Ransomware encrypts your files and demands payment. The businesses that survive it best are the ones that prepared before it happened. Here's the plan.
Before: make recovery boring
- Tested, offline backups — if your only backup is on the same network, it gets encrypted too. Keep an offline/immutable copy and actually restore from it once a quarter.
- Endpoint protection with rollback/EDR — see our antivirus comparison.
- Least-privilege access so one infected account can't spread.
During: stop the spread
Isolate affected devices from the network immediately (unplug Ethernet, disable Wi-Fi). Don't pay yet — and don't wipe evidence. Preserve logs.
After: recover and communicate
Restore from clean backups, reset credentials, and notify affected parties per your obligations (our breach checklist covers timing). Patch the entry point — usually phishing or an unpatched server.
Start with our ransomware protection guide and the 10-employee checklist.
Frequently Asked Questions
How often should I test my backup restoration?
Test backups quarterly at minimum. Verify you can restore files completely and that the restored data is clean (not infected). Document the restoration process and ensure multiple team members know how to execute it. Test both file restoration and full system recovery if possible.
What if we don't have cloud backups?
Local backups alone are risky - if ransomware encrypts your local network, it can encrypt local backups too. Use the 3-2-1 backup rule: 3 copies of data, 2 different media types, 1 offsite (cloud or physical media stored offsite). For businesses without reliable internet, consider offline backups that are physically disconnected after each backup.