10 Steps to Protect Your Business from Ransomware
Ransomware: The Threat You Cannot Afford to Ignore
Ransomware remains the most destructive cybercrime threat facing Australian businesses. According to the Australian Signals Directorate’s Annual Cyber Threat Report 2023–2024, the ASD responded to over 1,100 cyber security incidents during the year, with ransomware accounting for a significant proportion of the most damaging events. Small businesses are not exempt — in fact, they are increasingly targeted because attackers know SMEs are less likely to have robust defences or the resources to recover without paying.
The average cost of a ransomware attack on an Australian small business extends well beyond the ransom demand itself. When you factor in downtime, lost revenue, recovery costs, reputational damage and potential regulatory penalties, the total impact can be devastating. And paying the ransom is no guarantee of getting your data back — research consistently shows that a significant percentage of businesses that pay never fully recover their data.
The good news is that ransomware is largely preventable. These 10 steps, designed for SME budgets and capabilities, will dramatically reduce your risk.
Step 1: Enable Multi-Factor Authentication (MFA)
MFA is the single most effective measure you can take to prevent unauthorised access to your systems. Ransomware operators frequently gain initial access through stolen or guessed credentials. MFA adds a second verification step — a code from an authenticator app, a push notification or a hardware key — that stops attackers even if they have your password.
Prioritise MFA on email accounts, cloud services (Microsoft 365, Google Workspace), VPNs, remote desktop and any administrative accounts. For a step-by-step implementation guide, see our MFA setup guide.
Step 2: Patch Promptly
Unpatched software is one of the most common entry points for ransomware. Attackers actively scan for known vulnerabilities in operating systems, web browsers, email clients and business applications. When a patch is released, assume attackers are already exploiting the vulnerability it fixes.
- Enable automatic updates for operating systems and applications wherever possible.
- Patch critical vulnerabilities within 48 hours of release.
- Replace end-of-life software that no longer receives security updates.
- Do not forget firmware updates on routers, firewalls and network devices.
Patching is one of the Essential Eight strategies recommended by the ASD, and for good reason — it closes the doors that attackers walk through.
Step 3: Backup Using the 3-2-1 Rule
Reliable backups are your last line of defence against ransomware. If your systems are encrypted, a clean, recent backup means you can restore operations without paying a ransom. Follow the 3-2-1 rule:
- 3 copies of your data
- 2 different storage media (e.g., local drive and cloud)
- 1 copy stored offsite or offline
Critically, at least one backup must be offline or immutable. Ransomware is designed to find and encrypt network-connected backups. An offline backup that ransomware cannot reach is the difference between a bad day and a catastrophe.
Test your restores regularly. A backup that you have never tested is not a backup — it is a hope.
Step 4: Deploy Email Filtering
Email is the primary delivery mechanism for ransomware. Phishing emails with malicious attachments or links to infected downloads remain the most common initial infection vector. Effective email filtering catches the majority of these before they reach your staff.
- Use a business-grade email filtering service (Microsoft Defender for Office 365, Google Workspace security, or a dedicated email security gateway).
- Block executable attachments (.exe, .scr, .js, .vbs) at the gateway.
- Enable link scanning that checks URLs at the time of click, not just at delivery.
- Implement SPF, DKIM and DMARC to prevent email spoofing of your domain.
Step 5: Use Endpoint Protection
Modern endpoint protection (sometimes called next-generation antivirus or EDR) goes well beyond traditional signature-based antivirus. These tools use behavioural analysis to detect ransomware activity — such as mass file encryption — and can automatically isolate infected devices before the damage spreads.
Ensure endpoint protection is installed on every device that connects to your network or accesses business data, including laptops, desktops, servers and mobile devices. Keep definitions and software up to date.
Step 6: Segment Your Network
Network segmentation divides your network into separate zones, limiting how far ransomware can spread if it gets past your perimeter. At a minimum:
- Separate your Wi-Fi network for guests from your business network.
- Isolate servers containing sensitive data from general-use workstations.
- If you have operational technology (point-of-sale systems, manufacturing equipment), keep it on a separate network segment.
For many SMEs, a properly configured router or managed switch can achieve basic segmentation without significant cost.
Step 7: Enforce Least Privilege Access
The principle of least privilege means that every user account should have only the minimum permissions needed to do their job. If a ransomware operator compromises a standard user account, the damage is limited to what that account can access. If they compromise an administrator account, they can encrypt everything.
- Remove local administrator rights from daily-use accounts.
- Use separate administrator accounts for IT management tasks.
- Regularly review who has access to what, and revoke access that is no longer needed.
- Disable or delete accounts for departed employees immediately.
Step 8: Disable Macros by Default
Microsoft Office macros remain a favourite ransomware delivery method. Malicious Word or Excel documents with embedded macros are sent via phishing emails, and a single click on “Enable Content” can trigger the infection. Unless your business has a documented, legitimate need for macros in specific workflows:
- Disable macros by default across all devices using Group Policy or Microsoft 365 admin settings.
- Block macros in files downloaded from the internet (Microsoft’s default since 2022, but verify it is enforced).
- If macros are needed, allow them only from trusted locations with digitally signed code.
Step 9: Create an Incident Response Plan
When ransomware strikes, the first hours are critical. Without a plan, decisions are made under panic, and mistakes compound the damage. An incident response plan ensures your team knows exactly what to do:
- Who to contact (IT provider, insurer, legal, law enforcement)
- How to isolate affected systems to stop the spread
- How to communicate with staff, customers and stakeholders
- How to initiate backup restoration
- Your obligations under the mandatory ransomware reporting regime if a payment is made
Document the plan, distribute it (in print — not just on a server that might be encrypted), and rehearse it at least annually.
Step 10: Train Your Staff
Technology can block many attacks, but your staff are the final line of defence. A well-trained employee who pauses before clicking a suspicious link, who reports an unusual email, who questions an unexpected request for credentials, can stop a ransomware attack in its tracks.
- Conduct regular, short security awareness training — monthly micro-sessions are more effective than annual marathons.
- Run phishing simulations to test and reinforce awareness.
- Create a culture where reporting suspicious activity is encouraged, not punished.
- Ensure new staff receive security training during their first week of onboarding.
“Ransomware does not discriminate by business size. A 15-person accounting firm and a 15,000-person bank are both viable targets. The difference is preparation.”
If you look at the 10 steps above, they map naturally across all four pillars of the IDIA framework — a framework-independent cybersecurity operating model. Identity covers MFA and least-privilege access (Steps 1 and 7). Data covers backups and macro controls that protect your information assets (Steps 3 and 8). Infrastructure covers patching, email filtering, endpoint protection and network segmentation (Steps 2, 4, 5 and 6). Assurance covers your incident response plan and staff training — the governance and continuous improvement activities that tie everything together (Steps 9 and 10). Thinking in these four pillars helps you see ransomware defence as a complete operating model, not a disconnected checklist.
Know Where You Stand
Implementing these 10 steps will significantly reduce your ransomware risk, but knowing where to start depends on understanding your current posture. Platforms like How’s My Cyber use the IDIA framework (Identity, Data, Infrastructure, Assurance) to organise every control into a clear operating model that works alongside any standard. Start with the free CYBER9 assessment to benchmark your business across nine critical domains — including backup resilience, access control, patching discipline and incident readiness — in under 10 minutes. No technical expertise required, and you will receive a prioritised action plan tailored to your business.
How secure is your business?
Take the free CYBER9 assessment and get your security score in under 10 minutes. No credit card required.
Try CYBER9 Free