Ransomware is not a sophisticated attack anymore. It is a business model. Groups buy access to networks the way you would buy a lead list, encrypt everything they can reach, and wait for someone to pay.
Small businesses get hit disproportionately hard — not because they are targeted personally, but because they are reachable and they recover slowly. A law firm with six people has the same exposure as a company with six hundred, and a fraction of the ability to absorb a week of downtime.
Here is what actually matters, in the order it matters.
How It Gets In
Almost every small business ransomware case starts in one of four places:
- A phishing email. Someone opens an attachment or enters credentials on a fake login page. This is still the most common entry point by a wide margin.
- Remote access left open. Remote Desktop exposed to the internet, often set up years ago by someone who has since moved on, usually with a weak password and no second factor.
- Software that never got patched. Attackers scan for known vulnerabilities constantly. A machine that is three months behind on updates is findable.
- A reused password. Credentials leaked in an unrelated breach get tried against your accounts. If a staff member used the same password on a shopping site, it is already in a list somewhere.
Notice that none of these require anyone to be careless in a dramatic way. They require an ordinary business day.
What Actually Stops It
You do not need an enterprise security programme. You need five things working reliably.
1. Multi-factor authentication on everything. Email first, then anything financial, then everything else. This single change blocks the overwhelming majority of credential attacks. It is free on most platforms and takes an afternoon.
2. Updates that install themselves. Not "we do them when we remember." Operating system and application patches need to apply automatically, after hours, on every machine — including the laptop that lives in someone's truck and only connects twice a week.
3. Backups that are offline or immutable. This is the one that decides whether ransomware is a bad week or a business-ending event. If your backup drive is plugged into the machine that gets encrypted, it gets encrypted too. Covered properly in the next section.
4. Endpoint protection that watches behaviour. Traditional antivirus matches known signatures. Modern ransomware changes its signature every time. What catches it is software that notices a process suddenly encrypting thousands of files and stops it mid-run.
5. Least privilege. Most people do not need administrator rights on their own computer. When a standard user account gets compromised, the damage stops at what that account could reach. When an admin account gets compromised, it does not.
Your Backups Are the Actual Insurance Policy
Everything above reduces the chance of getting hit. Backups determine what happens when something gets through anyway — and something eventually does.
A backup that protects you against ransomware has three properties. It is offsite, so a fire or a theft does not take it with the originals. It is versioned, so you can roll back to before the encryption started rather than restoring the encrypted files. And it is tested, so you know the restore works before you need it.
That last one catches a lot of businesses. An untested backup is a hypothesis, not a safety net. The time to discover that your backup has been silently failing for four months is not the morning you need it.
If It Happens: The First Hour
Speed matters more than perfection. In rough order:
- Disconnect, do not power off. Pull the network cable or turn off Wi-Fi on affected machines to stop it spreading. Leaving them powered on preserves evidence and sometimes keys held in memory.
- Do not pay yet. Paying is a decision to make with advice, not in a panic. Many groups do not provide a working decryption key, and paying marks you as someone who pays.
- Find out what was reached. Which machines, which shares, which cloud accounts. This determines both your recovery and your notification obligations.
- Check your backups before restoring. Restoring into a network that still has the attacker in it means doing this twice.
- Notify who you need to. Depending on your industry and what data was involved, you may have legal reporting deadlines measured in hours.
The Honest Summary
Ransomware protection for a small business is not one product. It is a handful of unglamorous things done consistently: patches applied, backups verified, MFA enforced, admin rights limited, and someone watching for the unusual.
The reason small businesses struggle with this is not that the list is hard. It is that the list requires someone to own it every week, forever, and most small businesses do not have that person.
That is precisely the gap Senturi fills — the patching, the verified backups, the endpoint protection and the monitoring all run automatically, and there is a real technician to message when something looks wrong.