Skip to main content

How to Protect Your Small Business from Ransomware

How ransomware really gets into small firms, the practical defences that actually work on an SME budget, and why tested backups are your last line of defence.

5 min read By Adnan R.
Ransomware warning message on a computer

Ransomware isn’t just a big-company problem — small firms are targeted precisely because their defences are thinner. Here’s how it gets in, the affordable measures that genuinely reduce your risk, and why a tested backup matters more than any single security product.

Share this article:

Table of Contents

Why small firms are a target, not an afterthought

There’s a persistent myth that ransomware only hits hospitals, councils and household-name companies. In reality, small businesses are attractive precisely because they tend to run without dedicated IT, patch slowly and back up inconsistently. Attackers don’t need to pick you personally — most ransomware arrives through automated, opportunistic campaigns that scan for any machine with a weak point. A five-person accountancy practice or a busy dental surgery is just as reachable as a large firm, and often far easier to compromise.

The damage isn’t only the ransom demand. It’s the days of downtime, the lost invoicing and client records, the awkward conversations with customers about their data, and the possible reporting obligation to the ICO. For a small business, that disruption alone can be more costly than the ransom itself.

How ransomware actually gets in

Understanding the entry routes is the whole game, because nearly all of them are things you can close off cheaply. In the machines we see in the workshop, the common ways in are:

  • Phishing emails. By far the most frequent. A convincing message with a malicious attachment or link — a fake invoice, a “failed delivery”, a shared document that asks you to sign in.
  • Weak or reused passwords on remote access. If you have Remote Desktop exposed to the internet, or staff reusing the same password everywhere, attackers can simply log in.
  • Unpatched software. Old versions of Windows, browsers, VPN appliances and plugins carry known holes that automated tools exploit.
  • Compromised credentials. Passwords leaked in unrelated breaches get tried against your email and cloud accounts.

Notice that none of these needs a sophisticated hacker. They rely on ordinary human habits and neglected maintenance — which is good news, because it means ordinary discipline defends against them.

The realistic defences that fit an SME budget

You don’t need an enterprise security budget. You need a handful of measures applied consistently. In rough order of impact for the money:

Turn on multi-factor authentication (MFA) everywhere. This is the single highest-value step. Even if a password leaks, MFA stops the login. Enable it on email, cloud storage and any remote access — it’s free on most platforms and takes minutes per account.

Keep everything updated. Enable automatic updates for Windows, browsers and business applications. Retire any machine still on an unsupported version of Windows, because it stops receiving the security fixes that block these attacks.

Close off remote access. Never expose Remote Desktop directly to the internet. If staff work remotely, put it behind a proper VPN or a managed access tool, and protect it with MFA.

Use reputable, centrally managed security software. The built-in Microsoft Defender is genuinely capable for many small firms; the priority is that it’s switched on, updating, and someone is actually watching the alerts.

Limit who has administrator rights. Day-to-day accounts should be standard users. Ransomware run by a limited account can do far less damage than one run as an administrator.

Train your team. Ten minutes explaining how to spot a suspicious email, and a clear “when in doubt, ask” culture, prevents more incidents than any product. Getting your email onto a properly configured platform — a clean Microsoft 365 setup with spam filtering and MFA enforced — removes a large slice of the risk before it reaches anyone’s inbox.

Pulling these together into a coherent plan is what our cybersecurity work for local firms is really about: not selling you a magic box, but closing the doors attackers actually use.

Why tested backups are your real last line of defence

Every defence above reduces the chance of infection. None of them makes it zero. That’s why your backup is the measure that decides whether a ransomware hit is an afternoon’s inconvenience or an existential crisis. If you can wipe the affected machines and restore clean data, the attacker has nothing to sell you.

But a backup only counts if it survives the attack and actually restores. Two failures we see repeatedly:

  • The backup was connected and got encrypted too. Modern ransomware deliberately hunts for attached drives and synced cloud folders. Your backup needs at least one copy that’s offline or otherwise isolated — versioned cloud storage or a rotated drive that isn’t permanently plugged in.
  • Nobody ever tested a restore. A backup you’ve never restored from is a hope, not a plan. At least once a quarter, actually recover a few files — and ideally a whole machine — to prove it works and to time how long it takes.

Proper, isolated, regularly tested backup solutions are the difference between shrugging off an attack and paying a criminal. If you set up nothing else this month, set up this.

Where to start

If you’re not sure how exposed you are, start with the basics: switch on MFA today, confirm your machines are fully updated, and check whether your backup includes a copy that ransomware can’t reach.

If you’d like a hand hardening your setup — or a straight review of your current defences without the jargon — call us on 020 7610 0500, drop into the Putney workshop, or use the contact form. We help small businesses across South West London and remotely UK-wide put sensible cybersecurity in place before anything goes wrong, not after.

Helpful Internal Links

Need Help With This Issue?

Speak with our support team for practical help and next steps.

Author

Adnan R.

Principal IT & Security Consultant

CISSP-certified IT and security consultant with an MSc in Information Security from Royal Holloway, University of London, and 20+ years across systems administration, networking and cybersecurity. Professional member of the British Computer Society (BCS).

Explore more

Related Posts

View all

How to Secure Your Home Wi-Fi Network

A practical guide to securing your home Wi-Fi: strong passwords, WPA3 encryption, a guest network, router firmware updates and keeping smart devices apart.