Ransomware is malicious software that locks (encrypts) your files and demands payment to unlock them. It isn't only a big-company problem — small businesses are frequent targets because their defences are often weaker. One click on a fake invoice email can stop billing, production and accounts for days. The good news: a handful of basics block most attacks.
How ransomware usually gets in
- Phishing emails — fake invoices, courier notices or "payment pending" attachments.
- Weak or reused passwords, especially on remote desktop (RDP) left open to the internet.
- Unpatched software — old Windows versions, outdated servers and firewalls.
- Pirated or untrusted software downloaded by staff.
- USB drives from unknown sources.
The ransomware protection checklist
1. Backups that ransomware can't reach
Follow the 3-2-1 backup rule, keep at least one copy offline or unchangeable (immutable), and test restores regularly. Backups are what turn a disaster into an inconvenience.
2. Keep everything updated
Apply updates to Windows, servers, firewall firmware, browsers and business software like Tally or your ERP. Replace systems that no longer receive security updates.
3. Turn on multi-factor authentication (MFA)
Require a second step — an app code or prompt — for email, VPN, remote access and every admin account. It stops most attacks that rely on stolen passwords.
4. Never expose remote desktop to the internet
Remote desktop left open to the internet is one of the most common ways in. Put remote access behind a VPN instead.
5. Use proper endpoint protection
Install modern, centrally managed antivirus or endpoint protection on every computer and server — and make sure someone actually watches the alerts.
6. Limit admin rights
Staff should use standard accounts for daily work. Admin access should be separate and used only when needed.
7. Filter your email
Use spam and phishing filtering, block risky attachments, and set up SPF, DKIM and DMARC so criminals can't easily impersonate your domain.
8. Train your team
Teach staff to spot suspicious emails and to verify unusual requests — especially changes to bank details — with a phone call.
9. Separate your network
Keep guest Wi-Fi, CCTV and smart devices on separate networks from your office computers and servers, so one infected device can't reach everything. See how to set up office Wi-Fi properly.
10. Have a response plan
Write down who to call, how to disconnect affected machines, and where your backups are. Five minutes of planning saves hours of panic.
What to do if you're hit
- Disconnect affected computers from the network — unplug the cable or turn off Wi-Fi. Don't delete anything.
- Call your IT support immediately.
- Don't pay without expert advice — payment doesn't guarantee recovery.
- Report the incident to your national cybercrime authority. In India, use cybercrime.gov.in — organisations may also need to report certain incidents to CERT-In, so check what applies to you.
- Restore from clean backups once the threat has been removed, and change all passwords.
Frequently asked questions
Can antivirus alone stop ransomware?
No. Antivirus is one layer. Real protection comes from combining backups, updates, multi-factor authentication, email filtering and staff awareness.
Should we pay the ransom?
Authorities generally advise against it. Paying doesn't guarantee you'll get your data back, and it funds further attacks. Clean, tested backups are the real protection.
Are small businesses really targeted?
Yes. Many attacks are automated and look for any vulnerable system, regardless of company size. Smaller businesses are often easier targets because their defences are weaker.
How protected is your business?
Our free IT health check reviews your backups, updates, email security and network — with a written report of what to fix first.