Ransomware: how to protect your business
Short answer: Ransomware is malicious software that encrypts a company’s files and demands a ransom to unlock them. It most often gets in through a phishing email. The best protection is a trained team, 2FA, updates, limited access and reliable, regularly tested backups that let you restore without paying.
Ransomware is malicious software that encrypts a company’s files and demands a ransom to unlock them. Often the attackers also threaten to publish the stolen data. The result is stalled operations, lost data and major reputational harm. The key thing to know: ransomware most often gets into a business not through a sophisticated break-in, but through a simple phishing email.
How ransomware gets into a business
- A phishing email with a malicious attachment (e.g. an Office document with macros or a .zip file).
- A link to a page that downloads malicious software.
- Stolen login details, through which the attacker logs in and starts the encryption.
- Unpatched software with known vulnerabilities.
How to protect yourself: prevention
Since most attacks start with a human, prevention relies on both technology and alertness.
- Train employees to spot phishing — this is the first line of defence.
- Enable 2FA, so a stolen password does not open the door.
- Regularly update systems and software to close known vulnerabilities.
- Limit access rights — an employee sees only what the job requires.
- Block dangerous attachments and macros where they are not needed.
Backups — the most important defence
If your data is encrypted, a reliable backup lets you recover without paying. But a backup is only useful when it actually works. Follow the 3-2-1 principle: three copies, on two different media, one of them kept off the network. And most importantly — periodically verify that you can actually restore data from the backup.
A backup you have never tried to restore is not a backup — it is an assumption. Test restoration regularly, not during an incident.
What to do when an attack happens
- Isolate affected devices — disconnect them from the network so the encryption does not spread.
- Do not pay the ransom immediately — it gives no guarantees and encourages new attacks.
- Inform management and IT, and document what happened and when.
- Restore data from reliable backups.
- Assess whether you need to inform customers and responsible authorities about the data.
Where the weakest link is
Technical measures are essential, but ransomware is most often let in by a person who opened the wrong attachment or entered a password on a fake page. So resilience starts with a trained team. Safe phishing simulations show who actually clicks dangerous links, and short training right after a mistake turns risk into a skill — which is exactly what Opsinel automates.
Try it yourself
Could you spot a phishing email?
10 realistic emails and an explanation after each answer. About 5 minutes, no sign-up.
Take the phishing quizCan scammers send email in your name?
A free SPF, DKIM and DMARC check of your domain. The domains you enter are not stored.
Frequently asked questions
Should I pay the ransomware ransom?
Usually no. Paying does not guarantee your data will be unlocked and it encourages new attacks. A reliable backup lets you recover without paying.
How does ransomware usually get into a business?
Most often through phishing — a malicious attachment or link in an email, or through stolen login details. So employee alertness is the first protection.
What is the single most important protection step?
Reliable, regularly tested backups together with a trained team. Backups let you recover, and alert employees stop the attack before the encryption starts.
What does the 3-2-1 backup principle mean?
Three copies, stored on two different media, with one kept off the network. This layout lets you recover even when ransomware reaches the main system.
My files are encrypted — can I recover them without paying?
If you have a working, separate backup — yes, you restore from it. So backups matter not only to make but to periodically verify that data can actually be restored.
Sources and further reading
Public guidance from security agencies and standards bodies.
- NCSC (UK)Mitigating malware and ransomware attacks
- NCSC (UK)What you need to know about ransomware
- CISA (US)#StopRansomware guide