Ransomware is malicious software that locks or encrypts a victim’s files and demands payment to restore access. Increasingly, attackers also steal data before encrypting it and threaten to publish it — a tactic known as double extortion.
Small businesses are frequent targets because they often have valuable data but fewer security resources than large companies. A single attack can halt operations for days or weeks, damage customer trust, and lead to significant recovery costs.
The good news is that most ransomware attacks can be prevented or contained with a set of practical measures. Use this checklist to strengthen your business’s defenses.
How Ransomware Gets In
Understanding common entry points helps you prioritize your defenses:
- Phishing emails with malicious links or attachments
- Stolen or weak passwords, especially for remote access tools
- Unpatched software with known vulnerabilities
- Exposed remote desktop (RDP) services accessible from the internet
- Compromised vendors or IT providers with access to your systems
- Malicious downloads and fake software updates
The Ransomware Protection Checklist
1. Backups: Your Most Important Defense
If you have reliable, recent backups that attackers can’t reach, you can restore your systems without paying.
- ☐ Follow the 3-2-1 rule: keep at least three copies of your data, on two different types of storage, with one copy offsite.
- ☐ Keep at least one backup offline or immutable (unchangeable), so ransomware can’t encrypt or delete it.
- ☐ Use separate credentials for backup systems, protected with MFA.
- ☐ Test restores regularly — a backup you’ve never restored is a backup you can’t trust.
- ☐ Back up cloud data too, including email and file-sharing services.
For more on how backups differ from simple file syncing, see our guide on cloud backup vs cloud storage.
2. Multi-Factor Authentication (MFA)
- ☐ Enforce MFA on email, remote access, VPNs, and cloud services.
- ☐ Require MFA for all administrator accounts.
- ☐ Use phishing-resistant MFA, such as security keys or passkeys, for high-risk accounts where possible.
Learn which methods offer the strongest protection in our guide to 2FA methods ranked.
3. Patching and Updates
- ☐ Turn on automatic updates for operating systems, browsers, and applications.
- ☐ Prioritize patches for internet-facing systems such as VPNs, firewalls, and email servers.
- ☐ Replace or isolate unsupported software that no longer receives security updates.
- ☐ Keep an inventory of all devices and software so nothing is forgotten.
4. Secure Remote Access
- ☐ Never expose Remote Desktop Protocol (RDP) directly to the internet.
- ☐ Use a secure VPN or zero-trust access solution with MFA. See how to choose a VPN.
- ☐ Remove access for former employees and vendors promptly.
5. Email and Phishing Protection
- ☐ Use an email security service that filters malicious links and attachments.
- ☐ Set up SPF, DKIM, and DMARC to reduce spoofing of your domain.
- ☐ Train staff regularly to recognize phishing. Our guide on how to spot phishing scams is a good starting point.
- ☐ Make it easy for employees to report suspicious messages without fear of blame.
6. Endpoint Protection
- ☐ Install reputable endpoint protection on all computers and servers.
- ☐ Consider endpoint detection and response (EDR) tools, which monitor for suspicious behavior and can stop attacks in progress.
- ☐ Enable built-in protections such as firewalls and controlled folder access where available.
7. Limit Access (Least Privilege)
- ☐ Give employees access only to the systems and data they need.
- ☐ Don’t use administrator accounts for everyday work.
- ☐ Use a password manager and unique passwords for every account — see password managers explained.
- ☐ Review user accounts and permissions regularly.
8. Network Segmentation
- ☐ Separate critical systems (such as finance and backups) from general office networks.
- ☐ Put guest Wi-Fi on a separate network.
- ☐ Isolate internet-connected devices like cameras and printers.
9. Vendor and Third-Party Security
- ☐ Ask IT providers and key vendors about their security practices, including MFA use.
- ☐ Limit vendor access to only what they need, and monitor it.
10. Incident Response Plan
- ☐ Write a simple incident response plan describing who does what during an attack.
- ☐ Keep an offline copy of the plan and key contacts, since your systems may be unavailable.
- ☐ List contacts for your IT provider, cyber insurer, legal counsel, and law enforcement.
- ☐ Run a tabletop exercise at least once a year to practice your response.
11. Cyber Insurance
- ☐ Review whether cyber insurance makes sense for your business.
- ☐ Understand the policy’s requirements — many insurers require MFA, backups, and EDR before offering coverage.
Quick Priority Guide
| Priority | Action | Why it matters |
|---|---|---|
| 1 | Offline or immutable backups, tested regularly | Lets you recover without paying |
| 2 | MFA on email, remote access, and admin accounts | Stops most stolen-password attacks |
| 3 | Patch internet-facing systems quickly | Closes common entry points |
| 4 | Close exposed RDP | A frequent ransomware entry route |
| 5 | Staff phishing training | Reduces risky clicks |
| 6 | Endpoint protection / EDR | Detects and stops attacks in progress |
| 7 | Incident response plan | Speeds up recovery and limits damage |
What to Do If You’re Hit by Ransomware
- Isolate affected devices immediately by disconnecting them from the network — but don’t turn them off unless advised, as this may destroy evidence.
- Activate your incident response plan and contact your IT provider.
- Contact your cyber insurer, if you have one, before taking major actions.
- Report the attack to law enforcement. In the U.S., you can report to the FBI’s IC3 or a local FBI field office, and to CISA.
- Preserve evidence, such as ransom notes and logs.
- Restore from clean backups after the threat has been removed.
- Reset passwords and review access across all systems.
- Consider legal obligations — you may need to notify customers or regulators if personal data was exposed.
Should you pay the ransom?
Law enforcement agencies, including the FBI, generally advise against paying. Payment doesn’t guarantee you’ll get your data back or that stolen data won’t be published, and it can encourage further attacks. Paying may also carry legal risks in some situations. Discuss your options with legal counsel, your insurer, and law enforcement.
Free Resources
Government agencies publish free guidance for small businesses. In the U.S., CISA’s StopRansomware resources and the FTC’s small business cybersecurity guides are good places to start. Many other countries have similar national cybersecurity centers.
Frequently Asked Questions
Is my business too small to be targeted?
No. Many ransomware attacks are automated and opportunistic, targeting any organization with weak defenses regardless of size.
Does antivirus alone stop ransomware?
Antivirus helps, but it isn’t enough on its own. Layered defenses — backups, MFA, patching, and training — are far more effective.
How often should we back up?
It depends on how much data you can afford to lose. Many businesses back up critical data daily or more frequently.
Final Thoughts
Ransomware is a serious threat, but it’s not inevitable. Reliable offline backups, multi-factor authentication, prompt patching, secure remote access, and staff awareness will stop or contain most attacks. Work through this checklist step by step, starting with backups and MFA, and review it at least once a year.
This article is for general educational purposes and is not legal or professional security advice. Consider working with a qualified IT security provider.