Ransomware hit a company near you: here's what they should have had

When ransomware hits a company in your area, it's never because they were targeted by something too advanced to stop. It's because they were missing one or more of the same few things every time. The good news is these aren't complicated or expensive. They're just things companies have to actually do.
Backups that aren't connected to the network
This one stops most ransomware cold. Ransomware encrypts your files to hold them for ransom. If you have a copy that the malware can't reach, you just restore it and you're done. No payment, no negotiation.
The critical part is that your backups have to be disconnected from the network, at least most of the time. If everything on your system can talk to everything else, the ransomware can find the backup and encrypt that too. You need backups that sit offline, on a separate drive or in cloud storage configured so the attacker can't access them even if they compromise your main systems.
This alone stops a ransomware attack from being a ransom situation. It becomes an inconvenience. You know you can recover, so you just do it.
Employees who can spot a phishing email
Ransomware usually gets in because someone clicked a malicious link or opened a dangerous attachment. Phishing emails look like they're from a trusted source, but they're bait. A Finance invoice from your accounting software. A delivery notification from a carrier. A password reset request from your email provider.
The attacker is counting on muscle memory and trust. Your employee is used to getting these emails, so they don't really read it. They just click.
Training people to spot these takes maybe an hour a year. Real training, not a quick video. Teaching them to slow down, check the sender's actual email address (not just the display name), look for generic greetings like "Dear User," and notice when links don't match what they claim to be. The difference between employees who can catch this and ones who can't is just time spent paying attention.
Passwords that are actually strong
A weak password on an admin account is an invitation. Ransomware operators often buy lists of known passwords from the dark web, or they use simple brute force attacks. They try common passwords first: "Password123," "Admin," "Company2024." If that works, they're in.
Strong passwords have at least 12 characters and mix uppercase, lowercase, numbers, and symbols. "Tr0pic@lMango!2024" is strong. "password" is not. Neither is something based on the company name or the system they're logging into.
But here's what actually happens in most companies: people use weak passwords because they have to remember them. That's why password managers exist. A password manager stores strong passwords securely so people don't have to remember anything except one master password. This takes maybe an hour to set up for a small team and solves the problem entirely. If your company is still asking people to remember complex passwords, you're creating the problem you're trying to solve.
Software updates that actually happen
Ransomware often gets in through known vulnerabilities in software. Microsoft releases patches for Windows. Adobe releases patches for Reader. Your accounting software releases patches. These exist because someone discovered a security flaw and the software company fixed it.
If you're not installing these patches, you're leaving the door open. Ransomware operators scan networks for systems that are still running old versions of software with known flaws. It's like having a broken lock on a door and complaining about it but not calling the locksmith.
The challenge is that updates sometimes require a restart or briefly interrupt work. But delaying them by months is just choosing to risk your business instead. Set a schedule. Make it a routine thing that happens when you're closed or on a weekend. Communicate it so people expect it. This isn't optional.
Actual monitoring of what's happening
If someone's in your network copying sensitive files or moving toward admin accounts, you probably don't know about it yet. By the time the ransomware encrypts everything, it's way too late.
Small companies often think monitoring is out of reach, but it doesn't have to be expensive. You need visibility into what's happening on your systems. That might be basic logs you review, cloud-based tools that watch for suspicious activity, or someone on your team checking in regularly. The point is you have to know if something weird is going on before the malware activates.
When someone logs in from a country they've never accessed the system from, or starts accessing files they usually don't touch, or copies large amounts of data, that's worth paying attention to. You catch that before the encryption starts and you stop the attack before it matters.
Most companies that get hit with ransomware are missing at least three of these things. Often all five. None of them are new ideas. None of them are cutting-edge technology. They're the basics, and they work because ransomware operators look for the easy targets. Make yourself a harder target and they move on to someone else.
