How to Protect Your Business from Ransomware
Ransomware is now the single most disruptive cyber threat facing small and mid-sized businesses. A single click on a malicious link can encrypt every file on your network, take down your servers, and lock you out of Microsoft 365. This guide explains — in plain language — how ransomware attacks unfold, why they happen to businesses just like yours, and the specific controls that reliably stop them. It's written for owners and operators across Greater Sudbury, Lively, Chelmsford, North Bay, and Northern Ontario, not IT specialists.
How ransomware actually gets in
Most ransomware attacks against SMBs don't start with a Hollywood-style hacker. They start with a phishing email, a stolen password, or an unpatched server exposed to the internet. Attackers scan every IP address on the internet continuously — being in Northern Ontario provides no protection.
- Phishing emails that trick a user into entering credentials or opening a malicious file
- Password reuse — a leaked personal password used on a work Microsoft 365 account
- Remote Desktop or VPN exposed to the internet without MFA
- Unpatched servers, firewalls, or backup appliances with known vulnerabilities
- Compromised third-party software or managed service tools
The controls that actually stop ransomware
There's no single product that stops ransomware. Prevention is layered — each control catches what the last one missed.
Prevention (stops most attacks before they start)
- Multi-factor authentication on Microsoft 365, VPN, and all remote access — enforced, not optional
- Endpoint Detection and Response (EDR) on every workstation and server
- Email filtering with anti-phishing and attachment sandboxing
- Aggressive patching of Windows, browsers, and third-party software
- Remove local admin rights from everyday user accounts
Containment (limits damage if something gets through)
- Network segmentation so a compromised workstation can't reach servers directly
- Least-privilege access — users only see what they need
- Application allow-listing on high-risk endpoints
- Disable macros in Office documents from the internet
Recovery (guarantees you can rebuild without paying)
- Immutable, off-network backups that ransomware can't reach or delete
- Independent Microsoft 365 backup (Microsoft doesn't back you up)
- Regular, tested restores — a backup you've never restored is a hope, not a plan
- Documented incident response runbook — who to call, in what order
What to do if you're hit right now
If you're reading this during an active incident, stop and act in this order. Speed matters, but so does not making it worse.
- Do NOT power off encrypted machines — disconnect them from the network instead (unplug the ethernet, disable Wi-Fi). Powering off can destroy forensic evidence.
- Disable affected user accounts and revoke Microsoft 365 sessions immediately
- Contact your IT provider or an incident response team — every minute matters
- Contact your cyber insurance provider before engaging any third party — they usually require it
- Do NOT pay the ransom without professional and legal guidance — it rarely goes the way people expect
- Preserve logs, screenshots, and the ransom note
The Sudbury and Northern Ontario reality
We've responded to ransomware and business email compromise incidents at law firms, medical clinics, construction companies, and non-profits across Greater Sudbury, Lively, Hanmer, Garson, Azilda, Copper Cliff, Coniston, Parry Sound, and North Bay. Being smaller or 'not a target' has never been a defence — automated attacks don't care about postal codes.
Frequently asked questions
How much does ransomware recovery cost?
It depends entirely on preparation. Businesses with immutable backups, documented runbooks, and cyber insurance typically recover in days for the cost of labour. Businesses without those often face six-figure outcomes between downtime, data loss, insurance shortfalls, and reputational damage.
Will paying the ransom get our data back?
Sometimes. But paying funds further attacks, may violate sanctions law, and doesn't guarantee working decryption keys or that attackers won't leak the data anyway. Always involve legal counsel and your insurer before considering payment.
Does cyber insurance cover ransomware?
Modern policies increasingly do, but only if you can demonstrate you had the required controls — MFA, EDR, backups, staff training — in place at the time of the incident. Answering 'no' on the renewal questionnaire is a good way to void your coverage.
Are Microsoft 365 files safe from ransomware?
No. Ransomware can and does encrypt OneDrive and SharePoint files through a compromised user account. Microsoft's built-in retention helps in some scenarios, but a dedicated Microsoft 365 backup is still essential.
How quickly can you help if we're hit?
Existing managed clients get immediate response. Non-clients we take on as incident-response engagements when capacity allows — containment, credential resets, forensic preservation, and coordination with your insurer's breach counsel.
Get a cybersecurity assessment
Find out where your business is exposed to ransomware and phishing — and get a prioritized plan to close the gaps.
Related services, locations, and resources
Related services
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
Related service areas
Related resources
- The Most Common Cybersecurity Threats Facing Small Businesses
Forget nation-state hackers. Here are the threats actually hitting Northern Ontario SMBs today — and the pr…
- Why Every Business Needs Multi-Factor Authentication
If you do only one security thing this year, do this. MFA blocks the vast majority of account-takeover atta…
- Business Antivirus vs Consumer Antivirus: What's the Difference?
Consumer antivirus was designed for one person and one PC. Business endpoint protection is a different prod…
- How to Recognize a Phishing Email Before It's Too Late
Phishing is the number-one way businesses get breached. Here's exactly what to look for — and what to do wh…
