All Resources
Cybersecurity

A Practical Ransomware Protection Checklist for Ontario Businesses

Most businesses that get hit with ransomware are not businesses with zero security controls. They usually have several controls in place that turned out, after the fact, to be misconfigured, incomplete, or simply assumed to be working without ever being tested. This checklist is built around that gap: for each control, there is a verification step, not just an instruction to install something. For the broader prevention concepts behind each control, see our article on [how to protect your business from ransomware](/resources/how-to-protect-your-business-from-ransomware); this checklist is meant to be worked through alongside that article, not instead of it.

Published August 10, 2026 Updated August 10, 2026 9 min read By Joshua Arimoro Greater Sudbury & Ontario
The short answer

A practical ransomware protection checklist covers backup integrity, endpoint detection, patch cadence, access controls, email filtering, and network segmentation, but the key difference from a basic list is verification: each control needs to be actually tested, such as performing a real backup restore or confirming multi-factor authentication truly blocks a login attempt, rather than assumed to be functioning correctly.

Why verification matters more than the control list itself

Backup software can report a successful backup job every night for months while the actual data is corrupted or incomplete, and nobody finds out until a restore is attempted during a real emergency. The same pattern applies to multi-factor authentication that was enabled for some accounts but never enforced tenant-wide, or endpoint protection installed on most devices except the three someone forgot to include when a laptop was replaced.

This checklist pairs each control with a specific way to verify it is actually working, since a checklist of controls that were configured once and never tested provides false confidence rather than real protection.

Backup integrity

Control

Daily backups of servers, workstations, and Microsoft 365 data, with at least one copy that is offline or immutable so ransomware cannot reach and encrypt it alongside production data.

Verification

Perform an actual full restore test at least quarterly, not just a check that the backup job status shows green. Confirm the restored data opens correctly and is current. See our backup and disaster recovery guidance for how restore testing should be structured.

Multi-factor authentication

Control

MFA enforced on every account with access to email, remote access, and any cloud application, not limited to administrator accounts.

Verification

Pull a report of every user account and confirm MFA registration status individually, rather than assuming a policy applied correctly to everyone. Test a sign-in attempt from an unregistered device to confirm it is actually blocked.

Want these controls verified, not just checked off?

We run a practical ransomware readiness assessment that tests each control rather than taking your existing setup on faith.

Book a Readiness Assessment

Endpoint protection coverage

Control

Modern endpoint protection with behavioural detection, ideally including EDR, installed and actively reporting on every server and workstation.

Verification

Pull the full device inventory from the endpoint protection console and cross-check it against your actual list of active devices. Any device on the network but missing from the console represents unmonitored exposure.

Patch cadence

Control

Critical and high-severity patches applied within the timeframes described in our article on how often businesses should install security updates, prioritizing internet-facing systems.

Verification

Generate a patch compliance report across all servers and workstations and identify any device more than 30 days behind on critical updates, rather than assuming automatic updates are working everywhere.

Email filtering and phishing defense

Control

Advanced anti-phishing filtering beyond the default spam filter, with SPF, DKIM, and DMARC published for your domain.

Verification

Run a controlled phishing simulation to measure actual click and report rates, and check your DMARC record's policy setting directly rather than assuming it was configured correctly when first set up.

Network segmentation and firewall configuration

Control

A properly configured business firewall with network segmentation separating guest Wi-Fi, staff devices, and any sensitive systems.

Verification

Attempt to reach an internal resource from the guest Wi-Fi network directly and confirm it is actually blocked, rather than assuming the segmentation configured months ago is still enforced after subsequent changes.

Administrative access controls

Control

A limited number of administrative accounts, separate from daily-use accounts, with regular review of who holds elevated privileges.

Verification

Pull a current list of every account with administrative rights across your domain, Microsoft 365 tenant, and firewall, and confirm each one is still needed and belongs to an active employee.

Incident response readiness

Control

A written incident response plan naming who to contact and what steps to take immediately if ransomware is detected.

Verification

Walk through a tabletop exercise with key staff at least annually, working through a hypothetical ransomware scenario to confirm the plan is understood, current, and that contact information is accurate. Our article on what to do if your business has been hacked is a useful reference during that exercise.

Sources and further reading

Frequently asked questions

How is this checklist different from a general ransomware prevention guide?

This checklist pairs every control with a specific verification step, such as an actual backup restore test or a real phishing simulation, rather than just listing controls to have in place. It is meant to be used alongside our broader ransomware protection guide.

How often should this checklist be run through in full?

A full verification pass, including a backup restore test and access review, at least twice a year is reasonable for most small and mid-sized Ontario businesses, with critical items like patch compliance checked more frequently.

What is the single most commonly failed verification step?

Backup restore testing is the most commonly skipped step we see, with businesses assuming backups are working based only on a green status indicator rather than an actual successful restore.

Does having all these controls guarantee ransomware will not succeed?

No control or combination of controls provides a guarantee. These controls, properly verified, significantly reduce both the likelihood of a successful attack and the impact if one occurs.

Can a small business realistically implement all of this?

Yes, most of these controls are achievable for small businesses with the right tools and a bit of scheduled discipline. Working through them in priority order, starting with backups and MFA, is more realistic than attempting everything at once.

About the author

Joshua Arimoro

Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.

More about our team

Get every ransomware control on this list actually verified

We will test your backups, access controls, and endpoint coverage rather than assuming your current setup is working.

Keep exploring

Related services, locations, and resources

Related services

Related resources