You are currently viewing How to Protect Your Small Business From Ransomware

How to Protect Your Small Business From Ransomware

Ransomware is the single most damaging cyber threat facing small businesses today — and the one the data says you’re most likely to face. The encouraging part: the same handful of controls stop the overwhelming majority of attacks, and none of them require an IT department.

Quick answer: Protect your small business from ransomware with seven steps: keep offline or immutable backups (and test them), deploy EDR, turn on MFA everywhere, patch software promptly, limit admin access, train staff to spot phishing, and write a short incident response plan. Backups are what let you recover without paying; the rest stop the attack from landing.

Here’s why this matters for you specifically: according to Verizon’s 2025 Data Breach Investigations Report, ransomware was involved in 88% of small-business breaches — more than double the rate at large organizations.


What is ransomware, and how does it hit a small business?

Ransomware is malware that locks up your files (or steals them) and demands payment to release them. Modern attacks often do both: they encrypt your data and threaten to leak it — “double extortion” — so that even good backups don’t fully remove the pressure to pay.

A typical small-business attack unfolds in a predictable order:

  1. An employee clicks a phishing link or opens a malicious attachment, or an attacker logs in with a stolen password.
  2. The malware quietly spreads and looks for backups to destroy.
  3. Files are encrypted and a ransom note appears.
  4. The business is offered a “deal” — often six figures. (Verizon’s 2025 DBIR puts the median ransom at $115,000.)

Understanding that sequence is the key to stopping it, because each step has a defense.

How to protect your small business from ransomware: 7 steps

Step 1 — Keep offline or immutable backups (and test them)

This is the most important control, full stop. If you can restore your data, ransomware loses most of its power over you. Follow the 3-2-1 rule: three copies, on two types of media, with at least one offline or immutable — meaning the malware can’t reach or overwrite it.

Then do the part most businesses skip: test a restore. An untested backup is a guess. Full method in our data backup strategy guide.

Step 2 — Deploy endpoint detection and response (EDR)

Traditional antivirus waits to recognise known malware. EDR watches for the behaviour ransomware shows as it spreads — and can isolate a machine before encryption finishes. For a team without IT staff, a managed EDR adds 24/7 human eyes. See endpoint protection vs antivirus and our best EDR for small business picks.

Step 3 — Turn on MFA everywhere

A large share of ransomware attacks start not with malware but with a stolen password used to log straight in. Multi-factor authentication — ideally passkeys or hardware keys — blocks that path. Prioritise email, remote access (VPN/RDP), and admin accounts. Learn how in MFA for business.

Step 4 — Patch software promptly

Attackers exploit known, unpatched vulnerabilities — which featured in roughly 1 in 5 attacks in the 2025 DBIR. Turn on automatic updates for your operating systems, browsers, and business apps, and prioritise anything exposed to the internet.

Step 5 — Limit admin access (least privilege)

Ransomware does the most damage when it runs with administrator rights. Give staff only the access their role needs, use separate admin accounts for admin tasks, and review permissions regularly. This single habit can turn a company-wide disaster into a single-machine inconvenience.

Step 6 — Train staff to spot the lures

Because most attacks begin with phishing, your team is the front line. Short, frequent training plus simulated phishing measurably cuts click rates. Start with how to spot a phishing email and our security awareness training guide.

Step 7 — Write a one-page incident response plan

When an attack hits, improvising costs time and money. A simple plan — who to call, how to isolate machines, where backups live, when to involve your insurer — turns panic into a checklist. Use our incident response plan template.

What should you do if you’re hit by ransomware?

If ransomware is already running, act in this order:

  1. Isolate affected devices — disconnect them from the network and Wi-Fi to stop the spread. Don’t power them off if you can help it; that can destroy forensic evidence.
  2. Don’t pay yet, and don’t delete anything. Paying funds the next attack and doesn’t guarantee recovery.
  3. Call for help — your IT provider, managed security (MDR) service, and your cyber insurer, who often have an incident response team.
  4. Preserve evidence and identify the strain if you can.
  5. Restore from clean backups once you’re sure the attacker is out.
  6. Notify affected parties and regulators as required — see what to do after a data breach.

Should a small business pay the ransom?

The consensus from law enforcement is no, where it can possibly be avoided. Payment funds criminal operations, marks you as a willing payer, and offers no guarantee your data is returned or kept private. Encouragingly, Verizon’s 2025 DBIR found 64% of victims now refuse to pay, up from 50% two years earlier. The best position to be in is one where you don’t have to make the choice — which is exactly what tested backups give you.

Does cyber insurance cover ransomware?

Often, yes — many policies cover ransom payments, recovery costs, and downtime. But insurers increasingly require basic controls like MFA and tested backups before they’ll issue or pay out on a policy. Compare options in best cyber insurance for small business.


Frequently asked questions

What is the best protection against ransomware for a small business?

Tested, offline or immutable backups are the single best protection, because they let you recover without paying. Combine them with EDR and MFA to stop most attacks from landing in the first place.

Can ransomware spread to my backups?

Yes, if your backups are always connected and writable. That’s why the 3-2-1 rule calls for at least one offline or immutable copy that ransomware cannot reach or overwrite.

How does ransomware usually get into a small business?

Most commonly through phishing emails and stolen or weak passwords, and sometimes through unpatched, internet-facing software. Training, MFA, and prompt patching address all three.

Is antivirus enough to stop ransomware?

No. Antivirus catches known threats, but ransomware often uses new or behaviour-based techniques that only EDR detects. See endpoint protection vs antivirus.

Should I pay the ransom?

Avoid it if at all possible. Payment funds crime, doesn’t guarantee recovery, and can mark you as a future target. Tested backups are what let you say no.


Part of our cyber threats hub. Sources: Verizon 2025 Data Breach Investigations Report (DBIR). Last updated June 2026. General information, not legal advice.

Reviewed by Nhon Dang, CEO Sunteco Cloiud. See our editorial guidelines and affiliate disclosure.

Leave a Reply