Backups and Ransomware Protection: A Checklist for Businesses
One morning an employee arrives at work and, instead of files, sees a message that the data has been encrypted and a payment is required to release it. It sounds like a movie scenario, but small and medium companies go through this regularly. The good news is that a well prepared company can survive such an attack without major damage.
How ransomware works
Ransomware is malicious software that encrypts files on computers and servers and demands a ransom. It most often gets in through:
- a fake email with an attachment or link,
- weak or reused passwords,
- unpatched vulnerabilities in systems and applications,
- unsecured remote access, such as RDP.
Paying the ransom is not recommended. There is no guarantee you will get the data back, and you are funding further attacks.
The 3-2-1 rule
The best known backup rule is simple:
- 3 copies of your data (the original and two backups),
- on 2 different types of storage (for example a disk and the cloud),
- with 1 copy off site or offline, so ransomware cannot reach it.
Today, "immutable" backups are often added, which do not allow a backup to be deleted or overwritten for a set period.
Why backups often fail
The biggest mistake is having a backup nobody has ever tested. It is often discovered that not everything was being saved, that the backup was damaged, or that recovery is slow. So try a restore on test data every so often. Also check that the backup is not connected to the network in a way that lets an attacker find it and encrypt it along with everything else.
Basic protection
- Update. Operating systems, applications, routers and firewalls.
- Turn on two factor authentication (MFA). Especially for email, cloud services and remote access.
- Use endpoint protection. A modern antivirus or an EDR solution.
- Segment the network. So an attack cannot spread from one computer to the whole company.
- Limit access rights. Not everyone needs administrator permissions.
- Secure remote access. Through a VPN and with two factor authentication.
Employees as the first line of defence
Most attacks start with a person, not with technology. Regular short training sessions and examples of fake emails can reduce the risk considerably. It is important that people are not afraid to report that they clicked something suspicious. A quick report can save the whole company.
An incident plan
Prepare a simple procedure for what to do when something happens:
- immediately disconnect the affected device from the network,
- inform the designated person or your IT partner,
- don't needlessly switch devices on or off, and don't delete traces,
- restore data from a verified backup,
- review what happened and assess your obligations towards authorities and customers (for example in case of a personal data leak).
Keep contacts ready and know who makes the decisions.
Conclusion
Backups and basic security are not expensive compared to what a company outage costs. If you want to find out where you stand, we offer an infrastructure and backup audit with a concrete list of recommendations. You can read more on the page Network and server administration.