HomeBlogCybersecurity

How to Prevent Ransomware: A Small Business Checklist

Pixel-art illustration of a robot on a pirate ship's deck raising a glowing blue shield against red, bug-shaped malware over a stormy sea

You prevent ransomware by closing the doors attackers use and making sure you can recover if one opens anyway. Patch internet-facing devices first, require multifactor authentication on email and remote access, take away everyday admin rights, run endpoint detection that someone watches, and keep offline or immutable backups you have restored in a test.

The checklist below follows the #StopRansomware Guide that CISA, the FBI, the NSA and MS-ISAC published in October 2023, reordered for a small business. It is the same stack our ransomware protection service runs inside our managed cybersecurity services. If you are in the middle of an attack now, skip to step 10 and call your IT provider.

How does ransomware get into a small business?

The #StopRansomware Guide groups the ways in as initial access vectors. In plain terms:

  • Internet-facing weaknesses. Remote desktop exposed to the internet, and VPNs or firewalls running old firmware.
  • Stolen passwords. Credentials phished or bought, then used on accounts without multifactor authentication.
  • Phishing. Malicious links and attachments, including macros in Office files.
  • Earlier malware. The guide notes that a ransomware infection can be evidence of an earlier, unresolved compromise.
  • Social engineering and vendors. Attackers posing as IT or help desk staff by phone or text, and access through third parties and managed service providers, which the guide says have been an infection vector for many client organizations.

In the incidents we have worked, encryption came last. The attacker got in through a VPN appliance with old firmware or a phished password without MFA, spent days or weeks looking around, found the backups and deleted them, then encrypted everything. Microsoft has documented one group that went from fake help desk calls and Teams messages to Black Basta ransomware. The gap between the first login and the encryption is your chance to catch it.

How do you prevent ransomware? A 10-step checklist

1. Patch internet-facing devices first

VPNs, firewalls and remote access gateways get patched before anything else, because they face the internet. The guide asks for timely patching of internet-facing systems, especially for known exploited vulnerabilities, and current software on VPNs and network devices. Our post on SonicWall VPN ransomware attacks shows how fast an unpatched appliance becomes the way in.

2. Take remote desktop off the internet

Do not expose Remote Desktop Protocol to the web. If staff need remote access, put it behind a VPN with multifactor authentication, close unused RDP ports and log every sign-in attempt, as the guide recommends.

3. Require MFA everywhere, phishing-resistant where you can

The guide calls for phishing-resistant MFA on all services, particularly email, VPNs and accounts that reach critical systems, and asks that systems and users without MFA be escalated to senior management. Passkeys or security keys for administrators come first; see passkeys vs. MFA.

4. Remove everyday admin rights

Staff work in standard accounts, and administrators use separate admin accounts only for admin tasks. The guide also recommends limiting local administration and auditing accounts quarterly for any that are inactive or unauthorized, including the access given to IT providers.

5. Run EDR on every device, and have someone watching

The guide recommends endpoint detection and response or application allowlisting on all devices, with alerts routed to people who will act on them. Detection helps only if someone sees the alert at 2 a.m. Our managed detection and response team watches every endpoint around the clock and can isolate a device when encryption behavior starts.

6. Filter email and DNS, and train people to report

Filter mail at the gateway, block risky attachment types, flag external senders, keep Office macros blocked and set DMARC on your domain. Add protective DNS so a click on a bad link goes nowhere. Then teach staff to recognize and report suspicious messages, which the guide treats as part of the same defense. Our email security services cover the mail side.

7. Segment the network and switch off SMBv1

Keep servers, workstations, guest Wi-Fi and devices such as cameras on separate segments so one infected laptop cannot reach everything. The guide also says to disable SMB version 1, block TCP port 445 at the internet edge and limit file-sharing traffic between workstations, since most workstations never need to reach each other. Our post on network segmentation covers where to start.

8. Keep offline or immutable backups, and time a restore

Ransomware crews hunt for backups. The guide notes that most ransomware actors try to find and delete or encrypt accessible backups, and that automatic cloud sync can copy encrypted files over good ones. Keep at least one copy offline or immutable, outside your normal sign-ins, and test restores on a schedule with the time to recover written down. Our disaster recovery service builds and tests that plan.

9. Limit what your vendors can reach

Give IT providers, software vendors and remote support tools only the access their role needs, and know which remote management tools are allowed on your network. The guide recommends least privilege for third parties and auditing remote access software for anything unauthorized. Ask your providers, us included, how they protect the access they hold.

10. Write a first-hour plan and rehearse it

Write down who does what in the first hour, keep a printed copy, and rehearse it. The guide's response checklist starts with three steps in order: find the affected systems and isolate them, taking the network offline at the switch if several are hit; power devices down only if you cannot disconnect them; then triage systems for recovery. Coordinate by phone rather than email, because attackers may be reading your mail. Our incident response retainer means the first call starts containment.

What did WannaCry teach small businesses?

In May 2017, WannaCry ransomware hit organizations in more than 150 countries, according to CISA's alert at the time. It spread on its own through a flaw in Windows file sharing (SMB version 1). Microsoft had released the fix, MS17-010, on March 14, 2017, two months before the outbreak. Three lessons still hold:

  • Unpatched systems. The patch existed, and WannaCry spread through machines that had not installed it. Patching on a schedule, with reporting, comes first for a reason.
  • Old protocols on flat networks. Once inside, it moved from machine to machine over SMBv1. Microsoft now says SMBv1 has significant security vulnerabilities and no longer installs it by default in Windows 11 or Windows Server 2019 and later, but older computers and software can still depend on it.
  • No offline copy. CISA's 2017 alert told organizations to keep offline backups and test that they work. Businesses with a clean copy could restore; those without one were left with the ransom note.

WannaCry spread automatically to whatever unpatched machines it could reach, whatever the size of the business. Today's crews still often get in through exposed, poorly secured remote services, the guide notes, which is why steps 1 and 2 come first.

How we protect clients from ransomware

Our ransomware protection runs in four layers: prevention (MFA, patched firewalls and VPNs, no standing admin rights, email defense), detection by our MDR team, immutable backups kept outside the production domain, and a disaster recovery plan tested with a timed restore. In the past three years we have handled more than 30 ransomware incidents, and every one was fully recovered; clients with a disaster recovery plan in place were back within 24 hours. It is included in our managed agreement, month to month.

Frequently asked questions

Is antivirus enough to stop ransomware?

No. Attackers often use legitimate tools, such as remote management software and PowerShell, that do not look like malware, and the #StopRansomware Guide recommends endpoint detection and response or application allowlisting on every device. Detection also needs a person: an alert that nobody reads until Monday gives the attacker the weekend.

Are cloud backups enough to recover from ransomware?

Not on their own. CISA warns that automatic cloud backups may not be enough, because files encrypted on a computer can sync to the cloud and overwrite good copies. Keep at least one copy offline or immutable, with enough retention to reach back before the attack started, and prove it with a timed restore. Microsoft 365 data needs its own backup too.

Should a small business pay a ransomware ransom?

The FBI, CISA and their partners do not recommend paying. Their guide says payment does not ensure your data is decrypted, that your systems are clean or that stolen data stays private, and it can carry sanctions risk under Treasury guidance. If you face the decision, read should you pay a ransomware ransom and involve your insurer and counsel.

What should we do in the first hour of a ransomware attack?

Isolate the affected computers from the network, or take the network offline at the switch if several are hit, and power devices down only if you cannot disconnect them. Coordinate by phone, not email. Then call your incident response provider and your cyber insurer before you wipe or rebuild anything, so evidence is preserved and the recovery follows your plan.

Sources and further reading

Ransomware Protection & Recovery

Discuss ransomware protection & recovery for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore Ransomware Protection & Recovery 845-203-3914