Ransomware attacks increasingly target smaller businesses precisely because they assume, often correctly, that security spending has lagged behind larger enterprises.
The good news is that a handful of consistently applied basics still stop the majority of attacks: patched systems, tested offline backups, staff trained to spot phishing, and monitoring that flags unusual activity quickly rather than after the fact.
None of this requires an enterprise budget. It requires consistency, and someone accountable for making sure it actually happens.