Ransomware is frightening, but for a small organization it is largely preventable and, with the right preparation, survivable. Because it almost always starts with a phishing email, readiness and everyday email security are the same work. Here is a plain checklist to prevent it, detect it early, and recover if it happens.
Ransomware usually starts with phishing, so preventing it means stopping phishing and requiring multi-factor authentication — and surviving it means having working, tested, offline backups. Add a simple written response plan (isolate, don't power off, call IT, report to the FBI/CISA, restore from backup), keep systems patched, and limit who has administrator access. U.S. authorities discourage paying the ransom; the goal is to never need that decision because your backups work.
Most ransomware arrives through email — a malicious attachment or link, or a stolen password used to log in. Stop that, and you've stopped most attacks before they start.
Prevention is never perfect, so the deciding factor is whether you can recover. That comes down to backups that actually work.
The sooner you notice, the less it spreads. Watch for the early signs — files suddenly renamed or inaccessible, security tools disabled, unusual account activity or logins at odd hours, and mailbox rules you didn't create. A monitored inbox and basic endpoint protection shorten the time between the first foothold and your response.
Work from your written plan, not from memory. CISA and NIST both describe the same lifecycle — contain, eradicate, recover, then review — and the first steps below are where small organizations most often go wrong.
Sources & further reading: CISA #StopRansomware Guide and "I've Been Hit by Ransomware" · FBI IC3 (ic3.gov) · Verizon 2025 Data Breach Investigations Report · Sophos State of Ransomware 2025 · NIST SP 800-61 incident handling. Figures are as reported for the year noted. Educational only; not a substitute for professional incident-response advice.
Most ransomware begins with email — a phishing message that either carries a malicious attachment or link, or that steals a password used to log in later. Stopping the initial phishing and requiring multi-factor authentication closes the most common doors, which is why email security and ransomware readiness are really the same project.
Working, tested, offline or immutable backups. If you can restore your systems from a clean backup, ransomware becomes an expensive disruption rather than a catastrophe. Backups only count if you have actually tested a restore — an untested backup is a hope, not a plan — and if at least one copy is kept where the ransomware cannot reach and encrypt it too.
U.S. authorities including the FBI and CISA discourage paying, because payment funds and encourages more attacks, may be legally risky, and does not guarantee you get your data back or that it wasn't copied. The decision can be complex in a real crisis, so the far better position is to never need to make it — by having tested backups and a plan ready in advance.
Isolate affected systems from the network to stop the spread, but do not power them off if you can avoid it (that can destroy useful evidence). Switch to out-of-band communication — phone, not the possibly-compromised email — then contact your IT support and cyber-insurer, preserve logs, report to CISA and the FBI at IC3.gov, and begin recovery from your known-good backups. Follow your written plan rather than improvising under pressure.
Two reasons, both avoidable. First, the backup was never restore-tested, so nobody knew it was incomplete or corrupt until they needed it — test a real restore on a schedule. Second, the backup was reachable from the network, so the ransomware encrypted it along with everything else. At least one copy must be offline or immutable, where the attacker cannot alter it. A backup that fails either test is a hope, not a plan.
Very. In Sophos's 2025 incident-response data, ransomware made up about 70% of the cases handled for small businesses, with malicious email and phishing among the leading entry points. Reported ransomware losses to the FBI's IC3 also rose sharply year over year. Small organizations are targeted precisely because they often lack tested backups and layered email defenses — which is exactly what this checklist builds.
Because ransomware almost always begins with a phishing email, Family Sentinel's Org Guard watches your organization's mail for the malicious links, attachments, and credential-theft lures that start it — and alerts a person you choose. Read-only, and never able to send or delete.