What ransomware actually does
Ransomware is criminal software that encrypts your files, meaning it scrambles them so nothing opens, and demands payment for the key. Modern crews add a second squeeze: before encrypting, they copy your data out and threaten to publish it, so even perfect backups do not end the extortion attempt.
It typically arrives through a convincing email attachment or link, a stolen password, or a remote-access tool left exposed to the internet. Small businesses are not too small to bother with. They are the preferred target, because the defenses are thinner and the ransoms, commonly in the tens of thousands, get paid.
You do not need an IT department to be a hard target. You need a handful of unglamorous habits and one hour of preparation.
Prevention that pulls its weight
Five things do most of the work:
- Multi-factor authentication everywhere: email first, then banking, then everything that supports it. This single habit blocks the stolen-password entry route.
- Updates on autopilot for your computers, browsers, and any server you own. Most infections exploit holes that were patched months earlier.
- Backups that ransomware cannot reach: at least one copy offline or in a cloud service with version history, and a restore you have actually tested. A backup drive permanently plugged into the computer gets encrypted along with everything else.
- Email filtering plus ninety seconds of staff skepticism about unexpected attachments and urgent payment requests.
- Nobody works day-to-day in an administrator account, because malware inherits the power of whoever clicked it.
All five together cost less per month than one hour of professional incident response.
The first hour after you find it
If a ransom note appears or files will not open:
- Disconnect the affected machines from the network. Unplug the cable, turn off the wifi. You are stopping the spread. Leave the machines powered on, because wiping or rebooting can destroy evidence and sometimes recovery options.
- Disconnect or power down backup drives, and check whether cloud backups are intact before anything else touches them.
- Write down what you see: the note, the time, which machines, what people clicked. Photos taken with your phone are fine.
- Call for help: your IT provider or a security professional, and your cyber insurer's hotline, which often must be notified before recovery starts to preserve coverage.
- From a clean device, change your critical passwords, email first.
- Do not email the criminals and do not pay in a panic. Nothing about hour one requires that decision.
Why paying rarely ends it
Payment feels like the fast exit. The record says otherwise.
Decryption tools supplied by criminals are often slow, partial, or broken. Payment buys a promise from people whose business is extortion. The stolen copy of your data does not come back; the publication threat simply goes quiet, or returns later. Paying also marks you as a business that pays, and repeat targeting of past payers is well documented. In some cases payment to a sanctioned group can itself create legal exposure, which is why insurers and law enforcement are involved in any such decision.
And even a successful decryption still leaves you rebuilding machines and resetting credentials. Most of the recovery bill arrives whether or not you pay. Report incidents to the FBI at ic3.gov: it costs nothing, and free decryption tools sometimes exist for older strains.
The cheap preparations that matter most
An hour of preparation changes the entire first day:
- A printed contact sheet with IT help, insurer hotline, bank, and key staff, stored off the computers, because the computers are exactly what stops working.
- A tested restore. Once or twice a year, actually restore a file or folder and time it. This is the difference between a bad day and a bad month.
- A one-page plan taped inside a cabinet: the numbered steps above, plus who decides what.
- Read your cyber insurance policy now and note what it requires. Many policies mandate MFA and specific notification windows, and skipping them can void coverage.
- Know where your data actually lives: which machines, which cloud accounts. Recovery starts with that list.
What to do next
- Tonight: turn on multi-factor authentication for your email. It is the single highest-value ten minutes in security.
- This week: confirm you have a backup that an infected machine could not reach, and restore one file from it to prove it works.
- This month: print the contact sheet, write the one-page plan, and read your insurance policy's security requirements.
- Then: walk through the five prevention basics and close the gaps, cheapest first.
If you want a second set of eyes, a short security review covers all of this. I do them regularly for DMV businesses at HashWhales, and the plan that comes out fits on one page, because a plan nobody reads protects nobody.
