petition, and the local press lists six causes — from the withdrawal from Russian business to a failed software migration. On revenue of 50 million euros the company had already reported a 17 million euro loss, long before anyone encrypted anything.

And the figure quoted everywhere — that sixty per cent of small businesses close within six months of an attack — has no traceable primary source. Germany has no statistic attributing insolvencies causally to cyberattacks; the official insolvency statistics do not record such a reason at all.

What remains is the more cautious and therefore more defensible statement: the attack was the trigger that pushed an already strained business over the edge. That is not reassurance. It is the opposite — because in the current economy, almost everyone is strained.

What follows from this

Three things, in this order.

Rehearse the restore, not the backup. At Südwestfalen-IT, whose breach in October 2023 paralysed some 72 municipalities, the backups survived unencrypted. That is why no ransom was paid. Full recovery still took until autumn 2024. A backup nobody has ever restored is a hope that consumes disk space — and even a working one is no substitute for a plan.

A second factor on every remote access. At that same Südwestfalen-IT, the attackers came in through a VPN without two-factor authentication, simply by guessing. It is the cheapest measure on this list and the one with the best return.

Play through the twenty hours. What actually happens if nothing starts up tomorrow morning? Who reaches the customers, how do wages get paid, where are the service providers' phone numbers — on paper, not on the encrypted file server. It costs one afternoon, and it is the part that four in ten in the Bitkom survey have never done.

The question is not whether your systems will be attacked. It is how long you can work without them — and whether you know that number before someone else finds it out for you.


Sources: company statement by ZEGO Textilveredelungszentrum · dhpg and Radio Euskirchen on Fasana · EUWID Recycling on Eu-Rec · Presseportal and t-online on Schumag · administrator Sack on Prophete · baden24 on Wehrle-Werk · KommunalWiki of the Heinrich Böll Foundation on Südwestfalen-IT · Bitkom survey on outage resilience, February 2026.