Cybersecurity readiness guide

Ransomware Readiness Checklist for Small Business

A practical checklist for reducing ransomware risk, protecting business data, and knowing what to do during the first hours of a suspected incident.

Ransomware planning starts before the warning message

Small businesses do not need a complicated security program to improve ransomware readiness. They need clear ownership of the basics: user access, Microsoft 365 security, endpoint protection, backups, monitoring, documentation, and a response plan that employees can follow under pressure.

The goal is to reduce the chance of a ransomware event, limit the damage if something gets through, and make recovery decisions less chaotic.

1. Reduce the easiest entry points

Many ransomware incidents begin with a compromised account, unsafe attachment, exposed remote access, or unmanaged device. Start by tightening the areas attackers most often test first.

  • Require multifactor authentication. MFA should be active for Microsoft 365, remote access, administrator accounts, backup portals, and sensitive vendor systems.
  • Review remote access. VPN, remote desktop, and remote support tools should be documented, limited, patched, and removed when no longer needed.
  • Patch workstations and servers. Operating system, browser, application, firewall, and firmware updates reduce avoidable exposure.
  • Limit administrator rights. Users should not have broad local or cloud administrator access unless the role truly requires it.

2. Make endpoint protection visible

Antivirus and endpoint tools are most useful when someone checks alerts, handles failed installs, and responds to suspicious activity. Security software that is installed once and ignored can leave gaps no one notices until a larger problem appears.

  • Confirm coverage. Every active workstation and server should have current endpoint protection.
  • Review alerts. Malware warnings, blocked activity, repeated failures, and disabled protection should create support action.
  • Remove stale devices. Old computers, former employee devices, and duplicate entries make it harder to see real coverage.
  • Connect endpoint alerts to support. Employees should know who to contact when a device behaves strangely.

3. Protect backups from the same incident

Backups are one of the most important ransomware controls, but only if they are monitored, protected, and tested. A backup that is connected, untested, or accessible with the same compromised account may not help when it is needed most.

  • Know what is backed up. Review servers, workstations, Microsoft 365, shared files, line-of-business data, and cloud applications.
  • Protect backup access. Backup administration should use MFA and should not rely on everyday user accounts.
  • Test restores. Periodic restore testing confirms that files, mailboxes, databases, or systems can actually be recovered.
  • Document recovery order. Decide which systems must come back first so the response team does not debate priorities during an outage.

4. Prepare the first-hour response

The first hour of a suspected ransomware incident should be calm and deliberate. Employees need to know who to call, what not to touch, and how leadership will make decisions.

  • Disconnect affected devices carefully. If a workstation appears infected, remove it from the network without wiping evidence or guessing at fixes.
  • Stop credential spread. Disable or reset affected accounts, revoke sessions, and review recent sign-ins where appropriate.
  • Preserve details. Record screenshots, filenames, times, affected users, alerts, and any suspicious messages or attachments.
  • Communicate internally. Tell employees what systems are affected, what to avoid, and where updates will come from.

5. Review after every scare

Even a false alarm can improve readiness. Each suspicious email, endpoint warning, failed backup, or account lockout is a chance to update documentation, refine monitoring, and clarify who owns the next step.

  • Update the checklist. Add missing systems, contacts, passwords ownership, and recovery notes.
  • Close the root cause. Fix exposed access, outdated software, missing MFA, weak permissions, or backup gaps.
  • Train around real examples. Use actual incidents and near misses to make employee guidance more practical.
  • Schedule regular review. Ransomware readiness should be revisited as users, devices, cloud tools, and vendors change.

Need a ransomware readiness review?

Smart IT Firm can help review endpoint protection, Microsoft 365 access, backups, monitoring, and recovery planning before a security scare becomes a business interruption.