What Is Ransomware? How Small Businesses Can Prepare, Protect and Recover
Updated: Aug 27

Originally published May 2022 | Substantially updated August 2026
When I originally wrote this article in 2022, I described ransomware mostly as something that started with a phishing email. An employee clicked a malicious link or downloaded a file, ransomware infected the computer, files became encrypted, and the business was presented with a demand for money to get them back. That can still happen, but four years later I would not explain ransomware to a small business owner that simply.
Ransomware has evolved, and so has the way I think businesses need to prepare for it. I am still concerned about employees clicking malicious links, but I am also concerned about compromised credentials, remote access, unpatched systems, vulnerabilities, administrative privileges, what an attacker can reach after getting inside the environment, whether data can be stolen, whether backups are accessible from the same environment, and whether the business has a realistic plan for responding and recovering. Protecting a small business from ransomware is not about finding one security product that stops everything. It is about putting layers in place so an attacker has fewer ways in, less ability to move around if something is compromised, a better chance of being detected, and fewer opportunities to take the entire business down.
That broader view is also reflected in current federal guidance. In June 2026, the National Institute of Standards and Technology released an updated Ransomware Risk Management profile aligned with the NIST Cybersecurity Framework 2.0. Rather than treating ransomware as a single technical problem, NIST addresses ransomware across governance, identification, protection, detection, response and recovery. That is much closer to how I think small businesses should approach the problem today.
What Is Ransomware?
Ransomware is a type of malicious attack that can prevent a business from accessing its systems or information, commonly through encryption, while an attacker demands payment. Modern ransomware attacks can also involve stealing information before systems are encrypted. The attacker may then threaten to publish or disclose the stolen information if the victim refuses to pay. This combination of encryption and data theft is often referred to as double extortion.
That distinction is important because it changes the conversation around recovery. If ransomware only meant that your files were encrypted, having a clean backup could potentially solve a large part of the problem. If an attacker spent time inside the environment before the encryption occurred, stole company or customer information, obtained credentials, accessed cloud systems, changed configurations, or established another way back into the network, restoring yesterday's backup does not answer all of those questions.
The visible ransomware message may actually be one of the last things that happens.
By the time someone walks into the office and discovers that files will not open, servers are unavailable, or a ransom note has appeared, the attacker may have already been in the environment for some period of time. That is why responding to ransomware should involve understanding what happened, what systems and accounts were affected, what the attacker may have accessed, and whether the environment is safe to restore.
How Does Ransomware Get Into a Small Business?
Phishing is still one possible path, but it is not the only one. Current CISA ransomware guidance specifically addresses compromised credentials, vulnerable or poorly secured remote services, VPNs, internet facing systems, software vulnerabilities, malicious downloads, third parties and other methods attackers can use to establish initial access.
That matters because I do not want a business owner believing that ransomware prevention consists of telling employees not to click suspicious emails. Employee awareness is important, but even a very cautious employee cannot compensate for an unpatched internet facing device, an exposed remote access service, a compromised administrator account, or another technical weakness elsewhere in the environment.
Some of the areas I would want to understand include:
Area | Why I Care About It |
User identities and credentials | Stolen credentials can give an attacker legitimate looking access to business systems. |
MFA and authentication | Strong authentication can make stolen credentials harder to use, particularly when phishing resistant methods are available. |
Remote access | VPNs, RDP, remote support tools and other remote access methods can become entry points if they are exposed, outdated or poorly secured. |
Software and firmware | Known vulnerabilities in operating systems, applications, firewalls, VPN appliances and other devices can provide another way into the environment. |
Administrative privileges | Excessive privileges can allow a compromised account or device to cause considerably more damage. |
Endpoint security | Endpoint protection and EDR can help identify and respond to suspicious activity on computers and servers. |
Network design | A flat network can make it easier for an attacker to reach additional systems after gaining access. |
Logging and monitoring | Useful logs can help identify suspicious activity and can become extremely important during an investigation. |
Backups | Backups that an attacker can reach, encrypt or delete may not be available when the business needs them most. |
Incident response | The business needs to know who is responsible for making decisions and what happens when an incident is discovered. |
None of those controls guarantees that ransomware cannot happen. The purpose of layered security is to avoid depending on one control to do everything.
Does MFA Stop Ransomware?
MFA is an important security control, but I would never tell a client that enabling MFA means the business is now protected from ransomware.
Current CISA guidance recommends phishing resistant MFA, particularly for email, VPNs and accounts that can access critical systems. That is an important distinction because not every MFA method provides the same level of resistance to phishing. Authentication technology continues to change, which is one of the reasons I look at the authentication methods actually being used when I perform a Microsoft 365 Tenant Security Review.
MFA is one layer. I still care about what an account can access after authentication, whether users have more privileges than they need, whether old accounts still exist, how administrative accounts are handled, what devices are trusted, what remote access methods are available, and whether unusual activity can actually be detected.
If an attacker gets through one layer, I want another layer waiting behind it.
Can Endpoint Protection Stop Ransomware?
Endpoint security is another important layer, but owning an antivirus or endpoint protection subscription does not automatically tell me that the business is protected. I want to know which devices are covered, whether the security agent is actually installed and healthy, whether policies are configured appropriately, whether alerts are being generated, who receives those alerts, and what happens when something suspicious is detected.
Modern endpoint detection and response capabilities can provide visibility that traditional antivirus alone was not designed to provide. They can help detect suspicious behaviors, malicious processes, credential activity and other indicators that may occur during an attack. CISA includes endpoint detection and response among the tools that can help organizations investigate abnormal activity and lateral movement.
The important part for a small business owner is understanding the difference between buying security software and managing security. A security product that nobody reviews, an agent that stopped reporting six months ago, or protection that was never installed on several computers does not provide the same value as a security environment that is actually configured and maintained.
That same principle applies to Microsoft 365, firewalls, backups, MFA and almost every other security control I work with. Owning the technology and knowing that it is properly configured are two different things.
Why Network Segmentation Matters During a Ransomware Attack
Once an attacker or malicious software gets into one device, another question becomes extremely important: what can it reach from there?
This is where network segmentation can matter. CISA recommends separating network resources to help contain an intrusion and limit an attacker's ability to move laterally through an environment. That does not mean every five person business needs an enormously complicated network with dozens of VLANs. The design needs to make sense for the actual business.
I do, however, want to understand why employee computers, servers, guest devices, cameras, IoT equipment, building systems and other devices are able to communicate with one another. Sometimes there is a legitimate business reason. Sometimes they were simply placed on the same network because that was the easiest way to set everything up.
This connects directly to the broader networking work I have been discussing in my recent articles. In Guest WiFi for Small Business: Why Managed WiFi and Network Segmentation Matter, I explain why guest and IoT devices do not necessarily belong on the same network as business systems. Network segmentation is not only a WiFi consideration. It can also become part of limiting what an attacker can reach if something inside the environment is compromised.
Can Ransomware Infect or Delete Backups?
This is one of the questions I especially want small businesses to understand because having backups and having recoverable backups are not necessarily the same thing.
Current CISA ransomware guidance recommends maintaining offline, encrypted backups of critical data and regularly testing their availability and integrity. CISA also specifically warns that ransomware variants may attempt to find and encrypt or delete accessible backups to make recovery more difficult.
That means I want to know much more than whether someone can answer “yes” when I ask if the company has backups.
I want to know what is being backed up. I want to know where the backups are stored, how frequently they run, what credentials or systems can access them, whether there are protected or immutable copies where appropriate, how long data is retained, and whether anyone has actually restored something from those backups recently enough to know the recovery process works.
I also want to understand what is not being backed up. A business may be protecting a local server while assuming Microsoft 365, a cloud application or another service is covered somewhere else. Another business may have excellent file backups but no documented way to rebuild the server or application those files depend on. A third may have backups that technically contain the data but cannot meet the timeframe in which the business needs to resume operations.
A successful backup job is good.
A tested recovery process tells me considerably more.
Ransomware Recovery Is More Than Restoring Yesterday's Backup
This is another area where my thinking has changed since I wrote the original article.
If a business discovers ransomware, I do not want the first reaction to be wiping computers and immediately restoring everything from backup. Before recovery begins, we need to understand the scope of the incident well enough to avoid restoring clean data into an environment that is still compromised.
CISA's ransomware response guidance recommends determining which systems were impacted, isolating affected systems, identifying accounts and systems involved in the breach, examining security tools and logs, prioritizing critical systems for recovery, and then restoring data to a clean environment from protected backups. CISA specifically cautions organizations to avoid reinfecting clean systems during recovery.
For a small business, that can create a difficult balance. The owner understandably wants everyone working again as quickly as possible. At the same time, restoring too quickly without understanding what happened can create another problem.
This is why I think incident response and disaster recovery need to work together.
Incident response asks what happened, what needs to be contained, what information needs to be preserved, who needs to be involved, and what systems can currently be trusted.
Disaster recovery asks how we safely restore the technology and information the business needs.
Business continuity asks how the company keeps operating while those things are happening.
I go much deeper into those relationships in my Incident Response Plan for Small Business.
What Should a Small Business Do if It Finds Ransomware?
The exact response depends on the environment and the incident, which is why I do not want employees improvising technical remediation from an internet checklist during an active ransomware event.
At a high level, the business needs to report the incident immediately through its established response process and begin containing the affected environment. CISA recommends identifying and isolating affected systems as an early response action. Depending on the situation, that may involve removing an affected computer from the network or taking broader network containment actions.
What I do not want an employee doing is clicking around the infected computer, deleting things, running random cleanup tools, wiping the machine, communicating with an attacker, or trying a series of internet fixes before IT has had an opportunity to understand what is happening. Actions taken during those first minutes can affect containment, available evidence and the eventual recovery process.
If your business is dealing with a suspected compromise right now, I wrote My Small Business Was Hacked. What Should I Do Right Now? specifically for that situation. It addresses the immediate response rather than trying to turn this ransomware article into an incident response manual.
Should a Small Business Pay a Ransom?
This is not a decision I would make for a client, and it is not one I would reduce to a generic yes or no answer in a blog.
A ransomware event can involve technical, operational, financial, insurance, legal, regulatory and law enforcement considerations. The business's cyber insurance carrier may have an established incident response process. Legal counsel or a specialist may need to become involved. There may also be restrictions or risks associated with making payments to certain parties.
From the IT side, my role is to help determine what happened within my technical scope, contain affected technology where appropriate, preserve relevant technical information, understand what can be recovered, restore systems safely when that decision is made, and coordinate with other specialists when the situation requires them.
This is another reason those relationships should be established before ransomware happens.
Does Cyber Insurance Cover Ransomware?
It may, but I would never tell a business owner that ransomware is automatically covered because the company has cyber insurance.
Cyber policies vary. Coverage, sublimits, exclusions, response procedures, required controls and notification requirements can differ between insurers and policies. A carrier may also have specific vendors, legal resources, forensic firms or other specialists it expects the insured business to contact as part of the claims process.
That is why I want a business to know where its current policy is, who the broker and carrier contacts are, and what the actual policy says before an incident occurs.
I discuss the technical side of that process in Cyber Insurance Requirements for Small Businesses. My role is not to interpret insurance coverage. What I can do is help a business understand and document the technical controls it actually has so that the owner and insurance professional are working from accurate information.
What Can a Small Business Do Before Ransomware Happens?
I do not think ransomware preparation should start with buying another product. I would start by understanding the environment the business already has and identifying where a failure would hurt the most.
That includes understanding the company's critical systems, data, devices, accounts, remote access, cloud services, network, backups, administrative access and outside technology providers. Current CISA ransomware guidance specifically recommends maintaining an asset inventory and understanding which systems are critical to revenue generation and other important business services because those priorities become extremely important during recovery.
From there, the business can look at whether the appropriate layers are actually in place:
Keep operating systems, applications, firewalls, VPN appliances and other technology appropriately patched and supported.
Use strong authentication and phishing resistant MFA where supported, particularly for email, remote access and privileged accounts.
Limit administrative privileges and avoid using privileged accounts for normal day to day work.
Secure and review remote access, including VPN, RDP and remote management tools.
Use appropriately configured endpoint protection and detection capabilities.
Segment networks where doing so reduces unnecessary access between systems.
Maintain useful security and system logs.
Protect backups from the same environment they are intended to recover and test restoration.
Know which systems and information are most important to restoring business operations.
Maintain an incident response plan that identifies responsibilities, authority, contacts and escalation procedures.
Review the environment periodically because businesses, threats and technology all change.
That list is not a promise that ransomware cannot happen. It is a way to make the business harder to compromise, make an incident easier to detect and contain, and make recovery more realistic if prevention fails.
How Do I Know if My Small Business Is Prepared for Ransomware?
This is the question I think matters more than asking whether the business owns antivirus.
If I were talking with a business owner about ransomware readiness, I would want to know whether we can answer questions like these:
Question | Why It Matters |
Do we know what computers, servers, cloud services and network devices we actually have? | You cannot protect or recover systems nobody knew existed. |
Is MFA actually enforced where we think it is? | Owning licensing or enabling MFA for some users is not the same as having a consistent authentication strategy. |
Who has administrative access? | Privileged accounts can dramatically increase the impact of a compromise. |
How do employees and outside vendors connect remotely? | Remote access can create significant exposure if it is not understood and secured. |
Are endpoint security tools installed and reporting on every device they should protect? | A security product cannot protect a device it is not actually monitoring. |
Are important systems appropriately segmented? | Segmentation can help limit lateral movement after an intrusion. |
What exactly is being backed up? | “We have backups” does not tell us whether the business can recover what it needs. |
Are backups protected from deletion or encryption? | A backup accessible to the compromised environment may also become a target. |
When did we last test a restore? | A successful backup notification is not the same as a successful recovery. |
Who does an employee call if ransomware is discovered? | The first minutes of an incident are not the time to find the IT provider's phone number. |
Who has authority to isolate systems or shut down parts of the network? | Technical containment may require decisions that affect business operations. |
Where is the cyber insurance information? | The policy may have specific incident reporting procedures. |
Which systems need to come back first? | Recovery priorities should be based on business operations, not whichever computer is easiest to restore. |
If several of those questions cannot be answered, I would rather find that out now than during an attack.
My Small Business Incident Response Checklist and free Incident Response Readiness Workbook can help businesses start documenting some of those answers. If the larger issue is that nobody has a current picture of the technology environment itself, an IT Baseline Assessment can provide a broader starting point.
Ransomware Is a Business Resilience Problem, Not Just a Computer Virus
That is probably the biggest change I would make to the article I wrote in 2022.
I still care about phishing. I still care about endpoint security. I still care about MFA, patching and backups. But I no longer think those controls make sense as a simple list of individual things a business should buy or turn on.
I want to know how they work together.
If credentials are stolen, what prevents the attacker from using them? If one computer is compromised, what prevents that compromise from reaching everything else? If suspicious activity occurs, will anyone see it? If a server is encrypted, can we recover it? If the backups are attacked too, is another protected copy available? If data was stolen, who needs to become involved? If systems need to stay offline during an investigation, can the business continue operating? If an incident happens at 8:00 on a Saturday night, does anyone know who is supposed to make those decisions?
That is why ransomware fits into a much larger technology conversation. It touches identity, Microsoft 365, endpoint protection, networking, remote access, backups, documentation, cyber insurance, incident response, disaster recovery and business continuity.
For the businesses I work with, those pieces should not exist as completely separate projects that nobody ever connects.
Where Should a Small Business Start?
If you are reading this and realizing that you cannot answer half of the questions above, I would not start by buying a ransomware product. Start by understanding what you already have.
If the concern is specifically Microsoft 365, a Microsoft 365 Tenant Security Review can help establish what is actually configured around identities, authentication, administrative access, security policies, Defender, devices, SharePoint, OneDrive, backup and other parts of the Microsoft environment.
If the questions are broader than Microsoft 365, an IT Baseline Assessment can look at the overall technology environment, including computers, servers, network infrastructure, remote access, endpoint security, backups, cloud services and documentation.
If you already understand the technology but have never established what happens during an emergency, start with the Small Business Incident Response Checklist or the more detailed Incident Response Plan for Small Business.
Ransomware preparation is not about predicting exactly how the next attacker will behave. It is about understanding your business well enough that one compromised account, one vulnerable device or one bad morning does not automatically become a company wide disaster.
Common Small Business Ransomware Questions
Can ransomware spread through a network?
Yes. Depending on the ransomware operation and how the environment is configured, attackers can move between systems and use network access, credentials and administrative privileges to expand the scope of an attack. This is one reason CISA recommends least privilege and network segmentation as part of ransomware risk reduction.
Can ransomware affect cloud data?
Cloud services should not automatically be treated as immune from ransomware or data extortion. The risk depends on the service, configuration, identities, permissions, synchronization, backup arrangements and the type of attack. Businesses need to understand the shared responsibility model for the cloud services they use and determine how critical cloud information will be protected and recovered.
Can ransomware infect backups?
Accessible backups can be encrypted, deleted or otherwise affected during an attack, which is why CISA recommends offline encrypted backups and regular recovery testing. Backup architecture matters just as much as whether a backup job says it completed successfully.
Is antivirus enough to protect a small business from ransomware?
No single endpoint security product can eliminate ransomware risk. Endpoint protection is an important layer, but ransomware preparation also involves identity security, MFA, patching, remote access, privileges, network design, logging, backups, incident response and recovery planning.
Does MFA prevent ransomware?
MFA can significantly strengthen authentication and make stolen credentials more difficult to use, particularly when phishing resistant authentication is used. It does not prevent every
ransomware attack and should be treated as one part of a layered security strategy.
Should I disconnect a computer if I think it has ransomware?
Isolation can be an important containment action during a ransomware incident. CISA recommends isolating affected systems, including disconnecting network connectivity when appropriate. Employees should follow their company's incident response procedure and contact the appropriate IT or security resource rather than experimenting with cleanup or recovery on their own.
Should a small business pay ransomware attackers?
That decision can involve technical, legal, insurance, financial, regulatory and law enforcement considerations and should not be based on generic internet advice. Businesses should follow their incident response process and involve the appropriate professionals and cyber insurance resources.
How often should ransomware backups be tested?
There is no single testing interval that fits every small business. The schedule should reflect how critical the systems and information are, how frequently they change, and the business's recovery requirements. What matters is that restoration is actually tested rather than assuming successful backup notifications prove the business can recover.
Related SNL-Tech Services Resources
Immediate steps and considerations when a business suspects that a computer, Microsoft 365 account or other part of its environment has been compromised.
A deeper look at incident roles, authority, escalation, technical runbooks, cyber insurance, evidence, recovery and business continuity.
A shorter readiness review with a free fillable Incident Response Readiness Workbook.
What I look at when helping a business understand and document the technical controls appearing on its cyber insurance questionnaire.
A deeper look at identities, authentication, administrative access, Microsoft Defender, devices, SharePoint, OneDrive, backup, security policies and other Microsoft 365 controls.
How SNL-Tech Services approaches cybersecurity, Microsoft 365, networks, backups, disaster recovery and the broader technology small businesses depend on.
Additional Resources
National Institute of Standards and Technology: Ransomware Risk Management, Cybersecurity Framework 2.0 Community Profile
NIST's June 2026 ransomware profile provides current guidance for governing, identifying, protecting against, detecting, responding to and recovering from ransomware events.
Cybersecurity and Infrastructure Security Agency: StopRansomware Guide
CISA's ransomware guidance covers common initial access methods, identity security, remote access, network segmentation, endpoint protection, logging, backups, incident response, containment and recovery.
Federal Bureau of Investigation: 2025 IC3 Annual Report
The FBI's annual Internet Crime Complaint Center report includes current ransomware complaint and reported loss information as well as information about commonly reported ransomware variants.
This article provides general cybersecurity information for small businesses. The appropriate technical, legal, regulatory, insurance and incident response actions depend on the business and the circumstances of the incident. SNL-Tech Services provides technical IT services and documentation within its scope. Legal requirements, insurance coverage and regulatory reporting questions should be addressed with the appropriate qualified professionals.





link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link link