How to protect your business from ransomware

Everything on this list works without buying anything from anyone. The last item is where software earns its keep.

Last updated August 7, 2026

Affiliate disclosure: we earn a commission if you sign up for CrowdStrike through links on this page, at no extra cost to you. Competitor facts come from their own published pages and are date-stamped; the commission does not change the numbers. How we review →

The 7-step defense, in priority order

1. Back up on the 3-2-1 rule, and test the restore

Three copies of important data, on two different media, one offline or immutable (attackers hunt and encrypt online backups first). A backup you have never restored is a hope, not a plan: test-restore one system quarterly and time it.

2. Turn on MFA everywhere that matters

Email, VPN, remote desktop, admin accounts, and your backup console. Stolen credentials, not exotic exploits, open most ransomware intrusions, and remote access without MFA is the single most common way in.

3. Patch the internet-facing things within days, not months

VPN appliances, firewalls, remote-access servers, and anything with a public IP get exploited within days of a vulnerability disclosure. Enable automatic OS updates on endpoints; put a calendar owner on firmware and appliance patches.

4. Kill what you don’t use

Disable exposed RDP or put it behind the VPN. Remove local admin rights from daily-driver accounts. Delete stale accounts of departed employees the day they leave. Every service you turn off is attack surface nobody has to defend.

5. Filter email and train the reflex

Most intrusions still start with a message. Modern email filtering plus a workforce that reports suspicious mail beats an annual training video; make reporting one click and praise the people who use it, even on false alarms.

6. Run modern endpoint protection on every device

Signature antivirus cannot see never-before-seen ransomware or fileless techniques; behavior-based next-gen antivirus and EDR can. Cover servers and laptops alike, including the forgotten machine in the corner, because attackers specifically look for the unprotected one.

7. Write the one-page incident plan before you need it

Who isolates machines, who calls the insurer, who talks to customers, where the contact list lives when email is down. Print it. A plan you write during the incident is not a plan.

Where a product like CrowdStrike fits

Steps 1 through 5 and 7 are process and configuration: they cost time, not licenses, and no security product substitutes for them. Step 6 is the one you buy. The honest shortcut argument: a platform like CrowdStrike Falcon compresses steps 6 and part of 7 into one agent, with behavior-based ransomware prevention that scored 100% in SE Labs' independent testing, a process-tree view that makes the “what happened” question answerable, and, at higher tiers, an around-the-clock human team so after-hours attacks (three-quarters of them, by the research CrowdStrike cites) do not wait for Monday. Falcon Go starts at $59.99 per device per year with a 15-day card-free trial; alternatives worth comparing are in our ranked roundup. Whatever you pick, pick something modern: the checklist above assumes step 6 is not a 2009-era antivirus.

FAQ

Can a small business really be a ransomware target?+

Yes, and disproportionately so. CrowdStrike’s own small-business research cites 73% of small and mid-sized businesses experiencing a breach or cyberattack in 2023, and most ransomware attacks land outside business hours when nobody is watching. Attackers automate targeting; size is not camouflage.

Is backup alone enough protection against ransomware?+

No. Backups get you your files back; they do not stop data theft, and modern ransomware crews steal data before encrypting so they can extort you even if you restore. Backups are the floor. Prevention (patching, MFA, modern endpoint protection) and detection are what keep you off the extortion table.

Do I need EDR or is antivirus enough?+

Antivirus stops known malware; EDR watches behavior so it can catch the hands-on-keyboard stage of a ransomware intrusion, the lateral movement and credential abuse that precede encryption. Small businesses without a security team get most of the benefit from next-gen antivirus plus a managed or easy-to-run EDR tier; that is exactly the gap products like Falcon Go and Falcon Enterprise price against.

What should I do first if I find ransomware?+

Isolate affected machines from the network immediately (pull the cable or disable Wi-Fi; do not power off, memory holds evidence), preserve one encrypted machine for forensics, activate your incident plan, and call your insurer and an incident-response firm before negotiating anything. Reporting to law enforcement (IC3/CISA in the US) is strongly encouraged.

Keep comparing

Ready to try it yourself?

Start free on CrowdStrike

15-day free trial, no credit card required

Try CrowdStrike free ↗
This page contains affiliate links. We may earn a commission at no extra cost to you.