Ransomware Protection: What Small Businesses Should Do First

Every ransomware decision that matters gets made long before the ransom note appears. By the time a screen says your files are encrypted, your options have been set months earlier — how your backups are connected, who can log in from outside, and whether anyone has ever tested a restore. Our guide to what ransomware is covers how the attacks work; this one is the preparation playbook.

Your backup has to be somewhere the attack can't reach

Ransomware doesn't only encrypt the documents you were working on — it encrypts everything the compromised account can write to. A USB drive left plugged in, a mapped network share, a NAS that accepts writes from that login — it all goes with the rest. A backup drive attached to the server isn't a backup during an attack; it's just more files to encrypt. What survives is a copy the infected machine cannot modify:

  • Offline copies. A drive physically disconnected between backup runs, or rotated and taken off-site. Unglamorous, and it works.
  • Immutable cloud backups. Storage where a copy is locked for a set retention period and can't be altered or deleted even with valid credentials.
  • Separate credentials. The backup system shouldn't authenticate with the same administrator account your staff and servers use. If one login opens both, one compromise loses both.

The 3-2-1 approach is still the sensible frame. Ransomware just adds a condition: one copy must be beyond the reach of a compromised account.

An untested restore is a rumour

Backup software reports success far more reliably than it delivers usable data. Jobs quietly stop covering a new server, a database is backed up mid-write and won't open, retention overwrites the last clean copy. None of it shows until the day you need it. Book a real restore test on a schedule, recover something meaningful somewhere other than its original location, and time it — better learnt on a quiet Tuesday than mid-incident.

Ransomware adds two wrinkles. Attackers are usually inside a network for a while before anything is encrypted, so your history has to reach back past the point of compromise, not merely to last night. And the restore belongs on clean, rebuilt machines: putting good data back on a compromised one invites a second round.

Shut the doors attackers actually use

Attacks on small businesses are rarely sophisticated. They tend to arrive through a remote-access login with a reused password, or an unpatched internet-facing device.

  • MFA on everything reachable from outside. Remote desktop, VPN, email, your accounts package, the router's admin page. A stolen password alone should never be enough, and two-factor authentication is the change worth making first.
  • Patch the edge first. Firewalls, routers, VPN appliances and anything else with a public address. These get scanned constantly, and known flaws are exploited quickly.
  • Never expose remote desktop directly. Put it behind a VPN or a brokered access service.

Limit what one click can reach

Ransomware runs with the permissions of whoever triggered it. If your team works day to day as local administrators, or one account can write to every folder in the business, a single click reaches everything. Give people the access their job needs, keep admin accounts separate from the ones used for email and browsing, and remove access when someone leaves.

Do the same with the network. Guest Wi-Fi on its own segment, card terminals, CCTV and smart devices kept away from the machines holding your data, the backup system in its own corner. Even a modest split turns a whole-business incident into a contained one.

Write the plan while everything is calm

An incident plan is mostly a list of phone numbers and a running order, and it has to exist on paper or on a phone — not in the file server that's currently encrypted. Record who declares an incident, who calls your IT support, insurer and bank, and who tells staff and customers what's happening. Our disaster recovery guide covers building that out. If personal data is involved there are reporting duties in the UK, so take proper advice rather than guess.

Decide now that you're not paying

Deciding in advance is itself a control, because it forces the real questions into the open: could we restore, how long would it take, what would we lose. If the honest answer is that you'd have to pay, you've found the gap while you can still fix it.

Get a straight assessment

We work with businesses across Edinburgh and the Lothians, from Livingston to Musselburgh, alongside our base in Wishaw. Our cyber security and managed IT services can review your backups, remote access and recovery plan honestly, with a clear quote before any work starts.

Get a free quote

Broken device or a business IT headache?

From cracked screens to fully managed networks, our specialists can help. Tell us what you need and we'll get back to you fast.

WhatsApp Book Quote