The Small Business Ransomware Survival Plan (Before, During, After)

If you run a small business, ransomware probably sits in the same mental bucket as lightning strikes: terrible, but unlikely to hit you. The uncomfortable truth is that attackers do not pick targets the way you might imagine. They run automated scans looking for weak passwords, unpatched systems, and exposed remote access, and small businesses show up in those scans constantly, precisely because they rarely have anyone watching.

The good news is that surviving ransomware is not about buying one magic product. It comes down to a handful of decisions you make before anything happens, a short list of actions in the first hour of an attack, and a disciplined recovery afterward. This article walks through all three phases in plain English.

Even if you never hire an IT provider, you can act on everything here. Print it, hand it to whoever handles your technology, and work through it one item at a time.

Before: build backups that actually restore

Ransomware crews go after your backups first. If they can encrypt or delete them, you have almost no options left except negotiating with criminals. So your backup setup needs to assume that an attacker with admin access will try to destroy it.

  • Keep at least one copy offsite and disconnected from your network, either truly offline or in cloud storage with immutability turned on, so nobody (including an attacker with your passwords) can alter it for a set period.
  • Do not confuse sync with backup. OneDrive, Dropbox, and Google Drive will happily sync encrypted files right over your good ones.
  • Test restores on a schedule. Once a quarter, actually restore a file, a folder, and if you can, a whole machine. A backup you have never restored is a hope, not a plan.

Before: make the break-in harder

Most ransomware gets in through one of three doors: a phishing email that steals a password, remote access with no multi-factor authentication, or an unpatched device facing the internet. Close those three doors and you have removed the most common ways in.

  • Turn on multi-factor authentication everywhere, starting with email and any remote access. An app like Microsoft Authenticator works fine, and a password manager like 1Password or Bitwarden stops the password reuse that makes stolen credentials so damaging.
  • Patch on a schedule, and treat your firewall, VPN, and anything else that faces the internet as the highest priority.
  • Replace consumer antivirus with endpoint detection and response (EDR) on every computer. EDR watches for ransomware behavior, like one account suddenly encrypting thousands of files, and can isolate a machine automatically.

Before: put the plan on paper

When ransomware hits, your documentation may be encrypted along with everything else. If your emergency contact list lives in a wiki on the server that just got locked, you do not have a plan, you have a hostage.

Print a one-page response sheet and keep copies at the office and at home. It should list who to call (your IT provider, your cyber insurance carrier with the policy number, and your bank), where your backups live and how to reach them, and who is allowed to speak to staff and customers about the incident. Ten minutes of writing now saves hours of panic later.

During: the first hour

The first hour sets the tone for the entire recovery. Your goals are simple: stop the spread, get professionals involved, and avoid destroying evidence.

  • Disconnect affected machines from the network. Unplug ethernet cables and turn off Wi-Fi. If you cannot tell what is affected, disconnect the switch or the internet connection itself.
  • Do not power everything off in a panic. Isolating a machine stops the spread just as well, and a running machine holds evidence in memory that investigators may need. Blindly shutting everything down can also corrupt databases that were still healthy.
  • Call your IT provider and your cyber insurance carrier before you touch anything else. Many policies require you to use their approved response team, and going around them can put your claim at risk.
  • Preserve evidence. Photograph ransom notes with your phone, write down which machines showed symptoms and when, and do not wipe or reinstall anything yet.
  • Do not coordinate the response from your company email. If attackers are inside your Microsoft 365 tenant, they can read every message you send. Use phone calls and text messages until email is confirmed clean.

After: restore in the right order

The biggest recovery mistake is restoring too fast onto a network the attacker still controls. Businesses that skip root cause analysis often get hit again, sometimes within weeks, and sometimes by the same crew walking through the same door.

Work with your responders to answer one question first: how did they get in? Phishing, exposed remote access, an unpatched device, or a password stolen in an earlier leak. Close that hole before anything comes back online.

Then rebuild in priority order. Identity comes first, meaning your Microsoft 365 or domain accounts, with every password rotated and every MFA method re-registered. Next come the systems that let you serve customers and collect money, then everything else. Restore data only from backups you have verified are clean, and keep monitoring closely for several weeks, because attackers sometimes leave themselves a second way back in.

After: reporting, and what paying really buys

You may have legal obligations after an attack, and they are simpler than they sound. Tell your insurer immediately, since policies have notification deadlines. If personal information about customers or employees was exposed, breach notification laws almost certainly apply (every US state has one, and Massachusetts is stricter than most), so get a lawyer’s advice on whom to notify and when. If you handle health information, HIPAA adds its own requirements. Report the attack to the FBI at ic3.gov and check CISA’s StopRansomware.gov even when you are not required to, because free decryption tools exist for some ransomware families and law enforcement sometimes recovers keys.

As for paying the ransom, understand what you are actually buying: a decryption tool from criminals, with no warranty. Decryptors are often slow, sometimes broken, and may recover only part of your data. Paying does not stop the crew from leaking or selling what they already stole, and it marks you as someone who pays. Payments to sanctioned groups can even create legal trouble of their own, which is why the FBI and CISA advise against paying, and why the decision usually runs through your insurer and lawyers anyway. The businesses that never face this choice are the ones with tested offsite backups.

Key Takeaways

  • A ransomware plan is mostly built before anything goes wrong: tested offsite backups, MFA, patching, and EDR do the heavy lifting.
  • In the first hour, disconnect infected machines instead of powering everything off, and call your IT provider and insurer before touching anything else.
  • Never coordinate incident response through your possibly compromised company email, since attackers may be reading it.
  • Find and close the entry point before you restore, or you are likely to get hit again.
  • Paying the ransom buys an unreliable decryption tool from criminals, which is why the FBI and CISA advise against it and why tested backups matter so much.

Ransomware often starts with one convincing phishing email, so book the free 30-minute security awareness session for your team at /free-training/, delivered remotely in English, Spanish, or Portuguese.


LogicSystemIQ is an IT managed services and SaaS studio based in Peabody, Massachusetts. We build DaycarePro (daycarepro.cloud), a trilingual SaaS for licensed home daycare providers. Reach us at (978) 815-1047 or Support@LogicSystemiq.com.

Scroll to Top