Skip to main content

Ransomware Protection for Small Business: What Actually Works.

5 min read
By Houston IT Developers
Empty modern office at dusk with a single desk lamp lit and computers powered down

Ransomware coverage tends to be either fear-mongering or a product pitch. This is the practical version: what actually works, in what order, and what to do in the first hour if it happens to you.

How it actually starts

The ransomware itself is the last step, not the first. By the time files start encrypting, an attacker has usually been inside for days or weeks — mapping the network, escalating privileges, stealing data and locating your backups.

Entry is almost always mundane:

  • Stolen or reused credentials, often bought rather than phished
  • Exposed remote access — RDP on the internet, or a VPN without MFA
  • Phishing, still effective because it only needs to work once
  • Unpatched internet-facing software, exploited automatically within days of a fix being published

None of that is exotic. Which is the good news: ordinary controls stop most of it.

The layers that work

Ordered by how much risk they remove per dollar.

1. MFA on everything, with no exceptions

The cheapest and most effective control available. Most credential-based entry dies here. The exceptions are what get exploited — the service account nobody wanted to break, the executive who found it annoying, the legacy protocol still permitted.

2. Offsite, immutable, tested backups

This is the layer that decides whether you reopen. Everything else reduces the chance of an incident; backups determine what an incident costs.

Three properties, all required:

  • Offsite — not a NAS in the same building, which encrypts with everything else
  • Immutable — cannot be altered or deleted for a fixed window, even by an administrator account. Attackers hunt backups specifically, and they usually have domain admin by then
  • Tested — a restore actually performed on a schedule. Untested backups fail at roughly the rate you would fear

Worth stating plainly because it surprises people: Microsoft does not back up your Microsoft 365 data for you. That is your responsibility under their shared-responsibility model. Neither does any major EDR vendor — not Huntress, not CrowdStrike, not Sophos. Backup is always a separate purchase.

3. Managed EDR with 24/7 response

Antivirus matches known-bad files; ransomware operators use legitimate built-in tools and per-target variants, so there is frequently nothing to match. EDR watches behaviour instead — mass file modification, shadow-copy deletion, lateral movement.

The managed part is what matters. Encryption runs fastest at night and on holidays, deliberately. Detection that emails an unattended inbox changes nothing. You need someone authorised to isolate the machine within minutes at any hour — which is MDR.

4. Patch the things facing the internet first

Most exploited vulnerabilities had a patch available. Prioritise anything internet-facing — VPN appliances, firewalls, remote access gateways, public web applications. These get scanned and exploited automatically, often within days of disclosure.

5. Segment the network

Flat networks are why one infected laptop becomes a company-wide outage. Separate servers from workstations, guest Wi-Fi from everything, and restrict which machines may talk to your file server at all. Segmentation does not prevent the first infection — it caps the blast radius.

6. Train people, and make reporting safe

Staff are the most-attacked control and the cheapest to improve. The goal is not perfect phishing detection; it is a culture where somebody says "I think I clicked something" within minutes instead of hiding it for a day. Security awareness training works best when reporting a mistake is genuinely consequence-free.

The first hour

Print this. If your systems are encrypted you will not be reading it on screen.

  1. Isolate, do not power off. Disconnect affected machines from the network — pull the cable, disable Wi-Fi. Powering off destroys memory evidence and can corrupt partially encrypted files.
  2. Do not delete anything, including the ransom note. It identifies the variant, and a decryptor may already exist publicly.
  3. Call your IT or security provider. If you have MDR, containment is likely already underway.
  4. Notify your cyber-insurance carrier immediately. Policies commonly require notification within a set window and mandate approved responders. Engaging your own vendor first can void coverage.
  5. Assume data was stolen. Most groups exfiltrate before encrypting. This is a disclosure question, not just a recovery one.
  6. Do not log in everywhere to check. Administrators logging into infected systems hands the attacker fresh credentials.
  7. Preserve logs. They may be the only evidence of what was accessed, and they answer the question regulators will ask.

On paying

Not moral advice — practical.

Paying does not reliably work. Decryptors are frequently slow, partial or broken, and recovery from a purchased decryptor routinely takes longer than recovery from good backups. It does not undo theft: if data was exfiltrated, you are buying a promise to delete a copy from people who just extorted you. It funds the next attack and marks you as a payer. And it may carry legal exposure where sanctioned entities are involved.

Decide with your insurer and counsel, never in the first panicked hour.

An honest baseline

If you do nothing else this quarter:

  • MFA everywhere, exceptions documented and justified
  • Offsite immutable backups, with one restore actually tested
  • Managed EDR with 24/7 response on every endpoint
  • Internet-facing systems patched on a schedule somebody owns
  • Everyone knows who to call, and knows they will not be punished for reporting

That is not comprehensive security. It is the set that stops most incidents and survives the rest — which for a small business is the practical goal.


We handle all of that as one service. Managed EDR with a 24/7 SOC, immutable backups with tested restores, email and identity protection, patching and staff training — on a flat per-user plan. See managed cybersecurity, or start with a free security assessment: we will tell you whether your backups would actually restore, which is the question that matters most and the one least often checked.

Houston IT Developers

Houston IT Developers

Houston IT Developers is a leading software development and digital marketing agency based in Houston, Texas. We specialize in web development, mobile apps, and digital solutions.

View all posts →

Need Help With Your Project?

Our team of experts is ready to help you build your next web or mobile application. Get a free consultation today.

Get in Touch

Related Posts