Skip to content
English - United States
  • There are no suggestions because the search field is empty.

How to Prevent Ransomware in a Small or Mid-Sized Business

The layered checklist that stops most ransomware, in priority order.

Ransomware is prevented with layers: multi-factor authentication, patching, endpoint detection, email filtering, immutable backups, least privilege and trained users. No single tool does it, but together they stop the large majority of attacks. Here is the order we recommend closing the gaps.

1. Multi-factor authentication everywhere

Email, remote access, VPN, cloud apps and admin accounts. Stolen passwords are the most common way in, and MFA makes them nearly useless. See what is MFA.

2. Patch on a schedule

Firewalls, VPN appliances, servers, workstations and third-party apps. Attackers scan the internet for known, unpatched vulnerabilities within days of disclosure.

3. Endpoint detection and response

Traditional antivirus looks for known files. EDR watches behavior, so it catches the encryption process starting and can isolate the machine. See what is EDR. Add managed detection and response if nobody is watching alerts after hours.

4. Backups attackers cannot touch

Ransomware groups look for backups and delete them before encrypting. An immutable, off-site copy that cannot be altered for a set period is what makes recovery possible without paying. See what is an immutable backup.

5. Email and web filtering

Block malicious attachments and links before they reach the inbox, and block connections to known-bad sites.

6. Least privilege

Users should not be local administrators, and nobody should use an admin account for daily work. Limit what any one compromised account can reach.

7. Close exposed remote access

No Remote Desktop open to the internet. Remote access goes through a VPN or a zero-trust gateway with MFA.

8. Train people, then test them

Recurring security awareness training with simulated phishing turns employees into a detection layer instead of the weak point.

9. Have a plan

An incident response plan that says who to call and what to isolate first shortens a bad day considerably.

Mentis Group includes MFA, EDR, patching, email filtering and training in every Fully Managed IT agreement, with SOC, MDR and immutable backup options through Enhanced Cybersecurity. Our ransomware prevention and removal page covers the Dallas-Fort Worth service. Start with what is ransomware for how attacks unfold.

Have a question about your own environment? Schedule a consultation with Mentis Group or call (866) 901-7808.