Ransomware: how to protect your business

By OpsinelPublished 8 min read

Short answer: Ransomware is malicious software that encrypts a company’s files and demands a ransom to unlock them. It most often gets in through a phishing email. The best protection is a trained team, 2FA, updates, limited access and reliable, regularly tested backups that let you restore without paying.

Ransomware is malicious software that encrypts a company’s files and demands a ransom to unlock them. Often the attackers also threaten to publish the stolen data. The result is stalled operations, lost data and major reputational harm. The key thing to know: ransomware most often gets into a business not through a sophisticated break-in, but through a simple phishing email.

How ransomware gets into a business

  • A phishing email with a malicious attachment (e.g. an Office document with macros or a .zip file).
  • A link to a page that downloads malicious software.
  • Stolen login details, through which the attacker logs in and starts the encryption.
  • Unpatched software with known vulnerabilities.

How to protect yourself: prevention

Since most attacks start with a human, prevention relies on both technology and alertness.

  • Train employees to spot phishing — this is the first line of defence.
  • Enable 2FA, so a stolen password does not open the door.
  • Regularly update systems and software to close known vulnerabilities.
  • Limit access rights — an employee sees only what the job requires.
  • Block dangerous attachments and macros where they are not needed.

Backups — the most important defence

If your data is encrypted, a reliable backup lets you recover without paying. But a backup is only useful when it actually works. Follow the 3-2-1 principle: three copies, on two different media, one of them kept off the network. And most importantly — periodically verify that you can actually restore data from the backup.

A backup you have never tried to restore is not a backup — it is an assumption. Test restoration regularly, not during an incident.

What to do when an attack happens

  • Isolate affected devices — disconnect them from the network so the encryption does not spread.
  • Do not pay the ransom immediately — it gives no guarantees and encourages new attacks.
  • Inform management and IT, and document what happened and when.
  • Restore data from reliable backups.
  • Assess whether you need to inform customers and responsible authorities about the data.

Technical measures are essential, but ransomware is most often let in by a person who opened the wrong attachment or entered a password on a fake page. So resilience starts with a trained team. Safe phishing simulations show who actually clicks dangerous links, and short training right after a mistake turns risk into a skill — which is exactly what Opsinel automates.

Try it yourself

Could you spot a phishing email?

10 realistic emails and an explanation after each answer. About 5 minutes, no sign-up.

Take the phishing quiz

Can scammers send email in your name?

A free SPF, DKIM and DMARC check of your domain. The domains you enter are not stored.

Frequently asked questions

Should I pay the ransomware ransom?

Usually no. Paying does not guarantee your data will be unlocked and it encourages new attacks. A reliable backup lets you recover without paying.

How does ransomware usually get into a business?

Most often through phishing — a malicious attachment or link in an email, or through stolen login details. So employee alertness is the first protection.

What is the single most important protection step?

Reliable, regularly tested backups together with a trained team. Backups let you recover, and alert employees stop the attack before the encryption starts.

What does the 3-2-1 backup principle mean?

Three copies, stored on two different media, with one kept off the network. This layout lets you recover even when ransomware reaches the main system.

My files are encrypted — can I recover them without paying?

If you have a working, separate backup — yes, you restore from it. So backups matter not only to make but to periodically verify that data can actually be restored.

Sources and further reading

Public guidance from security agencies and standards bodies.

From theory to practice

A phishing simulation lets your employees practise: they get a realistic email and, if they click, a short lesson straight away. Create an account and see sample data straight away.