Key Takeaways
- Layer your defences: endpoints, identity, backups, and email all need separate controls, not one silver bullet.
- Immutable, offsite backups are what actually gets you back online without paying a ransom.
- Modern ransomware steals your data before encrypting it, so backups alone do not remove the extortion risk.
- A written incident response plan turns a crisis into a process. Decide roles before you need them.
- Patch on a schedule. Most successful attacks start with a known, unpatched vulnerability.
How ransomware has changed
Early ransomware locked your files and demanded payment. Fast, blunt, and if you had a backup, mostly survivable. Modern ransomware groups steal your data first, then encrypt it, then threaten to leak it whether or not you pay. This is double extortion, and it means a good backup no longer solves the whole problem.
Most attacks start the same way: a compromised password, an unpatched system, or a convincing email attachment. Once inside, attackers move laterally looking for the systems that matter most, your domain controller, your backup server, before they trigger the encryption.
Signature-based antivirus catches known threats. It does not catch a zero-day exploit or an attacker using your own admin tools against you. Modern protection needs to watch behaviour, not just match file hashes.
Locking down your endpoints
Every laptop and workstation is a potential way in. Harden them and you force attackers toward the parts of your network that are actually being watched.
Endpoint detection and response
OxygenIT’s Endpoint Detection and Response monitors device activity in real time and blocks malicious processes as they execute, rather than waiting for a signature match.
Patch on a schedule, not when you remember
| System | Priority | Update frequency |
|---|---|---|
| Operating systems | Critical | Weekly |
| Web browsers | High | Real-time |
| Third-party applications | Medium | Monthly |
| Firmware | High | Quarterly |
Most successful ransomware attacks exploit a vulnerability that already had a patch available. A consistent schedule closes that gap before it gets used.
Remote and hybrid devices
Laptops on home networks need the same controls as machines in the office. VPNs and endpoint management keep them under company policy regardless of where they connect from.
Backups that actually survive an attack
Your backup is the last line of defence if everything else fails. A copy sitting on a local drive the ransomware can also reach is not a backup, it is a false sense of security.
Immutable storage
Immutable backups cannot be altered or deleted for a set period, by anyone, including a fully compromised admin account. This is what actually guarantees you have a clean copy to restore from.
The 3-2-1 rule
Keep three copies of your data, on two different types of media, with one copy offsite. The 3-2-1 backup rule means no single failure, physical, hardware, or a network intrusion, can wipe out everything at once.
Test your restores
A backup nobody has tested is a guess. Run scheduled restoration drills, confirm your actual recovery time against what the business needs, and document who is responsible for each step. Quarterly is a reasonable cadence. Fix what the drill reveals before the next one.
Securing email
Most ransomware still starts in an inbox. Email filtering that inspects attachments in a sandbox and checks sender authentication (SPF, DKIM) catches malicious files and spoofed senders before a human has to make the call.
Executive impersonation remains one of the most effective ways in, since a fake urgent request from “the CEO” bypasses a lot of normal caution.
Identity and network controls
Identity is the new perimeter. Limiting what each account can access limits how far an attacker gets if that account is compromised.
Multi-factor authentication
MFA stops most credential theft from becoming a breach, since a stolen password alone is not enough to get in.
Network segmentation
Split your network into isolated zones so an infected workstation cannot reach your core database servers directly. This limits the blast radius if one machine does get compromised.
Review admin access regularly
Admin accounts are what attackers want most. Review who actually still needs elevated access and revoke what is unused. It is a simple step that closes a gap most businesses do not think to check.
Building the human layer
Ongoing, relevant staff training turns your team into your most active line of defence, not your weakest link. Phishing simulations work best when the results are used to improve training, not to single people out. Leadership needs its own version of this training too, since executives are specifically targeted by whaling attacks.
When it goes wrong anyway
Even solid defences get breached sometimes. What matters is whether you have a plan already written, not one improvised during the incident.
Your incident response plan should name who leads the technical response, who talks to clients, and who handles the regulatory side, decided in advance, not during the crisis. A managed SOC watching your environment around the clock catches most incidents before they escalate this far.
After any real incident or drill, run a short debrief: what worked, what stalled, what needs to change. That is what turns one bad day into a stronger system, rather than a repeat.
Frequently Asked Questions
What are the early warning signs of ransomware
Unexpected file encryption, sudden performance drops, and unusual activity on administrative accounts are the most common early indicators.
Why is traditional antivirus not enough anymore
Signature-based antivirus only catches known threats. Modern attacks often use legitimate admin tools or unknown exploits that behavioural monitoring catches and signature matching does not.
How can a small business afford this level of protection
Managed services give smaller businesses enterprise-level monitoring through a flat monthly fee, rather than the cost of building an internal security team.
Does MFA stop every phishing attempt
It blocks most credential theft, but staff should still be cautious of unexpected login prompts, since sophisticated attacks can still trick users into approving one.
How often should backups run
It depends on how much data you can afford to lose. Many businesses run continuous or incremental backups so the gap between the last good copy and an incident stays small.
Are cloud applications automatically protected
No. Most cloud providers secure the platform, but protecting your own data and user access within it remains your responsibility.
What does immutability actually give you
A guarantee that your backup cannot be changed or deleted, even by a compromised admin account, so you always have a clean copy to restore from.