Ransomware isn’t slowing down. Attackers have shifted away from big, headline-grabbing targets toward small and mid-sized businesses, because the payoff-to-effort ratio is better: fewer defences, faster payouts, less public scrutiny. Most SMBs still run on the assumption that they’re “too small to be a target.” That assumption is the single biggest reason attacks succeed.
The plan most businesses have isn’t a plan
Ask most business owners what happens if ransomware hits, and the answer is usually some version of “we have backups.” That’s a start, not a plan. A backup that hasn’t been tested is a hope, not a recovery strategy. We regularly see businesses discover, mid-incident, that their backup jobs had been silently failing for weeks, or that the backups themselves were sitting on the same network the ransomware had already encrypted.
A real response plan answers questions before the incident, not during it: who makes the call to isolate systems, who contacts insurers and legal counsel, who communicates with staff and clients, and how quickly can operations actually resume from backup. If nobody in your business could answer those questions right now, that’s the gap to close first.
What actually needs to be in place
1. Backups that are tested, not just scheduled
Backups need to be immutable or air-gapped from the production network, and restored on a schedule, not just backed up on one. A backup you’ve never restored from is an assumption, not a safety net.
2. Endpoint detection that watches behaviour, not just signatures
Traditional antivirus looks for known malware signatures. Modern ransomware is often unrecognisable to signature-based tools because it’s assembled from legitimate system processes. Behaviour-based endpoint detection and response (EDR) catches the pattern, not the fingerprint, and can isolate an infected device automatically before it spreads.
3. Multi-factor authentication, everywhere
The overwhelming majority of ransomware incidents we see start with a compromised credential, not a sophisticated exploit. MFA on email, VPN, remote desktop and admin accounts closes off the most common entry point almost entirely.
4. Least-privilege access
If every user account has local admin rights, one compromised laptop can become a foothold across the whole network. Restricting admin rights to the accounts that genuinely need them limits how far an attacker can move once they’re in.
5. Patching that isn’t optional
A large share of ransomware still exploits vulnerabilities that had a patch available months earlier. A managed patching cadence, covering the operating system and third-party applications, removes a huge amount of low-hanging fruit.
If it does happen
Speed matters more than almost anything else once an incident starts. Isolating affected systems within minutes, rather than hours, is often the difference between a contained incident and a business-wide outage. That’s why the response plan needs to exist before the attack, with clear ownership and a tested recovery path, not assembled from scratch while systems are down and the clock is running.
Ransomware readiness isn’t a single product. It’s backups, detection, access control and patching working together, with a plan for the day it still gets through. Most businesses have one or two of those pieces. Very few have all of them tested and working together.