Ransomware is the scenario that keeps business owners up at night: one morning your files, your accounts, your customer records are all scrambled, and a message on screen demands payment to get them back. It usually starts with something small, like a clicked link or an infected attachment. For a small business, the real damage is often the days of downtime, not just the ransom.
How it gets in
Most ransomware arrives through a phishing email, a dodgy download, or an unpatched system left open to the internet. It often sits quietly for a while before it strikes, spreading across shared drives so it can lock as much as possible at once.
Backups are your real insurance
If you have a recent, working backup that the ransomware cannot reach, you can restore and carry on. The key words are recent and cannot reach, because a backup left permanently connected can be encrypted along with everything else.
Follow the 3-2-1 rule
Keep three copies of important data, on two different types of storage, with one kept off site or offline. It sounds technical, but the idea is simple: never let a single event destroy every copy at once.
Test that a restore actually works
A backup you have never restored from is only a hope. Every so often, prove you can get a file back. Plenty of businesses discover their backups were failing silently only at the worst possible moment.
Paying is a last resort, and no guarantee
Paying a ransom does not always get your files back, and it marks you as someone who will pay again. UK guidance from the NCSC and Action Fraud is to report the attack and seek help rather than pay. Prevention and good backups are far cheaper than the alternative.
Red flags to watch for
- Files suddenly renamed with a strange extension, or that will no longer open.
- A full screen message or text file demanding payment, often in cryptocurrency.
- Programs or documents that are unusually slow or start behaving oddly across the network.
- Antivirus or security tools being switched off without anyone doing it.
- A backup drive that is always plugged in and always writable, giving the malware a path to your only copy.
- Staff reporting a clicked link or opened attachment shortly before things went wrong.
Check yourself
0/31.Which of these gives a small business the best chance of recovering from a ransomware attack without paying?
2.Why is a backup drive that stays permanently plugged in and writable a weak defence against ransomware?
3.What does the 3-2-1 backup rule stand for?
This is general guidance, not a substitute for advice on your specific setup. Want a hand putting it into practice? Talk to us or see our care plans.
