Why this matters
Ransomware encrypts your files and demands payment to unlock them. It can stop a business from trading for days or weeks. Most ransomware starts with a phishing email, a stolen password or an unpatched system, so a few well-chosen controls make a big difference.
What you'll need
- A list of your business devices and systems
- Admin access or your IT provider
- Your current backup arrangements
Step-by-step instructions
Step 1
Turn on MFA everywhere
Enable MFA on email, Microsoft 365, remote access, accounting software and admin accounts. Stolen passwords are a leading entry point for ransomware.
Step 2
Keep systems and apps patched
Turn on automatic updates for Windows, browsers, Office and other software. Prioritise anything that faces the internet, such as firewalls and VPNs.
Step 3
Restrict administrator rights
Staff should use standard accounts for daily work. Admin accounts should be separate and used only when needed.
Step 4
Use reputable endpoint protection
Make sure every computer has active, centrally monitored antivirus or endpoint detection, such as Microsoft Defender for Business.
Step 5
Keep offline or immutable backups
Ransomware often tries to delete backups. Keep at least one copy that is offline or cannot be altered, and include cloud data like Microsoft 365.
Step 6
Train staff to spot phishing
Short, regular awareness training and a simple way to report suspicious emails reduce the chance of the first click.
Step 7
Write down what to do if it happens
A one-page incident plan with who to call, how to isolate devices and where backups are kept saves critical time.
Summary
MFA, patching, limited admin rights, good endpoint protection and tested offline backups together make ransomware far less likely and far less damaging.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.