Skip to content

Resource

Ransomware protection for small business

Ransomware is not a single event, it is a sequence with several steps between the first intrusion and the ransom note. That sequence is useful, because each stage offers a chance to stop it, and because the stage most businesses ignore is the one attackers deal with first: your backups.

The sequence, and where to break it

Attacks take time. Days or weeks typically pass between the first intrusion and the encryption event, which is the window in which detection matters.

Ransomware attack stages and the control that interrupts each
StageWhat happens
Initial accessMFA everywhere, email filtering, no remote desktop exposed to the internetStolen credentials, phishing, exposed remote access
Establish footholdEndpoint detection and response, with somebody reviewing alertsMalware installed, persistence created
Escalate privilegesNo standing admin rights, separate admin accounts, privileged access limitsAdministrative rights obtained
Move laterallyNetwork segmentation, so one machine cannot reach everythingSpread across the network
Destroy backupsImmutable backups that cannot be deleted even by an administratorBackup systems targeted first
Encrypt and demandBy this stage prevention has failed. Recovery is what remainsFiles encrypted, ransom note appears

The first hour

What you do immediately affects both the recovery and, if you have a policy, the insurance position. Powering machines off is the most common instinct and one of the more damaging.

  • Disconnect affected machines from the network, but do not power them off, because memory holds evidence
  • Do not delete anything, including the ransom note
  • Contact your IT provider and your cyber insurer before taking further action, since insurers often require specific steps
  • Preserve logs before anything is rebuilt or restored
  • Assume credentials are compromised and plan a reset, but coordinate it rather than doing it piecemeal
  • Do not communicate with the attacker without professional advice

Immutability is the control that decides the outcome

Every other control on this page reduces the chance of an incident. Immutable backups determine what happens once one occurs anyway.

An immutable backup cannot be modified or deleted for a defined retention period, by anyone, including an account with full administrative rights. That last part is what matters, because by the time ransomware triggers, the attacker usually holds exactly those rights.

A business with tested immutable backups faces a bad week: restore, rebuild, investigate, and a difficult conversation with staff and customers. A business without them faces a decision about whether to pay criminals for a decryption tool that may not work. The cost difference between those two positions is enormous, and the cost difference between the two backup configurations usually is not.

Common questions

Answered before you ask.

Should we ever pay a ransom?

That is a decision for the business with legal and insurance advice, not a technical one, and it should never be made in the first hours. What is worth understanding in advance is that payment does not reliably produce clean recovery: decryption tools supplied by attackers are often slow and imperfect, and paying confirms you are a business that pays. There are also legal considerations depending on who the attacker is. The way to avoid the question entirely is a backup that cannot be reached.

Why do backups get targeted first?

Because attackers understand the economics perfectly well. A business with working backups will not pay, so modern ransomware operations spend time locating and destroying backup systems before triggering encryption, frequently using administrative credentials they have already stolen. This is the entire reason immutability matters: a backup that cannot be altered or deleted for a fixed period survives even when the attacker holds full administrative control.

We are small. Are we really a target?

Targeting is largely automated, so size filters very little. Attackers scan continuously for exposed remote access, unpatched systems and credentials appearing in breach data, then work through whatever responds. Smaller businesses are attractive because security is usually thinner and the decision to pay sits with one person who can make it quickly. The useful question is not whether you will be probed, but whether an automated attempt would succeed.

What single control matters most?

Multi factor authentication for prevention, and immutable backups for survival. If only two things can be funded, those are the two. MFA closes the most common entry route, which is a working stolen credential rather than a sophisticated exploit. Immutable backups mean that even a complete failure of every other control leaves you with a recovery path rather than a negotiation.

Start with the assessment, not the contract.

We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.

CallFree assessment