Skip to content

How do we protect our organization from ransomware?

Short answer

Make it hard to get in, quick to spot, and possible to recover without paying. That means multi-factor authentication everywhere, prompt security updates, endpoint detection with someone watching around the clock, and backups attackers can't reach or delete, tested regularly. Then write down what you'll do on the day it happens.

Draft · pending expert review

Ransomware locks your files and systems until you pay. Most attackers now copy your data first, so they can threaten to publish it even if you restore from backup. They usually get in one of three ways: a phishing email, a stolen password on an account without multi-factor authentication, or an unpatched system that's reachable from the internet.

Keep them out

  • Multi-factor authentication on email, remote access, and every admin account
  • Security updates applied promptly, especially on firewalls, VPNs, and anything reachable from the internet
  • Email filtering and short, regular training, so fewer malicious links arrive and fewer get clicked
  • No everyday admin rights. People work in standard accounts; admin access is separate and limited

Catch it early

Endpoint detection and response (EDR) watches for the behavior ransomware depends on, such as encrypting files en masse, and can stop it. Attacks often start at night, on weekends, or over holidays, so someone has to act on those alerts at any hour. That's what managed detection and response (MDR) adds.

Be able to recover without paying

  • Keep at least one backup copy that can't be changed or deleted from your network. Attackers look for backups first
  • Back up Microsoft 365 too: email, OneDrive, SharePoint, and Teams
  • Test restores on a schedule. A backup you've never restored from is a hope, not a plan

Plan for the bad day

  • A written incident response plan: who decides, who to call, and how to reach people if email is down
  • Your cyber insurer's claims hotline, saved somewhere other than your network
  • Your notification duties to clients and regulators, which can come with strict deadlines in healthcare and financial services

Should you pay?

The FBI advises against it. Paying doesn't guarantee you'll get your data back or that stolen copies will be deleted, and paying some groups can violate U.S. sanctions. If it happens, bring in your insurer, legal counsel, and your IT team before anyone decides.

  • HOW TO Enable ONEDRIVE on startup2023
  • How to Create a Rule in Outlook to Delete Emails2016 · recorded on an older version; menus may look different
  • How to Select All Emails in Outlook2016 · recorded on an older version; menus may look different

Talk to a person, not a ticket

Tell us what's going on. We'll listen, ask good questions, and give you a straight answer about whether we can help.

Call us