A Practical Ransomware Protection Checklist for Ontario Businesses
Most businesses that get hit with ransomware are not businesses with zero security controls. They usually have several controls in place that turned out, after the fact, to be misconfigured, incomplete, or simply assumed to be working without ever being tested. This checklist is built around that gap: for each control, there is a verification step, not just an instruction to install something. For the broader prevention concepts behind each control, see our article on [how to protect your business from ransomware](/resources/how-to-protect-your-business-from-ransomware); this checklist is meant to be worked through alongside that article, not instead of it.
A practical ransomware protection checklist covers backup integrity, endpoint detection, patch cadence, access controls, email filtering, and network segmentation, but the key difference from a basic list is verification: each control needs to be actually tested, such as performing a real backup restore or confirming multi-factor authentication truly blocks a login attempt, rather than assumed to be functioning correctly.
Why verification matters more than the control list itself
Backup software can report a successful backup job every night for months while the actual data is corrupted or incomplete, and nobody finds out until a restore is attempted during a real emergency. The same pattern applies to multi-factor authentication that was enabled for some accounts but never enforced tenant-wide, or endpoint protection installed on most devices except the three someone forgot to include when a laptop was replaced.
This checklist pairs each control with a specific way to verify it is actually working, since a checklist of controls that were configured once and never tested provides false confidence rather than real protection.
Backup integrity
Control
Daily backups of servers, workstations, and Microsoft 365 data, with at least one copy that is offline or immutable so ransomware cannot reach and encrypt it alongside production data.
Verification
Perform an actual full restore test at least quarterly, not just a check that the backup job status shows green. Confirm the restored data opens correctly and is current. See our backup and disaster recovery guidance for how restore testing should be structured.
Multi-factor authentication
Control
MFA enforced on every account with access to email, remote access, and any cloud application, not limited to administrator accounts.
Verification
Pull a report of every user account and confirm MFA registration status individually, rather than assuming a policy applied correctly to everyone. Test a sign-in attempt from an unregistered device to confirm it is actually blocked.
Want these controls verified, not just checked off?
We run a practical ransomware readiness assessment that tests each control rather than taking your existing setup on faith.
Book a Readiness AssessmentEndpoint protection coverage
Control
Modern endpoint protection with behavioural detection, ideally including EDR, installed and actively reporting on every server and workstation.
Verification
Pull the full device inventory from the endpoint protection console and cross-check it against your actual list of active devices. Any device on the network but missing from the console represents unmonitored exposure.
Patch cadence
Control
Critical and high-severity patches applied within the timeframes described in our article on how often businesses should install security updates, prioritizing internet-facing systems.
Verification
Generate a patch compliance report across all servers and workstations and identify any device more than 30 days behind on critical updates, rather than assuming automatic updates are working everywhere.
Email filtering and phishing defense
Control
Advanced anti-phishing filtering beyond the default spam filter, with SPF, DKIM, and DMARC published for your domain.
Verification
Run a controlled phishing simulation to measure actual click and report rates, and check your DMARC record's policy setting directly rather than assuming it was configured correctly when first set up.
Network segmentation and firewall configuration
Control
A properly configured business firewall with network segmentation separating guest Wi-Fi, staff devices, and any sensitive systems.
Verification
Attempt to reach an internal resource from the guest Wi-Fi network directly and confirm it is actually blocked, rather than assuming the segmentation configured months ago is still enforced after subsequent changes.
Administrative access controls
Control
A limited number of administrative accounts, separate from daily-use accounts, with regular review of who holds elevated privileges.
Verification
Pull a current list of every account with administrative rights across your domain, Microsoft 365 tenant, and firewall, and confirm each one is still needed and belongs to an active employee.
Incident response readiness
Control
A written incident response plan naming who to contact and what steps to take immediately if ransomware is detected.
Verification
Walk through a tabletop exercise with key staff at least annually, working through a hypothetical ransomware scenario to confirm the plan is understood, current, and that contact information is accurate. Our article on what to do if your business has been hacked is a useful reference during that exercise.
Sources and further reading
Frequently asked questions
How is this checklist different from a general ransomware prevention guide?
This checklist pairs every control with a specific verification step, such as an actual backup restore test or a real phishing simulation, rather than just listing controls to have in place. It is meant to be used alongside our broader ransomware protection guide.
How often should this checklist be run through in full?
A full verification pass, including a backup restore test and access review, at least twice a year is reasonable for most small and mid-sized Ontario businesses, with critical items like patch compliance checked more frequently.
What is the single most commonly failed verification step?
Backup restore testing is the most commonly skipped step we see, with businesses assuming backups are working based only on a green status indicator rather than an actual successful restore.
Does having all these controls guarantee ransomware will not succeed?
No control or combination of controls provides a guarantee. These controls, properly verified, significantly reduce both the likelihood of a successful attack and the impact if one occurs.
Can a small business realistically implement all of this?
Yes, most of these controls are achievable for small businesses with the right tools and a bit of scheduled discipline. Working through them in priority order, starting with backups and MFA, is more realistic than attempting everything at once.
Joshua Arimoro
Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.
More about our teamGet every ransomware control on this list actually verified
We will test your backups, access controls, and endpoint coverage rather than assuming your current setup is working.
Related services, locations, and resources
Related services
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
Related service areas
Related resources
- Backing Up Primafact Case Files Properly
Case files in Primafact represent years of litigation work that can't be recreated. Here's what a proper ba…
- PCLaw Support for Ontario Law Firms: The IT Side of Running PCLaw
PCLaw handles billing, trust accounting, and time tracking for many Ontario firms. Here's what keeps it run…
- Protecting PCLaw Trust Accounting Data
Trust accounting data inside PCLaw deserves a distinct layer of protection. General infrastructure guidance…
- What Does a Sophos Firewall Actually Do for a Small Business?
A business-grade firewall does far more than block traffic at the edge. Here is what a device like a Sophos…
