Why this matters
Small businesses are frequent ransomware targets because they often have fewer defences. The good news is that a small set of practical controls blocks most attacks, and good backups mean you can recover without paying.
What you'll need
- Your IT provider or admin access
- Your backup details
- A list of staff and devices
Step-by-step instructions
Step 1
Secure every login with MFA
Email, Microsoft 365, remote access, accounting and banking.
Step 2
Patch quickly
Turn on automatic updates and prioritise browsers, Office, PDF readers and anything internet-facing.
Step 3
Remove everyday admin rights
Staff should not use admin accounts for email and browsing.
Step 4
Protect every device
Use managed endpoint protection with alerts going to someone who will act on them.
Step 5
Keep an offline backup
Maintain at least one backup that ransomware cannot reach, and test restoring from it.
Step 6
Train your team
Run short phishing awareness sessions and make reporting suspicious emails easy and blame-free.
Step 7
Know who to call
Have your IT provider, insurer and the Australian Cyber Security Hotline (1300 CYBER1) listed in your incident plan.
Summary
MFA, patching, limited admin rights, endpoint protection, offline backups and trained staff give small businesses strong protection against ransomware.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.