Skip to main content
Guides

The Small Business Owner's Guide to Ransomware (No Jargon, We Promise)

By Priya Nair3 min read

Ransomware is the one topic every business owner has heard of and almost nobody can explain. That's by design: the security industry loves jargon. This guide skips it. By the end you'll know what ransomware actually is, how it gets into small businesses, the five protections that genuinely matter, and exactly what to do in the first hour if it ever happens to you.

What ransomware actually is#

Imagine someone breaks into your office overnight, changes every lock in the building, and leaves a note offering to sell you the new keys. That's ransomware. Malicious software scrambles (encrypts) your files so they're unreadable, then the attacker demands payment to unscramble them. Modern crews add a second threat: pay up, or we publish your files online.

How it usually gets in#

  • Phishing emails. A convincing invoice, shipping notice, or voicemail attachment that someone on your team clicks. Still the number one entry point.

  • Stolen passwords. Credentials leaked from some other website get tried against your email and VPN. If you reuse passwords, this works.

  • Unpatched software. Known security holes in operating systems, firewalls, and remote access tools that never got updated.

  • Remote access left open. Remote desktop exposed to the internet so an old vendor or former employee account becomes a front door.

The five protections that actually matter#

  1. Multi-factor authentication everywhere. Email, VPN, banking, line-of-business apps. A stolen password alone should never be enough.

  2. Automatic patching. Updates applied on a schedule by policy, not when someone remembers.

  3. Managed EDR on every device. Modern endpoint protection can spot encryption behavior and isolate a machine in seconds, but only if someone is watching the alerts.

  4. Backups that follow the 3-2-1 rule. Three copies, two different types of storage, one offsite. At least one copy should be immutable, meaning the attacker can't encrypt or delete it even with admin access.

  5. Quarterly team training. Your people are the last line of defense. Short, regular training beats one long annual lecture every time.

If the worst happens: your first hour#

  1. Disconnect, don't power off. Pull the network cable or kill the Wi-Fi on affected machines. Leave them running; memory can hold evidence that helps recovery.

  2. Call your IT team or incident line immediately. Minutes matter. Containment is the whole game.

  3. Don't communicate from compromised accounts. Use phones or personal email until your tenant is confirmed clean.

  4. Don't pay before getting advice. Talk to your insurer and an incident response professional first. Payment doesn't guarantee recovery and may have legal implications.

  5. Notify your cyber insurance carrier. Most policies require prompt notice, and many include response resources you've already paid for.


None of this requires an enterprise budget. It requires doing the basics consistently, which is exactly what a good managed security service is for. If you'd like to know where your business stands, we'll check, free, no strings.

Get a free ransomware readiness check

Stay in the loop

Get new posts in your inbox. No spam, unsubscribe anytime.

More to read

Guides

10 Signs It's Time to Stop Doing Your Own IT

If the "computer person" at your company is whoever is youngest, or your server lives next to the mop sink, this one's for you. Ten honest signs your business has outgrown DIY IT, and what to do about it.

Marcus Webb2 min read