Ransomware preparation combines prevention, early detection, containment authority, and reliable restoration. Reduce exposed services and privileges, patch supported systems, protect administrator access, keep isolated tested backups, inventory critical operations, and practice an incident plan. If an event occurs, preserve evidence and coordinate qualified responders rather than improvising destructive cleanup.
Who this is for: Owners, IT generalists, and operational leaders preparing small organizations to withstand and recover from ransomware incidents.
- Know which systems and data must return first for the organization to operate safely.
- Maintain multiple protected backup copies and prove restoration with regular exercises.
- Preassign containment, legal, insurance, communications, and external response contacts before an emergency.
Prioritize essential operations
List services required for safety, payroll, customer communication, scheduling, identity, production, and regulatory records. Identify owners, dependencies, maximum tolerable interruption, and manual alternatives. A complete device inventory matters, but recovery priority should follow business consequence rather than hardware price or organizational seniority.
Map where critical data lives, how systems authenticate, and which administrators can change or delete it. Remove dormant accounts and unsupported services where practical. Segment administrative access, require strong multifactor authentication, and give ordinary users and workloads only the permissions they need. Avoid using domain-wide authority for daily support.
Build recoverable backups
Keep protected copies separated from normal production credentials and reachable paths. Use versioning, immutability, or offline storage as appropriate to the service. Encrypt backups, restrict their administrators, monitor deletion or policy changes, and retain enough history to recover from an incident discovered late. A synchronized folder alone is not a recovery strategy.
Test restoration, not just backup completion. Select representative servers, files, identity configuration, and application data, restore into an isolated environment, validate integrity, and record time plus dependencies. Include backup catalog and encryption-key recovery. Resolve failures with owners and repeat until the organization can meet its recovery objectives.
Prepare containment and communication
Define who may isolate networks, disable accounts, stop services, engage external responders, notify insurers, and approve public communication. Keep contacts available outside normal systems. Establish an alternate communication method in case email or identity is unavailable. Preserve contractual and official reporting contacts without inventing universal legal deadlines.
Document immediate priorities: protect people, prevent further spread, preserve evidence, maintain critical operations, and avoid uncoordinated changes. Staff should report unusual encryption notices, inaccessible shared files, or widespread errors promptly. They should not contact an actor, pay, delete evidence, or run random cleanup tools without authorized leadership and qualified advice.
Exercise and improve the plan
Run a tabletop exercise that begins with an ordinary symptom and forces decisions about isolation, identity, backups, customer service, and external support. Use synthetic facts and systems. Then conduct a separate technical restore test. Record decisions, missing authority, inaccessible contacts, failed assumptions, and recovery timing.
Patch high-risk supported systems, reduce exposed remote access, review administrator roles, and monitor endpoint, identity, and backup alerts. Revisit CISA guidance, inventories, contacts, insurance conditions, backup evidence, and recovery priorities quarterly. After an exercise or incident, assign improvements and verify them instead of merely updating the plan date.
Prepare a small accounting firm
A 25-person firm depends on cloud identity, shared client files, tax software, email, and one local document server.
- Rank identity, client records, current filings, communications, and payroll by operational consequence and dependency.
- Remove unused remote access, separate administrator accounts, require strong MFA, and narrow file permissions.
- Create protected cloud and offline backup copies under separate credentials, including server and identity configuration.
- Restore synthetic client folders and the document service into isolation, then record integrity and recovery time.
- Run a tabletop using external contacts and alternate communications, assign gaps, and schedule the quarterly repeat.
Ransomware readiness playbook
Maintain this playbook offline and review it with organizational leadership.
- Critical operations: service, owner, dependency, recovery order, time objective, and manual fallback.
- Protection: supported systems, patch ownership, MFA, segmented administration, least privilege, and monitoring.
- Backups: data set, frequency, isolated copy, administrator, retention, restore evidence, and key recovery.
- Response: isolation authority, responders, insurer, counsel, communications, alternate channel, and evidence lead.
- Exercise: scenario, decisions, restoration test, measured gaps, assigned fixes, and next quarterly date.
Common mistakes
- Counting synchronized production files as a backup without protected history or separate access.
- Giving backup administration to the same everyday account that manages endpoints and file shares.
- Waiting for an incident to decide who may isolate systems, contact responders, or communicate with customers.
Try one
A small clinic says its cloud drive is backed up because deleted files remain for thirty days. Evaluate the preparation gap.
A strong answer asks whether production administrators or compromised identities can delete versions, whether retention covers delayed discovery, and whether identity, application configuration, and other critical systems are included. It calls for separately protected copies, least-privilege backup administration, isolated restoration tests with synthetic data, measured recovery order, offline contacts, and qualified escalation. It avoids making legal guarantees about health records.
Sources
- CISA StopRansomware GuideCISA defensive preparation and response guidance for ransomware incidents.
- CISA Cyber EssentialsCISA baseline actions for leaders and small organizations managing cyber risk.