Ransomware Prevention Simplified: Protect Your Files and Your Business

Could your backups survive a ransomware attack? Learn practical ways to protect accounts, isolate recovery copies, and prepare your files and business for a safer recovery.

Imagine opening your laptop and discovering that your invoices, family photos, or customer records will no longer open. Now imagine that the backup drive connected to that laptop has been encrypted, too. That is why ransomware prevention requires more than installing security software.

The practical approach is to prevent access, contain damage, and prepare for recovery. Individuals and small businesses can make meaningful progress without an enterprise-sized budget—but the order of operations matters.

Ransomware can lock files and disrupt systems. Attackers may also steal information and threaten to publish it. Backups can help restore operations; they cannot reverse data theft. Your defenses need to address both risks.

Start with the essentials: protect your accounts, update your systems, and prove that you can restore your important files.

1. Build Backups That Can Survive an Attack

A successful backup notification is not proof that you can recover. The real question is whether a usable copy will remain available after an attacker compromises your device—or your administrator account.

The UK National Cyber Security Centre’s ransomware guidance recommends keeping backups separate from everyday systems and testing restoration.

  • Keep multiple copies. Include at least one offline or otherwise isolated recovery copy.
  • Disconnect external drives after backing up. A permanently connected drive can become another target.
  • Check cloud recovery features. File synchronization can propagate encrypted or deleted files. Verify version history, retention, and protection against deletion.
  • Test a restore. Recover selected files into a separate location and confirm that they open correctly.

For a household, this might mean cloud backup plus a disconnected external drive. A business also needs to test application recovery: restoring accounting files is not enough if the software, credentials, or configuration needed to use them are missing.

Ask your provider whether a compromised administrator could delete every backup. The NCSC’s ransomware-resistant cloud backup principles address deletion protection, recovery access, and related safeguards.

Tradeoff: Longer retention and stronger protection cost money and require planning. Choose them according to how much data you can afford to lose and how long you can operate without critical systems.

2. Secure Accounts and Close Unnecessary Remote Access

Attackers do not always break through software defenses. Sometimes they sign in with stolen credentials.

Enable multifactor authentication, or MFA, on email, cloud storage, remote access, and administrator accounts. Prioritize email because it often controls password resets for other services.

CISA recommends MFA, with phishing-resistant methods providing stronger protection. Ask about compatible FIDO2/WebAuthn security keys or passkeys rather than assuming every authentication method offers equivalent security. Use unique passwords and a password manager wherever passwords remain necessary.

Document account recovery and protect recovery codes. Otherwise, a lost phone or security key can become its own operational emergency.

For businesses, identify who can connect remotely and how. Disable unused remote-access services, avoid exposing Remote Desktop directly to the internet, and restrict approved access. Remove former employees’ accounts and review vendor access, too.

Practical example: A bookkeeper who needs an accounting application should not automatically receive administrative access to the entire office network.

3. Update Software Before Attackers Exploit It

Enable automatic updates where appropriate for operating systems, browsers, applications, and device protection. Remember routers, firewalls, VPN equipment, and other devices that may not update themselves.

For a business, maintain an inventory and prioritize exposed systems. CISA’s Known Exploited Vulnerabilities Catalog, referenced in its #StopRansomware Guide, helps identify vulnerabilities already being exploited. It informs priorities; it does not replace broader patch management.

Windows users should check support status. Standard Windows 10 support ended on October 14, 2025. Verify whether your specific device and edition still receive security updates through an applicable extended-update program or servicing lifecycle. Otherwise, move to a supported operating system. See Microsoft’s support guidance.

Tradeoff: Updates can interrupt work or affect compatibility. For critical business systems, assign an owner, test promptly, and set a completion deadline. Any delay needs a temporary mitigation and an expiration date.

4. Make Suspicious Requests Easy to Verify

Phishing awareness should teach a reliable response—not depend on spotting poor spelling. A polished message can still be malicious.

When an unexpected message asks you to sign in, open an attachment, install software, or grant remote access:

  • Pause. Urgency is a reason to verify, not bypass normal safeguards.
  • Use a known route. Open the service through your usual bookmark or app instead of the supplied link.
  • Confirm separately. Contact the sender using a number or channel you already trust.
  • Report quickly. If you already clicked, tell your IT contact immediately.

The FTC’s small-business cybersecurity resources provide practical guidance on phishing and related threats. Apply the same caution to unsolicited support calls and alarming browser pop-ups.

Businesses should combine training with email filtering, malicious-site blocking, and restrictions on risky attachments. Make reporting simple and non-punitive; employees should not have to decide whether an incident is serious before asking for help.

5. Limit Damage and Make Security Alerts Actionable

Least privilege means giving people and applications only the access they need. Use a standard account for everyday work and separate administrator credentials for administrative tasks. Review shared folders so one compromised account cannot modify every business file.

Businesses should also separate guest devices, employee computers, sensitive servers, and backup administration where practical. Network segmentation only helps when rules actually restrict traffic between those areas.

Keep antimalware protection active and updated. Endpoint detection and response, or EDR, can add investigation and containment capabilities, but buying a license is not the same as having someone respond.

Ask your IT provider: Who receives serious alerts after hours, and who can isolate an affected device? Protect important system logs and monitor changes to administrator accounts, backup settings, and security controls.

Windows: Consider Controlled Folder Access

Microsoft’s Controlled folder access can block untrusted applications from changing protected files. It requires Microsoft Defender Antivirus as the primary antivirus application, with real-time protection enabled.

In Windows Security, open Virus & threat protection, select Manage ransomware protection, and review Controlled folder access and protected folders.

Tradeoff: Legitimate applications may need explicit approval. Businesses should evaluate compatibility in Audit Mode before enforcement; Audit Mode records activity but does not block it. This feature supplements backups—it does not replace them.

6. Prepare for the Day Prevention Fails

Keep response instructions and emergency contacts accessible without your normal email or computers. Decide who can disconnect systems, how people will communicate, and which services must recover first.

If you suspect active ransomware, the CISA response guidance supports these immediate priorities:

  • Isolate affected devices. Disconnect Ethernet and Wi-Fi and notify IT immediately.
  • Avoid shutdown when isolation is possible. Powering off can destroy evidence in memory. If network disconnection is impossible, shutdown may be necessary to limit spread.
  • Use a separate, trusted communication channel. Do not assume company email is safe.
  • Preserve evidence. Retain ransom notes and relevant logs; avoid wiping systems before responders assess them.
  • Coordinate recovery. Address the compromise and validate recovery systems before reconnecting them.

Businesses should involve their incident-response provider, insurer where applicable, and legal counsel to assess data exposure and notification obligations.

In the United States, report the incident through your local FBI field office or the Internet Crime Complaint Center. The FBI does not support paying a ransom; payment does not guarantee recovery.

Your Ransomware-Prevention Checklist

For each item, record an owner and the last verification date. “We think so” is not a completed check.

  • ☐ Important files have an isolated backup, and a restoration test succeeded.
  • ☐ Backup retention, deletion protection, and recovery credentials are understood.
  • ☐ Important accounts enforce MFA, preferably phishing-resistant.
  • ☐ Devices receive supported security updates.
  • ☐ Unnecessary remote access and administrator privileges are removed.
  • ☐ Device protection is active, and serious alerts reach a responder.
  • ☐ Staff know how to verify unusual requests and report mistakes.
  • ☐ Response instructions, contacts, and recovery priorities are available offline.

Make Your Next Step Verifiable

Ransomware prevention is not a promise that nothing will go wrong. It is a disciplined effort to reduce the chance of compromise, limit the damage, and recover with confidence.

Start today: secure your primary email account, check your update status, and restore a file from backup. If you run a business, assign the remaining checklist items to named owners. Demonstrated protection matters more than assumed protection.

Browse all insights · Contact Bart McDonough