All resources Resources

A 5-step plan to keep ransomware from shutting you down

Ransomware isn't a sudden movie-style attack. It's usually a slow build that starts days or even weeks before any files get locked, often with something completely ordinary, like a login that should never have worked in the first place.

That's why protecting your business is about much more than installing anti-virus. It's about stopping an unwelcome visitor from quietly getting a foothold and spreading. Below is the plain-English, five-step plan we walk our clients through. None of it requires an enterprise budget, and none of it turns security into a daily chore.

Why ransomware is so hard to stop once it's started

An attack is rarely a single moment. It's a sequence: someone gets in, gives themselves more access, moves from one computer to another, finds your important data, and only locks everything up at the very end, once they can do the most damage.

Waiting until that final stage to react gets messy fast. By the time files start locking, an intruder who already has a valid login and the right permissions can move faster than anyone can investigate. As Microsoft puts it, attackers today often aren't breaking in at all. They're simply logging in.

At that point your options are limited. Law enforcement and security agencies are consistent on this: don't pay the ransom. There's no guarantee you'll get your data back, and paying only encourages the next attack.

There's no single magic fix. The plan that works is one that breaks the chain early, and makes sure that, if the worst happens, getting back to work is something you've already practised rather than something you're improvising under pressure.

The 5-step plan

Each step does one of three jobs: make it harder to get in, limit the damage if someone does, and make recovery dependable. They're meant to be practical and repeatable: start with the weakest spot and work down the list.

1. Make sign-ins hard to fake

Most ransomware still starts with a stolen password. The quickest win is to make a password alone useless to an attacker. That's what multi-factor authentication does: signing in takes the password plus a second step, usually a tap on your phone. The goal is sign-ins that hold up even when someone is specifically targeting you, not just a box that says "MFA is on."

  • Turn on multi-factor authentication for every account, starting with admin accounts and anything used to log in remotely.
  • Retire old, weaker sign-in methods that quietly leave a back door open.
  • Add extra checks for risky sign-ins: a new device, an unusual location, or a login at 3 a.m. from another country.

2. Give everyone only the access they actually need

This is the idea that each person's account can reach only what their job requires, and nothing more. Just as importantly, the powerful "administrator" accounts that can change everything should be kept separate from the ones people use for everyday work, so one compromised login doesn't hand over the whole business.

  • Keep admin accounts separate from day-to-day user accounts.
  • Get rid of shared logins, and trim the "everyone can access this" groups.
  • Limit the powerful tools to the few people and devices that genuinely need them.

3. Close the doors attackers already know about

Most break-ins use holes that are already well known, usually because a system is running outdated software or is exposed to the internet without protection. Closing these removes the easy wins before anyone can use them.

  • Set clear rules for updates: critical fixes go on right away, high-risk ones next, everything else on a steady schedule.
  • Prioritise anything facing the internet or used for remote access.
  • Don't forget the other programs you run, not just Windows or macOS itself.

4. Spot trouble early

The aim is to catch the warning signs before files start locking: an alert about unusual behaviour you can act on, not a support ticket saying documents suddenly won't open.

  • Monitor your computers so suspicious activity gets flagged quickly.
  • Agree in advance what gets dealt with immediately and what can wait for review.

5. Keep backups safe, and prove they work

A good backup is the difference between a bad afternoon and a disaster. But it only counts if an attacker can't reach it and you've actually tested that you can restore from it. Security agencies on both sides of the Atlantic say the same thing: backups need to be both protected and genuinely restorable.

  • Keep at least one backup copy isolated from the rest of your systems.
  • Run a test restore on a regular schedule: a backup you've never restored from is a guess, not a safety net.
  • Decide ahead of time what gets restored first if you ever need it.

The goal: stay out of crisis mode

Ransomware thrives when everything is reactive: when an incident feels urgent, unclear, and improvised. This plan does the opposite. It turns the usual weak spots into settled, predictable defaults.

You don't have to rebuild everything overnight. Pick the weakest link, tighten it, and make that the new normal. When the basics are consistently in place and regularly tested, a ransomware attempt goes from a business-stopping crisis to a contained problem you're ready for.

If you'd like a second set of eyes on where you stand today, that's exactly what we do, in plain English, with no pressure. A free IT check-up is an easy place to start.

Worried ransomware could stop your business?

Book a free IT check-up and we'll tell you, in plain English, where you're exposed and what we'd shore up first.

Get started