Ransomware is software that encrypts every file it can reach, on the computer it lands on and on every shared drive connected to it, then demands a payment for the key. The stories in the news are about hospitals and councils. The everyday victims are small businesses, because they have money, they cannot work without their files, and they have no one whose job it is to prevent it.
How it gets in
Almost always one of three ways:
- An email attachment or link that someone opens. An invoice, a shipping notice, a document to review. The person did nothing unusual; the message was convincing.
- A stolen password for email or for remote access to a computer, used to sign in and install the software directly. Passwords are stolen by phishing or bought from earlier breaches.
- Software that was not updated. A known weakness in an old program, an old Windows, or a router, used to get in without anyone doing anything.
Antivirus catches some ransomware and misses the rest, because the software is changed daily to get past it. It is worth having, and it is not the defence.
The three things that stop it
1. A backup the ransomware cannot reach
This is the one that matters. A business with a good backup restores its files and carries on. A business without one pays, or closes.
The backup has to be one the ransomware cannot encrypt along with everything else. That rules out a drive that is permanently plugged in and a shared folder on the network, because those are just more files to encrypt. What works:
- An online backup service that keeps old versions of files, so you can go back to before the attack.
- A drive that is disconnected after each backup, kept somewhere else, and rotated with a second one.
- For Microsoft 365 or Google Workspace, a separate backup of the mailboxes and files, because the built-in version history is not designed for this and can be deleted by an intruder with the right access.
Our simple backup plan describes a setup that meets this test. Then test the restore. A backup that has never been restored is a hope, not a plan.
2. Two-step sign-in on email and on remote access
Most ransomware attacks on small businesses start with a password. Two-step sign-in, where a code from a phone is also required, makes a stolen password useless. Turn it on for every email account, for any remote desktop or remote access tool, and for the router's remote management if it has one. It is free and it takes ten minutes per account.
3. Updates, applied
Windows, macOS, the browser, Office, the router. Set them all to update automatically, and restart when asked. An old program with a known hole is the way in that needs nobody to click anything. Computers still on Windows 10 need to be dealt with; our guide to old PCs after Windows 10 support goes through the options.
Things that help as well
- Do not let everyone be an administrator. Day-to-day accounts should be standard users. Ransomware running as a standard user does less damage.
- Turn on Controlled folder access in Windows Security, which blocks unknown programs from changing documents.
- Limit what the shared drive lets each person write to. Ransomware encrypts what its victim can write to, and no more.
- Tell staff what a suspicious message looks like, and make it easy and blameless to report one. The person who opened the attachment is not the problem; the missing backup is.
If it happens
Disconnect the affected computer from the network at once, by pulling the cable or turning off Wi-Fi, and do not turn it off, because evidence is lost. Do not pay before talking to someone who deals with this; payment does not always bring the key, and it marks the business as a payer. Report it to the FBI at ic3.gov. Then restore from the backup onto a clean machine.
Cyber insurance
Insurers now ask exactly the questions above: do you have offline backups, two-step sign-in and updates? A business that can answer yes gets cover at a sensible price. A business that cannot may not get cover at all. Getting the three things in place is worth doing for that reason alone.
Where we come in
We put the three defences in place for small businesses, test the restore, and write down what to do on the day so that nobody has to work it out under pressure. It is a few hours of work and it is the best value security spend a small business can make.