Ransomware feels like it hits all at once — you arrive Monday and the files are locked. In truth, most attacks build over days or weeks. Someone gets in, looks around, grabs more access, then triggers the lock at the end. That slow build is good news. It means there are many points where you can break the chain before anything gets encrypted.
Most attackers today don’t smash a window. They log in with a password that was stolen or guessed. So the plan below is less about fancy tools and more about closing the doors they walk through. Law enforcement still advises against paying a ransom — payment doesn’t guarantee your files back, and it marks you as a target for next time.
Step 1: Make sign-ins hard to fake
Turn on multi-factor sign-in, and choose a form that resists fake login pages and stolen codes. Start with admin accounts and anything reachable from the internet. Remove old sign-in methods that skip it. Add rules that ask for extra proof when a login looks odd — new country, new device, strange hour.
Step 2: Give people only the access they need
Most staff don’t need admin rights, and admins shouldn’t use those rights for daily email and browsing. Keep admin accounts separate. Drop shared logins nobody can trace. The less each account can reach, the less an attacker gains by stealing it.
Step 3: Close the holes you already know about
Attackers love known weak spots that were never patched. Set a simple rule: fix critical problems fast, and start with anything facing the internet or used for remote access. Don’t forget the extra apps and plug-ins you installed years ago — those count too.
Step 4: Catch it early
The gap between “someone got in” and “files are locked” is your chance. Watch for odd behavior — a normal account suddenly touching files it never uses, or trying to reach many systems at once. Set alerts that reach a real person quickly, not a report nobody reads until Friday.
Step 5: Keep backups you’ve actually tested
Backups are what let you say no to a ransom — but only if they work. Keep at least one copy separated from your main systems, so the same attack can’t lock it too. Then test a restore on a schedule. Decide in advance what comes back first, so recovery day isn’t the day you start planning. This is core cybersecurity hygiene, not a luxury.
Ransomware is a chain of small steps, not a single blow. Break it early: make sign-ins hard to fake, limit what each account can reach, patch the obvious holes, watch for odd behavior, and keep a tested backup you can restore without paying anyone. Any one link you break can stop the whole attack.
A few fair questions
If we have backups, do we still need the rest?
Yes. Backups get you running again, but a lock-up still means downtime, cleanup, and possibly stolen data. The earlier steps stop the attack before it costs you those days.
Should we ever pay the ransom?
It’s your call, but the odds are poor. Some keys don’t work, some attackers come back, and paying funds the next attack. A tested backup is a far better plan than hoping a criminal keeps a promise.
Does cyber insurance require any of this?
More every year. Multi-factor sign-in, backups, and fast patching now show up on renewal forms. Our cyber-insurance renewal checklist covers what insurers ask before they’ll cover you.
Want a straight read on where your defenses stand today? Book 15 minutes with Wayne Libonati, President & CEO. Prefer to start on your own? Score your current IT relationship in about 3 minutes.