Ransomware Protection for Small Business: Before, During, After
Ransomware is the attack that ends businesses. Not dents them — ends them. A locked network, encrypted backups, a countdown clock, and a demand. The reason it keeps working is not sophisticated cryptography; it is that most small businesses have no tested recovery path. This is the full lifecycle: what stops it before it starts, what to do in the first hour, and how to come back without funding the criminals.
How ransomware actually gets in
Four doors account for nearly every small-business infection. Phishing email with a weaponed attachment or a link to a fake login page — still number one. Exposed remote access: an RDP port or remote-access tool open to the internet with a reused password. Unpatched edge devices: routers, VPN appliances, and firewalls past end-of-support. And compromised credentials bought from a breach dump and tried against every login page on your domain.
Modern crews do not encrypt on arrival. They sit quietly for days — mapping shares, finding the backup server, exfiltrating data. The encryption you notice at 9 a.m. on a Monday was decided the previous Thursday. That dwell time is your best defense window, and the controls below shorten it.
Before: the five defenses that matter
- MFA on every remote entry point. Email, VPN, admin panels. Credential-stuffing does not beat MFA; it moves on.
- 3-2-1 backups with one immutable copy. Three copies, two media, one offsite — and one that ransomware cannot encrypt or delete, whether that is immutable object storage or a rotation that is offline.
- Restore drills. A backup you have never restored is a hope. Pull a file back every month; a full machine quarterly.
- Close the exposed doors. RDP does not belong on the open internet. Put remote access behind a VPN and rate-limit authentication.
- Patch on a cadence. EOL hardware is the front door with the broken lock. Budget for replacements as a security line item.
You do not need to outspend ransomware crews. You need a recovery path that makes their product worthless.
During: the first hour
If files start encrypting: isolate, do not power off. Pull the network cable, disable Wi-Fi, isolate the VLAN — powering down can destroy memory evidence. Take a photo of the ransom note. Then: call your insurance carrier (many policies have breach coaches and preferred forensics — calling them late can void coverage), call IT or your MSSP, and preserve everything. Do not email details of the incident from the compromised network. If you have cyber insurance, notify them before engaging anyone — panel counsel rules matter.
One more thing for the first hour: protect the backups before touching anything else. Disconnect the backup server or take the rotation offline. Attackers target backups first precisely because a dead backup forces payment.
After: recover, report, harden
Rebuild from clean media, restore from the immutable copy, and change every credential before machines rejoin the network. Report to law enforcement (IC3 in the US) and check breach-notification duties if data was stolen — modern attacks leak as leverage. Then close the door they used: patch the entry vector, reset every account, and run the restore drill you now realize you should have run months ago.
Should you pay?
My answer is no, and it is not just ethics — it is economics. Paying funds the operation that will hit your neighbor next, marks you as a payer for the next crew, decryptors are frequently broken or slow, and roughly a third of victims who pay get asked to pay again. The businesses that walk away intact are the ones with an offline backup and a rehearsed recovery. Build that and the countdown clock becomes someone else's problem.
// business_resilience
Know what an attacker would find first
A Phantom Opsec Scan maps your external exposure — open services, leaked credentials, and public footprint — so you close the doors before anyone tests them.
Get the $97 Phantom Scan →